Edit tour

Linux Analysis Report
sync.arm7.elf

Overview

General Information

Sample name:sync.arm7.elf
Analysis ID:1637902
MD5:8a6109d58a08dd6e18e72999fdea5e7e
SHA1:e33eb5d16a428ef6693aba34336ffa43a800b644
SHA256:597e16b001de0eefc8eee2ebcfb53e6c670f94c4fdc42ded8f5e42d7ec25c76b
Tags:elfuser-abuse_ch
Infos:

Detection

Score:72
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Performs DNS TXT record lookups
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1637902
Start date and time:2025-03-14 01:47:23 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sync.arm7.elf
Detection:MAL
Classification:mal72.evad.linELF@0/0@54/0
  • VT rate limit hit for: dnsresolve.socialgains.cf
Command:/tmp/sync.arm7.elf
PID:6271
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
Infect
Standard Error:
  • system is lnxubuntu20
  • sync.arm7.elf (PID: 6271, Parent: 6192, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/sync.arm7.elf
  • dash New Fork (PID: 6282, Parent: 4331)
  • rm (PID: 6282, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.8qFPUqxga1 /tmp/tmp.KKoCOey2qq /tmp/tmp.Ik5SJzv8Ic
  • dash New Fork (PID: 6283, Parent: 4331)
  • rm (PID: 6283, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.8qFPUqxga1 /tmp/tmp.KKoCOey2qq /tmp/tmp.Ik5SJzv8Ic
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-14T01:49:20.682155+010020135141A Network Trojan was detected192.168.2.23606478.8.8.853UDP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sync.arm7.elfAvira: detected
Source: sync.arm7.elfVirustotal: Detection: 45%Perma Link
Source: sync.arm7.elfReversingLabs: Detection: 60%

Networking

barindex
Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.23:60647 -> 8.8.8.8:53
Source: global trafficTCP traffic: 192.168.2.23:55782 -> 142.44.232.40:61003
Source: unknownDNS traffic detected: query: dnsresolve.socialgains.cf replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownTCP traffic detected without corresponding DNS query: 142.44.232.40
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: dnsresolve.socialgains.cf
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal72.evad.linELF@0/0@54/0
Source: /usr/bin/dash (PID: 6282)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.8qFPUqxga1 /tmp/tmp.KKoCOey2qq /tmp/tmp.Ik5SJzv8IcJump to behavior
Source: /usr/bin/dash (PID: 6283)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.8qFPUqxga1 /tmp/tmp.KKoCOey2qq /tmp/tmp.Ik5SJzv8IcJump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/sync.arm7.elf (PID: 6271)File: /tmp/sync.arm7.elfJump to behavior
Source: /tmp/sync.arm7.elf (PID: 6275)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm7.elf (PID: 6275)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm7.elf (PID: 6271)Queries kernel information via 'uname': Jump to behavior
Source: sync.arm7.elf, 6271.1.000055c8a5bc8000.000055c8a5d17000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: sync.arm7.elf, 6271.1.000055c8a5bc8000.000055c8a5d17000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: sync.arm7.elf, 6271.1.00007ffe3cb7e000.00007ffe3cb9f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: sync.arm7.elf, 6271.1.00007ffe3cb7e000.00007ffe3cb9f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/sync.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sync.arm7.elf

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1637902 Sample: sync.arm7.elf Startdate: 14/03/2025 Architecture: LINUX Score: 72 19 dnsresolve.socialgains.cf 2->19 21 142.44.232.40, 55782, 55784, 55786 OVHFR Canada 2->21 23 3 other IPs or domains 2->23 25 Suricata IDS alerts for network traffic 2->25 27 Antivirus / Scanner detection for submitted sample 2->27 29 Multi AV Scanner detection for submitted file 2->29 8 sync.arm7.elf 2->8         started        11 dash rm 2->11         started        13 dash rm 2->13         started        signatures3 31 Performs DNS TXT record lookups 19->31 process4 signatures5 33 Sample deletes itself 8->33 15 sync.arm7.elf 8->15         started        process6 process7 17 sync.arm7.elf 15->17         started       
SourceDetectionScannerLabelLink
sync.arm7.elf45%VirustotalBrowse
sync.arm7.elf61%ReversingLabsLinux.Backdoor.Mirai
sync.arm7.elf100%AviraANDROID/AVE.Agent.xdjci
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
dnsresolve.socialgains.cf
unknown
unknowntrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    34.249.145.219
    unknownUnited States
    16509AMAZON-02USfalse
    142.44.232.40
    unknownCanada
    16276OVHFRfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    34.249.145.219na.elfGet hashmaliciousPrometeiBrowse
      boatnet.arm6.elfGet hashmaliciousMiraiBrowse
        NewAge3ATOmpsl.elfGet hashmaliciousUnknownBrowse
          NewAge3ATOx86.elfGet hashmaliciousUnknownBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    zerarm5.elfGet hashmaliciousUnknownBrowse
                      zerm68k.elfGet hashmaliciousUnknownBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            re.bot.mpsl.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    arm-20250314-0007.elfGet hashmaliciousMiraiBrowse
                                      zBOVQFssy2.elfGet hashmaliciousUnknownBrowse
                                        bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                          bot.arm.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                            • 185.125.190.26
