Edit tour

Linux Analysis Report
nimips.elf

Overview

General Information

Sample name:nimips.elf
Analysis ID:1635960
MD5:833feb0df15c75d09fd2f10ffbd7b5e0
SHA1:839be5d2776caada6254e9457071f862c643432b
SHA256:5b339544ba55c78bff25dbd5e737cd854d6c61d5ed3b1866d6d5fe110a8a9d7e
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1635960
Start date and time:2025-03-12 09:05:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:nimips.elf
Detection:MAL
Classification:mal60.troj.linELF@0/2@0/0
Command:/tmp/nimips.elf
PID:5517
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5507, Parent: 3670)
  • rm (PID: 5507, Parent: 3670, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.WtMgtKnvIZ /tmp/tmp.44CFdAkDOy /tmp/tmp.klGVCjsXl9
  • dash New Fork (PID: 5508, Parent: 3670)
  • rm (PID: 5508, Parent: 3670, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.WtMgtKnvIZ /tmp/tmp.44CFdAkDOy /tmp/tmp.klGVCjsXl9
  • nimips.elf (PID: 5517, Parent: 5442, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/nimips.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: nimips.elfAvira: detected
Source: nimips.elfVirustotal: Detection: 20%Perma Link
Source: nimips.elfReversingLabs: Detection: 18%

Networking

barindex
Source: global trafficTCP traffic: 156.244.44.239 ports 0,1,50182,2,5,8
Source: global trafficTCP traffic: 156.244.6.124 ports 41763,5102,1,2,26141,30751,4,6
Source: global trafficTCP traffic: 156.244.13.166 ports 49722,7680,29486,2,4,7,9
Source: global trafficTCP traffic: 154.205.155.97 ports 35086,7680,0,3,5,6,8
Source: global trafficTCP traffic: 192.168.2.15:57432 -> 154.205.155.243:7680
Source: global trafficTCP traffic: 192.168.2.15:52278 -> 156.244.6.124:26141
Source: global trafficTCP traffic: 192.168.2.15:57992 -> 156.244.13.166:49722
Source: global trafficTCP traffic: 192.168.2.15:34446 -> 156.244.44.239:50182
Source: global trafficTCP traffic: 192.168.2.15:53110 -> 154.205.155.97:35086
Source: global trafficTCP traffic: 192.168.2.15:56978 -> 156.244.14.93:46164
Source: global trafficTCP traffic: 192.168.2.15:54380 -> 154.205.157.159:26141
Source: global trafficUDP traffic: 192.168.2.15:37511 -> 74.125.250.129:19302
Source: /tmp/nimips.elf (PID: 5529)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.6.124
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.13.166
Source: nimips.elf, 5517.1.00007f3ce8455000.00007f3ce845e000.rw-.sdmpString found in binary or memory: http://0/t/wget.sh
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.linELF@0/2@0/0
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1333/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1695/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/911/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/914/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1591/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1585/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/802/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/804/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/3407/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1484/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/133/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1479/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/931/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1595/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/812/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/933/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/3419/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/3310/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/262/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/142/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/263/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/264/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/265/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/145/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/266/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/267/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/268/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/3303/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/269/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1486/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/1806/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/3440/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/270/cmdlineJump to behavior
Source: /tmp/nimips.elf (PID: 5517)File opened: /proc/271/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 5507)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.WtMgtKnvIZ /tmp/tmp.44CFdAkDOy /tmp/tmp.klGVCjsXl9Jump to behavior
Source: /usr/bin/dash (PID: 5508)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.WtMgtKnvIZ /tmp/tmp.44CFdAkDOy /tmp/tmp.klGVCjsXl9Jump to behavior
Source: /tmp/nimips.elf (PID: 5517)Queries kernel information via 'uname': Jump to behavior
Source: nimips.elf, 5517.1.00005628d0897000.00005628d093e000.rw-.sdmpBinary or memory string: (V!/etc/qemu-binfmt/mips
Source: nimips.elf, 5517.1.00007ffee6d3a000.00007ffee6d5b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/nimips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/nimips.elf
Source: nimips.elf, 5517.1.00007f3ce8455000.00007f3ce845e000.rw-.sdmpBinary or memory string: vmware
Source: nimips.elf, 5517.1.00007ffee6d3a000.00007ffee6d5b000.rw-.sdmpBinary or memory string: (V/tmp/qemu-open.OTzpNo\
Source: nimips.elf, 5517.1.00007f3ce8455000.00007f3ce845e000.rw-.sdmpBinary or memory string: qemu-arm
Source: nimips.elf, 5517.1.00005628d0897000.00005628d093e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: nimips.elf, 5517.1.00007f3ce8455000.00007f3ce845e000.rw-.sdmpBinary or memory string: qemu-armXsB
Source: nimips.elf, 5517.1.00007ffee6d3a000.00007ffee6d5b000.rw-.sdmpBinary or memory string: %s/qemu-op
Source: nimips.elf, 5517.1.00007ffee6d3a000.00007ffee6d5b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: nimips.elf, 5517.1.00007f3ce8455000.00007f3ce845e000.rw-.sdmpBinary or memory string: vmwarem4
Source: nimips.elf, 5517.1.00007ffee6d3a000.00007ffee6d5b000.rw-.sdmpBinary or memory string: MPDIR%s/qemu-op
