Edit tour

Linux Analysis Report
sync.arm4.elf

Overview

General Information

Sample name:sync.arm4.elf
Analysis ID:1641101
MD5:5e734310db8e36069032d1372a9e650f
SHA1:3d31a882302e829442e0b3851fe31c5c3268cd73
SHA256:8434b9fa406878e4122f418b7ae38391521e0fd83834b41ca0b01bf0f32ec1b3
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Performs DNS TXT record lookups
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1641101
Start date and time:2025-03-18 03:00:38 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 22s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sync.arm4.elf
Detection:MAL
Classification:mal64.evad.linELF@0/0@15/0
Command:/tmp/sync.arm4.elf
PID:5491
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
syncne
Standard Error:
  • system is lnxubuntu20
  • sync.arm4.elf (PID: 5491, Parent: 5415, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/sync.arm4.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:01:33.064498+010020135141A Network Trojan was detected192.168.2.14441651.0.0.153UDP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sync.arm4.elfVirustotal: Detection: 45%Perma Link
Source: sync.arm4.elfReversingLabs: Detection: 44%

Networking

barindex
Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.14:44165 -> 1.0.0.1:53
Source: global trafficTCP traffic: 192.168.2.14:60936 -> 185.194.205.79:61003
Source: unknownDNS traffic detected: query: dnsresolve.socialgains.cf replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: global trafficDNS traffic detected: DNS query: dnsresolve.socialgains.cf
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal64.evad.linELF@0/0@15/0

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/sync.arm4.elf (PID: 5491)File: /tmp/sync.arm4.elfJump to behavior
Source: /tmp/sync.arm4.elf (PID: 5495)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm4.elf (PID: 5495)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm4.elf (PID: 5491)Queries kernel information via 'uname': Jump to behavior
Source: sync.arm4.elf, 5491.1.00007ffe33be5000.00007ffe33c06000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/sync.arm4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sync.arm4.elf
Source: sync.arm4.elf, 5491.1.000056287782f000.000056287795d000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: sync.arm4.elf, 5491.1.00007ffe33be5000.00007ffe33c06000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: sync.arm4.elf, 5491.1.000056287782f000.000056287795d000.rw-.sdmpBinary or memory string: w(V!/etc/qemu-binfmt/arm

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1641101 Sample: sync.arm4.elf Startdate: 18/03/2025 Architecture: LINUX Score: 64 15 dnsresolve.socialgains.cf 2->15 17 185.194.205.79, 60936, 61003 HTSENSEFR France 2->17 19 Suricata IDS alerts for network traffic 2->19 21 Multi AV Scanner detection for submitted file 2->21 8 sync.arm4.elf 2->8         started        signatures3 23 Performs DNS TXT record lookups 15->23 process4 signatures5 25 Sample deletes itself 8->25 11 sync.arm4.elf 8->11         started        process6 process7 13 sync.arm4.elf 11->13         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
sync.arm4.elf45%VirustotalBrowse
sync.arm4.elf44%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
dnsresolve.socialgains.cf
unknown
unknownfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    185.194.205.79
    unknownFrance
    204145HTSENSEFRfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    185.194.205.79sync.x86_64.elfGet hashmaliciousUnknownBrowse
      sync.arm4.elfGet hashmaliciousUnknownBrowse
        sync.sh4.elfGet hashmaliciousUnknownBrowse
          sync.x86.elfGet hashmaliciousUnknownBrowse
            sync.x86.elfGet hashmaliciousUnknownBrowse
              sync.sh4.elfGet hashmaliciousUnknownBrowse
                sync.arm5.elfGet hashmaliciousUnknownBrowse
                  sync.x86_64.elfGet hashmaliciousUnknownBrowse
                    sync.mipsel.elfGet hashmaliciousUnknownBrowse
                      sync.superh.elfGet hashmaliciousUnknownBrowse
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        HTSENSEFRsync.x86_64.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.arm4.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.sh4.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.x86.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.x86.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.sh4.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.arm5.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.x86_64.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.mipsel.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        sync.superh.elfGet hashmaliciousUnknownBrowse
                        • 185.194.205.79
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                        Entropy (8bit):6.10662385165585
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:sync.arm4.elf
                        File size:63'792 bytes
                        MD5:5e734310db8e36069032d1372a9e650f
                        SHA1:3d31a882302e829442e0b3851fe31c5c3268cd73
                        SHA256:8434b9fa406878e4122f418b7ae38391521e0fd83834b41ca0b01bf0f32ec1b3
                        SHA512:2d9452f9f7c9c75ece3e96ab2aacf0ccd149c4a1541f54fa33332c88f3d8eee004794784ac9f82a4cff7a4782ca66ebb3405a7623fc546a5b755b19f747fd6c7
                        SSDEEP:1536:iAMS8H5eyaPqkHaSImTCmIFaWR4olo+7qxd5vEC:azHk6SImTC5QWRYE4EC
                        TLSH:D2535B52F8C2A213C5D45A76FA4F02CC371257E9E2DE3603CE294F6237AB56B0EA7511
                        File Content Preview:.ELF...a..........(.........4...........4. ...(.....................l...l...............p...p...p...................Q.td..................................-...L."....5..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:ARM
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:ARM - ABI
                        ABI Version:0
                        Entry Point Address:0x8190
                        Flags:0x202
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:3
                        Section Header Offset:63392
                        Section Header Size:40
                        Number of Section Headers:10
                        Header String Table Index:9
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x80940x940x180x00x6AX004
                        .textPROGBITS0x80b00xb00xd7f00x00x6AX0016
                        .finiPROGBITS0x158a00xd8a00x140x00x6AX004
                        .rodataPROGBITS0x158b40xd8b40x1ab80x00x2A004
                        .ctorsPROGBITS0x1f3700xf3700x80x00x3WA004
                        .dtorsPROGBITS0x1f3780xf3780x80x00x3WA004
                        .dataPROGBITS0x1f3840xf3840x3dc0x00x3WA004
                        .bssNOBITS0x1f7600xf7600xa2ac0x00x3WA004
                        .shstrtabSTRTAB0x00xf7600x3e0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x80000x80000xf36c0xf36c6.13750x5R E0x8000.init .text .fini .rodata
                        LOAD0xf3700x1f3700x1f3700x3f00xa69c3.53280x6RW 0x8000.ctors .dtors .data .bss
                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                        Download Network PCAP: filteredfull