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            re.bot.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            arm-20250314-0007.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            zBOVQFssy2.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            re.bot.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            arm-20250314-0007.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            zBOVQFssy2.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            bot.arm.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                            • 109.202.202.202
                                            AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.171.230.55
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.255.164.76
                                            https://uphlold-llogijn.godaddysites.com/Get hashmaliciousUnknownBrowse
                                            • 13.248.243.5
                                            Synapse X (Cracked By Henri) (1).exeGet hashmaliciousUnknownBrowse
                                            • 52.216.52.64
                                            OVHFRgeneral2.exeGet hashmaliciousXWormBrowse
                                            • 91.134.10.182
                                            https://hospitalnews.com/paramedics-in-six-provinces-to-provide-palliative-care-in-the-home/Get hashmaliciousUnknownBrowse
                                            • 198.100.159.124
                                            faktura_FV2025020660849.htmlGet hashmaliciousUnknownBrowse
                                            • 54.39.128.117
                                            AAHiVVNIKQESryT.exeGet hashmaliciousFormBookBrowse
                                            • 51.222.255.207
                                            http://observalgerie.comGet hashmaliciousCAPTCHA Scam ClickFixBrowse
                                            • 37.59.22.41
                                            https://saleemitraders.com/wp/confirm.htmlGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                            • 158.69.25.207
                                            faktura_FV2025020637756.htmlGet hashmaliciousUnknownBrowse
                                            • 149.56.240.129
                                            https://sceanmcommnunmnlty.com/xroea/spwoe/zxiweGet hashmaliciousUnknownBrowse
                                            • 91.134.10.168
                                            http://feirao2025.com.br/consulta/Get hashmaliciousUnknownBrowse
                                            • 91.134.60.128
                                            miori.arm.elfGet hashmaliciousUnknownBrowse
                                            • 142.44.221.81
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):6.09255647319265
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:sync.arm7.elf
                                            File size:87'572 bytes
                                            MD5:8a6109d58a08dd6e18e72999fdea5e7e
                                            SHA1:e33eb5d16a428ef6693aba34336ffa43a800b644
                                            SHA256:597e16b001de0eefc8eee2ebcfb53e6c670f94c4fdc42ded8f5e42d7ec25c76b
                                            SHA512:673737b695986faa4104aadb40771c3f01c1278863510f96fda741dd6be4fff1757b1d370e03760979980652f80d3f59c5df37d1305b6b9302ab514efabd58d1
                                            SSDEEP:1536:/An2B7KrKPKwKKKuK1xbCTkwImwSIgcp7MawRNLm5S/dlj3iall/nh6Y79a5f:57KrKPKwKKKuK1gImrIT7MawRNLmUHl+
                                            TLSH:3D83394AF8816B11D4D526BEFE0E1289335347BDE3EE7112DE244B2037DAA6B0F76512
                                            File Content Preview:.ELF..............(.........4....S......4. ...(........pPM..P...P...................................hN..hN...............P...P...P..H....................P...P...P..................Q.td..................................-...L..................@-.,@...0....S

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:ARM
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x8194
                                            Flags:0x4000002
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:5
                                            Section Header Offset:86972
                                            Section Header Size:40
                                            Number of Section Headers:15
                                            Header String Table Index:14
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x80d40xd40x100x00x6AX004
                                            .textPROGBITS0x80f00xf00x130e00x00x6AX0016
                                            .finiPROGBITS0x1b1d00x131d00x100x00x6AX004
                                            .rodataPROGBITS0x1b1e00x131e00x1b580x00x2A008
                                            .ARM.extabPROGBITS0x1cd380x14d380x180x00x2A004
                                            .ARM.exidxARM_EXIDX0x1cd500x14d500x1180x00x82AL204
                                            .eh_framePROGBITS0x250000x150000x40x00x3WA004
                                            .tbssNOBITS0x250040x150040x80x00x403WAT004