Source: nimips.elf, 5517.1.00007ffee6d3a000.00007ffee6d5b000.rw-.sdmpBinary or memory string: /tmp/qemu-open.OTzpNo
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1635960 Sample: nimips.elf Startdate: 12/03/2025 Architecture: LINUX Score: 60 13 156.244.13.166, 29486, 38492, 41540 POWERLINE-AS-APPOWERLINEDATACENTERHK Seychelles 2->13 15 156.244.44.239, 34446, 50182 POWERLINE-AS-APPOWERLINEDATACENTERHK Seychelles 2->15 17 6 other IPs or domains 2->17 19 Antivirus / Scanner detection for submitted sample 2->19 21 Multi AV Scanner detection for submitted file 2->21 23 Connects to many ports of the same IP (likely port scanning) 2->23 7 dash rm nimips.elf 2->7         started        9 dash rm 2->9         started        signatures3 process4 process5 11 nimips.elf 7->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
nimips.elf20%VirustotalBrowse
nimips.elf18%ReversingLabsLinux.Trojan.Mirai
nimips.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://0/t/wget.shnimips.elf, 5517.1.00007f3ce8455000.00007f3ce845e000.rw-.sdmpfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    156.244.6.124
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
    154.205.157.159
    unknownSeychelles
    26484IKGUL-26484USfalse
    154.205.155.243
    unknownSeychelles
    26484IKGUL-26484USfalse
    156.244.14.93
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKfalse
    156.244.13.166
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
    154.205.155.97
    unknownSeychelles
    26484IKGUL-26484UStrue
    74.125.250.129
    unknownUnited States
    15169GOOGLEUSfalse
    156.244.44.239
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    156.244.6.124sh4.elfGet hashmaliciousUnknownBrowse
      arm7.elfGet hashmaliciousUnknownBrowse
        arm6.elfGet hashmaliciousUnknownBrowse
          arm6.elfGet hashmaliciousUnknownBrowse
            arm7.elfGet hashmaliciousUnknownBrowse
              m68k.elfGet hashmaliciousUnknownBrowse
                arm6.elfGet hashmaliciousUnknownBrowse
                  arm.elfGet hashmaliciousUnknownBrowse
                    spc.elfGet hashmaliciousUnknownBrowse
                      arm5.elfGet hashmaliciousUnknownBrowse
                        154.205.157.159aarch64.elfGet hashmaliciousUnknownBrowse
                          arm6.elfGet hashmaliciousUnknownBrowse
                            arm7.elfGet hashmaliciousUnknownBrowse
                              aarch64.elfGet hashmaliciousUnknownBrowse
                                arm6.elfGet hashmaliciousUnknownBrowse
                                  ppc.elfGet hashmaliciousUnknownBrowse
                                    mpsl.elfGet hashmaliciousUnknownBrowse
                                      aarch64.elfGet hashmaliciousUnknownBrowse
                                        sh4.elfGet hashmaliciousUnknownBrowse
                                          m68k.elfGet hashmaliciousUnknownBrowse
                                            156.244.14.93arm6.elfGet hashmaliciousUnknownBrowse
                                              156.244.13.166ppc.elfGet hashmaliciousUnknownBrowse
                                                arm7.elfGet hashmaliciousUnknownBrowse
                                                  arm6.elfGet hashmaliciousUnknownBrowse
                                                    mips.elfGet hashmaliciousUnknownBrowse
                                                      arm5.elfGet hashmaliciousUnknownBrowse
                                                        arm6.elfGet hashmaliciousUnknownBrowse
                                                          i686.elfGet hashmaliciousUnknownBrowse
                                                            aarch64.elfGet hashmaliciousUnknownBrowse
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                  154.205.155.97mips.elfGet hashmaliciousUnknownBrowse
                                                                    arm.elfGet hashmaliciousUnknownBrowse
                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                        156.244.44.239sh4.elfGet hashmaliciousUnknownBrowse
                                                                          arm7.elfGet hashmaliciousUnknownBrowse
                                                                            No context
                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                            IKGUL-26484USresgod.m68k.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.249.231.151
                                                                            resgod.arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.249.231.183
                                                                            mips.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.155.97
                                                                            arm.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.155.97
                                                                            aarch64.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.157.159
                                                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.155.97
                                                                            cbr.arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.249.231.178
                                                                            tmips.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.238.135.163
                                                                            arm6.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.157.159
                                                                            arm7.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.157.159
                                                                            POWERLINE-AS-APPOWERLINEDATACENTERHKresgod.mips.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.251.3.4
                                                                            ppc.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.13.166