                                            .init_arrayINIT_ARRAY0x250040x150040x40x00x3WA004
                                            .fini_arrayFINI_ARRAY0x250080x150080x40x00x3WA004
                                            .gotPROGBITS0x250100x150100xa80x40x3WA004
                                            .dataPROGBITS0x250b80x150b80x2900x00x3WA004
                                            .bssNOBITS0x253480x153480xb0940x00x3WA004
                                            .shstrtabSTRTAB0x00x153480x730x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            EXIDX0x14d500x1cd500x1cd500x1180x1184.51840x4R 0x4.ARM.exidx
                                            LOAD0x00x80000x80000x14e680x14e686.12330x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                                            LOAD0x150000x250000x250000x3480xb3dc4.74150x6RW 0x8000.eh_frame .tbss .init_array .fini_array .got .data .bss
                                            TLS0x150040x250040x250040x00x80.00000x4R 0x4.tbss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                            Download Network PCAP: filteredfull

                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2025-03-14T01:49:20.682155+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.23606478.8.8.853UDP
                                            • Total Packets: 71
                                            • 61003 undefined
                                            • 443 (HTTPS)
                                            • 80 (HTTP)
                                            • 53 (DNS)
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 14, 2025 01:48:39.246177912 CET43928443192.168.2.2391.189.91.42
                                            Mar 14, 2025 01:48:51.820359945 CET4433925634.249.145.219192.168.2.23
                                            Mar 14, 2025 01:48:51.820664883 CET39256443192.168.2.2334.249.145.219
                                            Mar 14, 2025 01:48:51.825330973 CET4433925634.249.145.219192.168.2.23
                                            Mar 14, 2025 01:48:54.996675014 CET5578261003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:48:55.001435041 CET6100355782142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:48:55.001497030 CET5578261003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:48:55.001600981 CET5578261003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:48:55.006275892 CET6100355782142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:48:55.627985001 CET4251680192.168.2.23109.202.202.202
                                            Mar 14, 2025 01:48:59.723351002 CET43928443192.168.2.2391.189.91.42
                                            Mar 14, 2025 01:49:16.379539013 CET6100355782142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:49:16.380043030 CET5578261003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:49:16.384747982 CET6100355782142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:49:33.292141914 CET5578461003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:49:33.297003984 CET6100355784142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:49:33.297136068 CET5578461003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:49:33.297136068 CET5578461003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:49:33.301815987 CET6100355784142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:49:40.677731037 CET43928443192.168.2.2391.189.91.42
                                            Mar 14, 2025 01:49:54.679085970 CET6100355784142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:49:54.679287910 CET5578461003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:49:54.684067011 CET6100355784142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:50:11.527545929 CET5578661003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:50:11.532357931 CET6100355786142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:50:11.532423019 CET5578661003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:50:11.532449007 CET5578661003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:50:11.537201881 CET6100355786142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:50:32.916548967 CET6100355786142.44.232.40192.168.2.23
                                            Mar 14, 2025 01:50:32.917330027 CET5578661003192.168.2.23142.44.232.40
                                            Mar 14, 2025 01:50:32.922055006 CET6100355786142.44.232.40192.168.2.23
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 14, 2025 01:48:39.134820938 CET5555353192.168.2.231.0.0.1
                                            Mar 14, 2025 01:48:39.236597061 CET53555531.0.0.1192.168.2.23
                                            Mar 14, 2025 01:48:40.239078045 CET4134653192.168.2.238.8.8.8
                                            Mar 14, 2025 01:48:40.254486084 CET53413468.8.8.8192.168.2.23
                                            Mar 14, 2025 01:48:41.256154060 CET4294853192.168.2.231.0.0.1
                                            Mar 14, 2025 01:48:41.281104088 CET53429481.0.0.1192.168.2.23
                                            Mar 14, 2025 01:48:42.283035994 CET5349753192.168.2.231.0.0.1
                                            Mar 14, 2025 01:48:42.415119886 CET53534971.0.0.1192.168.2.23