                                                                            sh4.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.44.239
                                                                            arm7.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.44.239
                                                                            arm6.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.14.93
                                                                            pesanan09900011.exeGet hashmaliciousFormBookBrowse
                                                                            • 154.213.39.66
                                                                            tnZI8EzSx3.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.202.215.234
                                                                            Anpy55Zkwp.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.127.126.183
                                                                            IfmB4tGS4L.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.127.126.183
                                                                            zzSk99EqY0.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.202.215.234
                                                                            POWERLINE-AS-APPOWERLINEDATACENTERHKresgod.mips.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.251.3.4
                                                                            ppc.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.13.166
                                                                            sh4.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.44.239
                                                                            arm7.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.44.239
                                                                            arm6.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.244.14.93
                                                                            pesanan09900011.exeGet hashmaliciousFormBookBrowse
                                                                            • 154.213.39.66
                                                                            tnZI8EzSx3.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.202.215.234
                                                                            Anpy55Zkwp.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.127.126.183
                                                                            IfmB4tGS4L.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.127.126.183
                                                                            zzSk99EqY0.exeGet hashmaliciousFormBookBrowse
                                                                            • 45.202.215.234
                                                                            IKGUL-26484USresgod.m68k.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.249.231.151
                                                                            resgod.arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.249.231.183
                                                                            mips.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.155.97
                                                                            arm.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.155.97
                                                                            aarch64.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.157.159
                                                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.155.97
                                                                            cbr.arm5.elfGet hashmaliciousMiraiBrowse
                                                                            • 156.249.231.178
                                                                            tmips.elfGet hashmaliciousUnknownBrowse
                                                                            • 156.238.135.163
                                                                            arm6.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.157.159
                                                                            arm7.elfGet hashmaliciousUnknownBrowse
                                                                            • 154.205.157.159
                                                                            No context
                                                                            No context
                                                                            Process:/tmp/nimips.elf
                                                                            File Type:data
                                                                            Category:dropped
                                                                            Size (bytes):16
                                                                            Entropy (8bit):3.5
                                                                            Encrypted:false
                                                                            SSDEEP:3:TgF03n:TgU
                                                                            MD5:4D28E55E74CD0D53BAACADA13DD5507E
                                                                            SHA1:55E77DA643437917673B1729630AF37D72B04A57
                                                                            SHA-256:CC56840CB1AAE05A8CF7236A813D2C79FC65E01FFC1E2794BC9BAC77A13A72B9
                                                                            SHA-512:2EEFE4DA52AAB7F47B7EA12C082A546666877371D442282254B45EFCF009AFBDFBF4DA9298487BC7DF8F4940D654A3AEA254E1BA50DD46BC77B4157726BCE325
                                                                            Malicious:false
                                                                            Reputation:low
                                                                            Preview:/tmp/nimips.elf.