                                            Mar 14, 2025 01:48:43.417748928 CET5339553192.168.2.238.8.4.4
                                            Mar 14, 2025 01:48:43.444219112 CET53533958.8.4.4192.168.2.23
                                            Mar 14, 2025 01:48:44.446897984 CET4873453192.168.2.238.8.4.4
                                            Mar 14, 2025 01:48:44.462861061 CET53487348.8.4.4192.168.2.23
                                            Mar 14, 2025 01:48:45.464740992 CET5260253192.168.2.238.8.8.8
                                            Mar 14, 2025 01:48:45.480025053 CET53526028.8.8.8192.168.2.23
                                            Mar 14, 2025 01:48:46.481627941 CET4170353192.168.2.231.1.1.1
                                            Mar 14, 2025 01:48:46.506474018 CET53417031.1.1.1192.168.2.23
                                            Mar 14, 2025 01:48:47.507992029 CET4620253192.168.2.231.0.0.1
                                            Mar 14, 2025 01:48:47.647207975 CET53462021.0.0.1192.168.2.23
                                            Mar 14, 2025 01:48:48.648840904 CET4236753192.168.2.231.1.1.1
                                            Mar 14, 2025 01:48:48.673717022 CET53423671.1.1.1192.168.2.23
                                            Mar 14, 2025 01:48:49.675889015 CET4868553192.168.2.231.1.1.1
                                            Mar 14, 2025 01:48:49.777173042 CET53486851.1.1.1192.168.2.23
                                            Mar 14, 2025 01:48:50.780131102 CET5613853192.168.2.238.8.8.8
                                            Mar 14, 2025 01:48:50.795197010 CET53561388.8.8.8192.168.2.23
                                            Mar 14, 2025 01:48:51.796993017 CET3843653192.168.2.238.8.4.4
                                            Mar 14, 2025 01:48:51.825294971 CET53384368.8.4.4192.168.2.23
                                            Mar 14, 2025 01:48:52.829308987 CET4063053192.168.2.238.8.4.4
                                            Mar 14, 2025 01:48:52.855660915 CET53406308.8.4.4192.168.2.23
                                            Mar 14, 2025 01:48:53.858429909 CET3308753192.168.2.231.0.0.1
                                            Mar 14, 2025 01:48:53.994760036 CET53330871.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:17.382390022 CET5160453192.168.2.231.0.0.1
                                            Mar 14, 2025 01:49:17.406884909 CET53516041.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:18.408164978 CET3528653192.168.2.231.0.0.1
                                            Mar 14, 2025 01:49:18.544640064 CET53352861.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:19.547591925 CET3889453192.168.2.231.0.0.1
                                            Mar 14, 2025 01:49:19.679615021 CET53388941.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:20.682154894 CET6064753192.168.2.238.8.8.8
                                            Mar 14, 2025 01:49:20.696975946 CET53606478.8.8.8192.168.2.23
                                            Mar 14, 2025 01:49:21.698385000 CET5721753192.168.2.231.1.1.1
                                            Mar 14, 2025 01:49:21.801558018 CET53572171.1.1.1192.168.2.23
                                            Mar 14, 2025 01:49:22.802974939 CET4535653192.168.2.231.1.1.1
                                            Mar 14, 2025 01:49:22.827456951 CET53453561.1.1.1192.168.2.23
                                            Mar 14, 2025 01:49:23.828758001 CET4841553192.168.2.231.1.1.1
                                            Mar 14, 2025 01:49:23.933381081 CET53484151.1.1.1192.168.2.23
                                            Mar 14, 2025 01:49:24.934823036 CET4447653192.168.2.238.8.8.8
                                            Mar 14, 2025 01:49:25.070182085 CET53444768.8.8.8192.168.2.23
                                            Mar 14, 2025 01:49:26.072407961 CET5849053192.168.2.231.0.0.1
                                            Mar 14, 2025 01:49:26.176239014 CET53584901.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:27.178355932 CET3948253192.168.2.238.8.8.8
                                            Mar 14, 2025 01:49:27.193649054 CET53394828.8.8.8192.168.2.23
                                            Mar 14, 2025 01:49:28.195244074 CET5469553192.168.2.238.8.4.4
                                            Mar 14, 2025 01:49:28.210820913 CET53546958.8.4.4192.168.2.23
                                            Mar 14, 2025 01:49:29.212079048 CET4355653192.168.2.238.8.4.4
                                            Mar 14, 2025 01:49:29.227672100 CET53435568.8.4.4192.168.2.23
                                            Mar 14, 2025 01:49:30.230143070 CET5874953192.168.2.238.8.8.8
                                            Mar 14, 2025 01:49:30.244966030 CET53587498.8.8.8192.168.2.23
                                            Mar 14, 2025 01:49:31.246786118 CET4654553192.168.2.231.0.0.1
                                            Mar 14, 2025 01:49:31.271733999 CET53465451.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:32.273381948 CET3318053192.168.2.238.8.8.8
                                            Mar 14, 2025 01:49:32.290241957 CET53331808.8.8.8192.168.2.23