                                                                            Process:/tmp/nimips.elf
                                                                            File Type:data
                                                                            Category:dropped
                                                                            Size (bytes):16
                                                                            Entropy (8bit):3.5
                                                                            Encrypted:false
                                                                            SSDEEP:3:TgF03n:TgU
                                                                            MD5:4D28E55E74CD0D53BAACADA13DD5507E
                                                                            SHA1:55E77DA643437917673B1729630AF37D72B04A57
                                                                            SHA-256:CC56840CB1AAE05A8CF7236A813D2C79FC65E01FFC1E2794BC9BAC77A13A72B9
                                                                            SHA-512:2EEFE4DA52AAB7F47B7EA12C082A546666877371D442282254B45EFCF009AFBDFBF4DA9298487BC7DF8F4940D654A3AEA254E1BA50DD46BC77B4157726BCE325
                                                                            Malicious:false
                                                                            Reputation:low
                                                                            Preview:/tmp/nimips.elf.
                                                                            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                            Entropy (8bit):5.519665250965247
                                                                            TrID:
                                                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                            File name:nimips.elf
                                                                            File size:85'104 bytes
                                                                            MD5:833feb0df15c75d09fd2f10ffbd7b5e0
                                                                            SHA1:839be5d2776caada6254e9457071f862c643432b
                                                                            SHA256:5b339544ba55c78bff25dbd5e737cd854d6c61d5ed3b1866d6d5fe110a8a9d7e
                                                                            SHA512:74364af6f497e08d95245c1c040f5c56e962966f55f1c1c87d99a61279a0abaedfb8aa204b7209dc2c4a306faa3f6448864cb2f29ae33bb9b672d714263eb582
                                                                            SSDEEP:1536:LM6Ek3io/h7l7yDahFSFC0F1cuvvRfZvS011ZHs6euTbFWa:LM6EDo/h70ahFSj5xv53Hpbx
                                                                            TLSH:A183D90F2E65CFADF26DC33447B74A31936923D522E1C685D2ACE2111F6434EA45FBA8
                                                                            File Content Preview:.ELF.....................@.`...4..J......4. ...(.............@...@....?...?...............@..E@..E@....D..l$........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'..h...!........'9&

                                                                            ELF header

                                                                            Class:ELF32
                                                                            Data:2's complement, big endian
                                                                            Version:1 (current)
                                                                            Machine:MIPS R3000
                                                                            Version Number:0x1
                                                                            Type:EXEC (Executable file)
                                                                            OS/ABI:UNIX - System V
                                                                            ABI Version:0
                                                                            Entry Point Address:0x400260
                                                                            Flags:0x1007
                                                                            ELF Header Size:52
                                                                            Program Header Offset:52
                                                                            Program Header Size:32
                                                                            Number of Program Headers:3
                                                                            Section Header Offset:84624
                                                                            Section Header Size:40
                                                                            Number of Section Headers:12
                                                                            Header String Table Index:11
                                                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                            NULL0x00x00x00x00x0000
                                                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                            .textPROGBITS0x4001200x1200x125e00x00x6AX0016
                                                                            .finiPROGBITS0x4127000x127000x5c0x00x6AX004
                                                                            .rodataPROGBITS0x4127600x127600x18700x00x2A0016
                                                                            .ctorsPROGBITS0x4540000x140000x80x00x3WA004
                                                                            .dtorsPROGBITS0x4540080x140080x80x00x3WA004
                                                                            .dataPROGBITS0x4540200x140200x4340x00x3WA0016
                                                                            .gotPROGBITS0x4544600x144600x5e40x40x10000003WAp0016
                                                                            .sbssNOBITS0x454a440x14a440x140x00x10000003WAp004
                                                                            .bssNOBITS0x454a600x14a440x61c40x00x3WA0016
                                                                            .shstrtabSTRTAB0x00x14a440x490x00x0001
                                                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                            LOAD0x00x4000000x4000000x13fd00x13fd05.56160x5R E0x10000.init .text .fini .rodata
                                                                            LOAD0x140000x4540000x4540000xa440x6c243.56440x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                            Download Network PCAP: filteredfull

                                                                            • Total Packets: 104
                                                                            • 2 Ports have been hidden.
                                                                            • 5102 undefined
                                                                            • 7680 undefined
                                                                            • 19302 undefined
                                                                            • 26141 undefined
                                                                            • 29486 undefined
                                                                            • 30751 undefined
                                                                            • 35086 undefined
                                                                            • 41763 undefined
                                                                            • 46164 undefined
                                                                            • 49722 undefined
                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                            Mar 12, 2025 09:05:49.450234890 CET574327680192.168.2.15154.205.155.243
                                                                            Mar 12, 2025 09:05:49.469615936 CET768057432154.205.155.243192.168.2.15
                                                                            Mar 12, 2025 09:05:49.469732046 CET574327680192.168.2.15154.205.155.243
                                                                            Mar 12, 2025 09:05:50.055377960 CET768057432154.205.155.243192.168.2.15
                                                                            Mar 12, 2025 09:05:50.056807041 CET574327680192.168.2.15154.205.155.243
                                                                            Mar 12, 2025 09:05:50.147697926 CET768057432154.205.155.243192.168.2.15
                                                                            Mar 12, 2025 09:05:50.149936914 CET574327680192.168.2.15154.205.155.243
                                                                            Mar 12, 2025 09:05:55.941111088 CET574327680192.168.2.15154.205.155.243
                                                                            Mar 12, 2025 09:05:55.945899963 CET768057432154.205.155.243192.168.2.15
                                                                            Mar 12, 2025 09:05:56.255506039 CET768057432154.205.155.243192.168.2.15
                                                                            Mar 12, 2025 09:05:56.255917072 CET574327680192.168.2.15154.205.155.243
                                                                            Mar 12, 2025 09:05:56.260749102 CET768057432154.205.155.243192.168.2.15
                                                                            Mar 12, 2025 09:05:57.257802010 CET5227826141192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:05:57.262640953 CET2614152278156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:05:57.262713909 CET5227826141192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:05:58.231502056 CET2614152278156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:05:58.231678009 CET5227826141192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:05:58.594455957 CET2614152278156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:05:58.594784975 CET5227826141192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:03.712675095 CET5227826141192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:03.717737913 CET2614152278156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:04.112289906 CET2614152278156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:04.112533092 CET5227826141192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:04.117240906 CET2614152278156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:05.114464045 CET5799249722192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:05.119282007 CET4972257992156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:05.119359970 CET5799249722192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:05.677733898 CET4972257992156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:05.677865982 CET5799249722192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:05.764384031 CET4972257992156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:05.764506102 CET5799249722192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:11.606878042 CET5799249722192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:11.611546040 CET4972257992156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:11.772489071 CET4972257992156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:11.772648096 CET5799249722192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:11.777333021 CET4972257992156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:12.774808884 CET4581841763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:12.779562950 CET4176345818156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:12.779638052 CET4581841763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:13.743180990 CET4176345818156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:13.743401051 CET4581841763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:14.088491917 CET4176345818156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:14.088654041 CET4581841763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:19.245702982 CET4581841763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:19.250591993 CET4176345818156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:19.643256903 CET4176345818156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:19.643599033 CET4581841763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:19.648426056 CET4176345818156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:20.645785093 CET3444650182192.168.2.15156.244.44.239
                                                                            Mar 12, 2025 09:06:20.650497913 CET5018234446156.244.44.239192.168.2.15
                                                                            Mar 12, 2025 09:06:20.650595903 CET3444650182192.168.2.15156.244.44.239
                                                                            Mar 12, 2025 09:06:21.205595970 CET5018234446156.244.44.239192.168.2.15
                                                                            Mar 12, 2025 09:06:21.205766916 CET3444650182192.168.2.15156.244.44.239
                                                                            Mar 12, 2025 09:06:21.292264938 CET5018234446156.244.44.239192.168.2.15
                                                                            Mar 12, 2025 09:06:21.292490959 CET3444650182192.168.2.15156.244.44.239
                                                                            Mar 12, 2025 09:06:27.104226112 CET3444650182192.168.2.15156.244.44.239
                                                                            Mar 12, 2025 09:06:27.109421015 CET5018234446156.244.44.239192.168.2.15
                                                                            Mar 12, 2025 09:06:27.270301104 CET5018234446156.244.44.239192.168.2.15
                                                                            Mar 12, 2025 09:06:27.270416021 CET3444650182192.168.2.15156.244.44.239
                                                                            Mar 12, 2025 09:06:27.275827885 CET5018234446156.244.44.239192.168.2.15