                                            Mar 14, 2025 01:49:55.681885004 CET5922653192.168.2.238.8.8.8
                                            Mar 14, 2025 01:49:55.697074890 CET53592268.8.8.8192.168.2.23
                                            Mar 14, 2025 01:49:56.699244976 CET4508153192.168.2.231.1.1.1
                                            Mar 14, 2025 01:49:56.818214893 CET53450811.1.1.1192.168.2.23
                                            Mar 14, 2025 01:49:57.820002079 CET4232753192.168.2.231.0.0.1
                                            Mar 14, 2025 01:49:57.844325066 CET53423271.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:58.846312046 CET3367453192.168.2.231.0.0.1
                                            Mar 14, 2025 01:49:58.965168953 CET53336741.0.0.1192.168.2.23
                                            Mar 14, 2025 01:49:59.967566967 CET3876153192.168.2.238.8.4.4
                                            Mar 14, 2025 01:49:59.982523918 CET53387618.8.4.4192.168.2.23
                                            Mar 14, 2025 01:50:00.984344959 CET3668353192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:01.015083075 CET53366831.1.1.1192.168.2.23
                                            Mar 14, 2025 01:50:02.016998053 CET5328853192.168.2.231.0.0.1
                                            Mar 14, 2025 01:50:02.051023960 CET53532881.0.0.1192.168.2.23
                                            Mar 14, 2025 01:50:03.052995920 CET5093353192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:03.171473026 CET53509331.1.1.1192.168.2.23
                                            Mar 14, 2025 01:50:04.173093081 CET4603053192.168.2.231.0.0.1
                                            Mar 14, 2025 01:50:04.278285980 CET53460301.0.0.1192.168.2.23
                                            Mar 14, 2025 01:50:05.279972076 CET3745453192.168.2.238.8.4.4
                                            Mar 14, 2025 01:50:05.295125961 CET53374548.8.4.4192.168.2.23
                                            Mar 14, 2025 01:50:06.296962023 CET4301153192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:06.321554899 CET53430111.1.1.1192.168.2.23
                                            Mar 14, 2025 01:50:07.323278904 CET4686653192.168.2.238.8.8.8
                                            Mar 14, 2025 01:50:07.369757891 CET53468668.8.8.8192.168.2.23
                                            Mar 14, 2025 01:50:08.371293068 CET5708153192.168.2.238.8.8.8
                                            Mar 14, 2025 01:50:08.386274099 CET53570818.8.8.8192.168.2.23
                                            Mar 14, 2025 01:50:09.387614965 CET3651853192.168.2.238.8.8.8
                                            Mar 14, 2025 01:50:09.403037071 CET53365188.8.8.8192.168.2.23
                                            Mar 14, 2025 01:50:10.404441118 CET4705253192.168.2.231.0.0.1
                                            Mar 14, 2025 01:50:10.526216030 CET53470521.0.0.1192.168.2.23
                                            Mar 14, 2025 01:50:33.919358015 CET5213253192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:33.944494963 CET53521321.1.1.1192.168.2.23
                                            Mar 14, 2025 01:50:34.945955038 CET4479653192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:35.083549976 CET53447961.1.1.1192.168.2.23
                                            Mar 14, 2025 01:50:36.085597038 CET5701253192.168.2.238.8.4.4
                                            Mar 14, 2025 01:50:36.100718975 CET53570128.8.4.4192.168.2.23
                                            Mar 14, 2025 01:50:37.102365971 CET3397053192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:37.230719090 CET53339701.1.1.1192.168.2.23
                                            Mar 14, 2025 01:50:38.232395887 CET5480753192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:38.371865988 CET53548071.1.1.1192.168.2.23
                                            Mar 14, 2025 01:50:39.373466015 CET3295953192.168.2.238.8.8.8
                                            Mar 14, 2025 01:50:39.388720036 CET53329598.8.8.8192.168.2.23
                                            Mar 14, 2025 01:50:40.390295029 CET5787353192.168.2.231.0.0.1
                                            Mar 14, 2025 01:50:40.529112101 CET53578731.0.0.1192.168.2.23
                                            Mar 14, 2025 01:50:41.531939030 CET5584353192.168.2.238.8.8.8
                                            Mar 14, 2025 01:50:41.546344995 CET53558438.8.8.8192.168.2.23
                                            Mar 14, 2025 01:50:42.549210072 CET4897853192.168.2.231.1.1.1
                                            Mar 14, 2025 01:50:42.574299097 CET53489781.1.1.1192.168.2.23