                                                                            Mar 12, 2025 09:06:28.272264957 CET5311035086192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:06:28.277085066 CET3508653110154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:06:28.277180910 CET5311035086192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:06:28.853638887 CET3508653110154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:06:28.853859901 CET5311035086192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:06:28.944199085 CET3508653110154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:06:28.944299936 CET5311035086192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:06:34.737967968 CET5311035086192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:06:34.742806911 CET3508653110154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:06:34.907857895 CET3508653110154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:06:34.908016920 CET5311035086192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:06:34.912705898 CET3508653110154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:06:35.909784079 CET5697846164192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:06:35.914568901 CET4616456978156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:06:35.914654970 CET5697846164192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:06:36.493526936 CET4616456978156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:06:36.493659019 CET5697846164192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:06:36.594511032 CET4616456978156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:06:36.594605923 CET5697846164192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:06:42.387408972 CET5697846164192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:06:42.392157078 CET4616456978156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:06:42.555394888 CET4616456978156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:06:42.555562973 CET5697846164192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:06:42.560317039 CET4616456978156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:06:43.557588100 CET474185102192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:43.562402010 CET510247418156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:43.562470913 CET474185102192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:44.537098885 CET510247418156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:44.537261963 CET474185102192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:44.893003941 CET510247418156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:44.893100977 CET474185102192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:50.012728930 CET474185102192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:50.017436981 CET510247418156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:50.415610075 CET510247418156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:50.415869951 CET474185102192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:06:50.421542883 CET510247418156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:06:51.417444944 CET415407680192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:51.422173977 CET768041540156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:51.422235012 CET415407680192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:52.019418955 CET768041540156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:52.019728899 CET415407680192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:52.107898951 CET768041540156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:52.108027935 CET415407680192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:55.223207951 CET768041540156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:55.223345041 CET415407680192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:57.906826973 CET415407680192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:06:57.913408041 CET768041540156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:06:57.913520098 CET415407680192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:07:12.923177004 CET3849229486192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:07:12.928028107 CET2948638492156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:07:12.928143978 CET3849229486192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:07:13.495294094 CET2948638492156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:07:13.495446920 CET3849229486192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:07:13.596221924 CET2948638492156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:07:13.596330881 CET3849229486192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:07:19.394051075 CET3849229486192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:07:19.398737907 CET2948638492156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:07:19.559772968 CET2948638492156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:07:19.560091972 CET3849229486192.168.2.15156.244.13.166
                                                                            Mar 12, 2025 09:07:19.564800024 CET2948638492156.244.13.166192.168.2.15
                                                                            Mar 12, 2025 09:07:20.562134981 CET421427680192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:07:20.572060108 CET768042142154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:07:20.572143078 CET421427680192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:07:21.156042099 CET768042142154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:07:21.156137943 CET421427680192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:07:21.244621992 CET768042142154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:07:21.244690895 CET421427680192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:07:27.028722048 CET421427680192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:07:27.033538103 CET768042142154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:07:27.194858074 CET768042142154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:07:27.195080996 CET421427680192.168.2.15154.205.155.97
                                                                            Mar 12, 2025 09:07:27.199867964 CET768042142154.205.155.97192.168.2.15
                                                                            Mar 12, 2025 09:07:28.197223902 CET5829230751192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:28.202271938 CET3075158292156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:28.202353001 CET5829230751192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:29.167956114 CET3075158292156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:29.168179989 CET5829230751192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:29.527924061 CET3075158292156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:29.528218031 CET5829230751192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:34.652203083 CET5829230751192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:34.656977892 CET3075158292156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:35.074227095 CET3075158292156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:35.074600935 CET5829230751192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:35.079406977 CET3075158292156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:36.076422930 CET4583641763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:36.081818104 CET4176345836156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:36.081933022 CET4583641763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:37.035407066 CET4176345836156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:37.035612106 CET4583641763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:37.381653070 CET4176345836156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:37.381793022 CET4583641763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:42.530328035 CET4583641763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:42.535011053 CET4176345836156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:42.922646999 CET4176345836156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:42.922812939 CET4583641763192.168.2.15156.244.6.124
                                                                            Mar 12, 2025 09:07:42.927562952 CET4176345836156.244.6.124192.168.2.15
                                                                            Mar 12, 2025 09:07:43.924365044 CET5438026141192.168.2.15154.205.157.159
                                                                            Mar 12, 2025 09:07:43.929069996 CET2614154380154.205.157.159192.168.2.15
                                                                            Mar 12, 2025 09:07:43.929137945 CET5438026141192.168.2.15154.205.157.159
                                                                            Mar 12, 2025 09:07:44.521296978 CET2614154380154.205.157.159192.168.2.15
                                                                            Mar 12, 2025 09:07:44.521433115 CET5438026141192.168.2.15154.205.157.159
                                                                            Mar 12, 2025 09:07:44.609761953 CET2614154380154.205.157.159192.168.2.15
                                                                            Mar 12, 2025 09:07:44.609865904 CET5438026141192.168.2.15154.205.157.159
                                                                            Mar 12, 2025 09:07:50.380997896 CET5438026141192.168.2.15154.205.157.159
                                                                            Mar 12, 2025 09:07:50.385776043 CET2614154380154.205.157.159192.168.2.15
                                                                            Mar 12, 2025 09:07:50.546711922 CET2614154380154.205.157.159192.168.2.15
                                                                            Mar 12, 2025 09:07:50.547046900 CET5438026141192.168.2.15154.205.157.159
                                                                            Mar 12, 2025 09:07:50.551772118 CET2614154380154.205.157.159192.168.2.15
                                                                            Mar 12, 2025 09:07:51.548294067 CET4240452962192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:07:51.553106070 CET5296242404156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:07:51.553181887 CET4240452962192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:07:52.109603882 CET5296242404156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:07:52.109731913 CET4240452962192.168.2.15156.244.14.93
                                                                            Mar 12, 2025 09:07:52.196192980 CET5296242404156.244.14.93192.168.2.15
                                                                            Mar 12, 2025 09:07:52.196260929 CET4240452962192.168.2.15156.244.14.93
                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                            Mar 12, 2025 09:05:50.486779928 CET3751119302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:05:50.935803890 CET193023751174.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:05:58.259604931 CET5869519302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:05:58.710541964 CET193025869574.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:06:06.116063118 CET4452119302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:06:06.604783058 CET193024452174.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:06:13.776550055 CET3363319302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:06:14.243144989 CET193023363374.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:06:21.647715092 CET5323319302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:06:22.101768970 CET193025323374.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:06:29.274393082 CET3811919302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:06:29.736289024 CET193023811974.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:06:36.911093950 CET4609219302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:06:37.385452032 CET193024609274.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:06:44.559199095 CET5557619302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:06:45.010940075 CET193025557674.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:06:52.419106007 CET3390219302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:06:52.905220032 CET193023390274.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:07:13.925867081 CET5605219302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:07:14.392497063 CET193025605274.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:07:21.564167976 CET3504219302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:07:22.026973009 CET193023504274.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:07:29.199054956 CET5988119302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:07:29.649626017 CET193025988174.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:07:37.078353882 CET5365419302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:07:37.528518915 CET193025365474.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:07:44.925671101 CET5269319302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:07:45.379353046 CET193025269374.125.250.129192.168.2.15
                                                                            Mar 12, 2025 09:07:52.549588919 CET5430319302192.168.2.1574.125.250.129
                                                                            Mar 12, 2025 09:07:53.019531012 CET193025430374.125.250.129192.168.2.15

                                                                            System Behavior

                                                                            Start time (UTC):08:05:39
                                                                            Start date (UTC):12/03/2025
                                                                            Path:/usr/bin/dash
                                                                            Arguments:-
                                                                            File size:129816 bytes
                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                            Start time (UTC):08:05:39
                                                                            Start date (UTC):12/03/2025
                                                                            Path:/usr/bin/rm
                                                                            Arguments:rm -f /tmp/tmp.WtMgtKnvIZ /tmp/tmp.44CFdAkDOy /tmp/tmp.klGVCjsXl9
                                                                            File size:72056 bytes
                                                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                            Start time (UTC):08:05:39
                                                                            Start date (UTC):12/03/2025
                                                                            Path:/usr/bin/dash
                                                                            Arguments:-
                                                                            File size:129816 bytes
                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                            Start time (UTC):08:05:39
                                                                            Start date (UTC):12/03/2025
                                                                            Path:/usr/bin/rm
                                                                            Arguments:rm -f /tmp/tmp.WtMgtKnvIZ /tmp/tmp.44CFdAkDOy /tmp/tmp.klGVCjsXl9
                                                                            File size:72056 bytes
                                                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                            Start time (UTC):08:05:48
                                                                            Start date (UTC):12/03/2025
                                                                            Path:/tmp/nimips.elf
                                                                            Arguments:-
                                                                            File size:5777432 bytes
                                                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c