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Mar 14, 2025 01:48:39.134820938 CET192.168.2.231.0.0.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:40.239078045 CET192.168.2.238.8.8.80xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:41.256154060 CET192.168.2.231.0.0.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:42.283035994 CET192.168.2.231.0.0.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:43.417748928 CET192.168.2.238.8.4.40xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:44.446897984 CET192.168.2.238.8.4.40xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:45.464740992 CET192.168.2.238.8.8.80xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:46.481627941 CET192.168.2.231.1.1.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:47.507992029 CET192.168.2.231.0.0.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:48.648840904 CET192.168.2.231.1.1.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:49.675889015 CET192.168.2.231.1.1.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:50.780131102 CET192.168.2.238.8.8.80xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:51.796993017 CET192.168.2.238.8.4.40xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:52.829308987 CET192.168.2.238.8.4.40xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:48:53.858429909 CET192.168.2.231.0.0.10xd490Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:17.382390022 CET192.168.2.231.0.0.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:18.408164978 CET192.168.2.231.0.0.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:19.547591925 CET192.168.2.231.0.0.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:20.682154894 CET192.168.2.238.8.8.80x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:21.698385000 CET192.168.2.231.1.1.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:22.802974939 CET192.168.2.231.1.1.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:23.828758001 CET192.168.2.231.1.1.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:24.934823036 CET192.168.2.238.8.8.80x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:26.072407961 CET192.168.2.231.0.0.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:27.178355932 CET192.168.2.238.8.8.80x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:28.195244074 CET192.168.2.238.8.4.40x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:29.212079048 CET192.168.2.238.8.4.40x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:30.230143070 CET192.168.2.238.8.8.80x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:31.246786118 CET192.168.2.231.0.0.10x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:32.273381948 CET192.168.2.238.8.8.80x694fStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:55.681885004 CET192.168.2.238.8.8.80x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:56.699244976 CET192.168.2.231.1.1.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:57.820002079 CET192.168.2.231.0.0.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:58.846312046 CET192.168.2.231.0.0.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:49:59.967566967 CET192.168.2.238.8.4.40x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:00.984344959 CET192.168.2.231.1.1.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:02.016998053 CET192.168.2.231.0.0.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:03.052995920 CET192.168.2.231.1.1.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:04.173093081 CET192.168.2.231.0.0.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:05.279972076 CET192.168.2.238.8.4.40x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:06.296962023 CET192.168.2.231.1.1.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:07.323278904 CET192.168.2.238.8.8.80x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:08.371293068 CET192.168.2.238.8.8.80x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:09.387614965 CET192.168.2.238.8.8.80x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:10.404441118 CET192.168.2.231.0.0.10x3c6eStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:33.919358015 CET192.168.2.231.1.1.10xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:34.945955038 CET192.168.2.231.1.1.10xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:36.085597038 CET192.168.2.238.8.4.40xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:37.102365971 CET192.168.2.231.1.1.10xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:38.232395887 CET192.168.2.231.1.1.10xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:39.373466015 CET192.168.2.238.8.8.80xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:40.390295029 CET192.168.2.231.0.0.10xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:41.531939030 CET192.168.2.238.8.8.80xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 14, 2025 01:50:42.549210072 CET192.168.2.231.1.1.10xc7e8Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Mar 14, 2025 01:48:39.236597061 CET1.0.0.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:40.254486084 CET8.8.8.8192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:41.281104088 CET1.0.0.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:42.415119886 CET1.0.0.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:43.444219112 CET8.8.4.4192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:44.462861061 CET8.8.4.4192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:45.480025053 CET8.8.8.8192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:46.506474018 CET1.1.1.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:47.647207975 CET1.0.0.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:48.673717022 CET1.1.1.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:49.777173042 CET1.1.1.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:50.795197010 CET8.8.8.8192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:51.825294971 CET8.8.4.4192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:52.855660915 CET8.8.4.4192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:48:53.994760036 CET1.0.0.1192.168.2.230xd490Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:17.406884909 CET1.0.0.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:18.544640064 CET1.0.0.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:19.679615021 CET1.0.0.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:20.696975946 CET8.8.8.8192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:21.801558018 CET1.1.1.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:22.827456951 CET1.1.1.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:23.933381081 CET1.1.1.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:25.070182085 CET8.8.8.8192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:26.176239014 CET1.0.0.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:27.193649054 CET8.8.8.8192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:28.210820913 CET8.8.4.4192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:29.227672100 CET8.8.4.4192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:30.244966030 CET8.8.8.8192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:31.271733999 CET1.0.0.1192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:32.290241957 CET8.8.8.8192.168.2.230x694fName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:55.697074890 CET8.8.8.8192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:56.818214893 CET1.1.1.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:57.844325066 CET1.0.0.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:58.965168953 CET1.0.0.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:49:59.982523918 CET8.8.4.4192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:01.015083075 CET1.1.1.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:02.051023960 CET1.0.0.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:03.171473026 CET1.1.1.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:04.278285980 CET1.0.0.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:05.295125961 CET8.8.4.4192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:06.321554899 CET1.1.1.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:07.369757891 CET8.8.8.8192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:08.386274099 CET8.8.8.8192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:09.403037071 CET8.8.8.8192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:10.526216030 CET1.0.0.1192.168.2.230x3c6eName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:33.944494963 CET1.1.1.1192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:35.083549976 CET1.1.1.1192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:36.100718975 CET8.8.4.4192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:37.230719090 CET1.1.1.1192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:38.371865988 CET1.1.1.1192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:39.388720036 CET8.8.8.8192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:40.529112101 CET1.0.0.1192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:41.546344995 CET8.8.8.8192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 14, 2025 01:50:42.574299097 CET1.1.1.1192.168.2.230xc7e8Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):00:48:38
                                            Start date (UTC):14/03/2025
                                            Path:/tmp/sync.arm7.elf
                                            Arguments:/tmp/sync.arm7.elf
                                            File size:4956856 bytes
                                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                            Start time (UTC):00:48:38
                                            Start date (UTC):14/03/2025
                                            Path:/tmp/sync.arm7.elf
                                            Arguments:-
                                            File size:4956856 bytes
                                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                            Start time (UTC):00:48:38
                                            Start date (UTC):14/03/2025
                                            Path:/tmp/sync.arm7.elf
                                            Arguments:-
                                            File size:4956856 bytes
                                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                            Start time (UTC):00:48:51
                                            Start date (UTC):14/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):00:48:51
                                            Start date (UTC):14/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.8qFPUqxga1 /tmp/tmp.KKoCOey2qq /tmp/tmp.Ik5SJzv8Ic
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):00:48:51
                                            Start date (UTC):14/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):00:48:51
                                            Start date (UTC):14/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.8qFPUqxga1 /tmp/tmp.KKoCOey2qq /tmp/tmp.Ik5SJzv8Ic
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b