                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                        2025-03-18T03:01:33.064498+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.14441651.0.0.153UDP
                        • Total Packets: 21
                        • 61003 undefined
                        • 53 (DNS)
                        TimestampSource PortDest PortSource IPDest IP
                        Mar 18, 2025 03:01:37.262191057 CET6093661003192.168.2.14185.194.205.79
                        Mar 18, 2025 03:01:37.267092943 CET6100360936185.194.205.79192.168.2.14
                        Mar 18, 2025 03:01:37.267189980 CET6093661003192.168.2.14185.194.205.79
                        Mar 18, 2025 03:01:38.274332047 CET6093661003192.168.2.14185.194.205.79
                        Mar 18, 2025 03:01:38.279166937 CET6100360936185.194.205.79192.168.2.14
                        Mar 18, 2025 03:01:38.279269934 CET6093661003192.168.2.14185.194.205.79
                        Mar 18, 2025 03:01:38.279439926 CET6093661003192.168.2.14185.194.205.79
                        Mar 18, 2025 03:01:38.284079075 CET6100360936185.194.205.79192.168.2.14
                        Mar 18, 2025 03:02:38.330485106 CET6093661003192.168.2.14185.194.205.79
                        Mar 18, 2025 03:02:38.335310936 CET6100360936185.194.205.79192.168.2.14
                        TimestampSource PortDest PortSource IPDest IP
                        Mar 18, 2025 03:01:20.813493967 CET3766853192.168.2.141.1.1.1
                        Mar 18, 2025 03:01:20.933434963 CET53376681.1.1.1192.168.2.14
                        Mar 18, 2025 03:01:21.936352968 CET3587253192.168.2.141.0.0.1
                        Mar 18, 2025 03:01:22.073039055 CET53358721.0.0.1192.168.2.14
                        Mar 18, 2025 03:01:23.075293064 CET5003053192.168.2.148.8.8.8
                        Mar 18, 2025 03:01:23.101413012 CET53500308.8.8.8192.168.2.14
                        Mar 18, 2025 03:01:24.103750944 CET3657253192.168.2.141.1.1.1
                        Mar 18, 2025 03:01:24.128459930 CET53365721.1.1.1192.168.2.14
                        Mar 18, 2025 03:01:25.130521059 CET3341053192.168.2.141.0.0.1
                        Mar 18, 2025 03:01:25.248120070 CET53334101.0.0.1192.168.2.14
                        Mar 18, 2025 03:01:26.250250101 CET4753753192.168.2.148.8.4.4
                        Mar 18, 2025 03:01:26.276056051 CET53475378.8.4.4192.168.2.14
                        Mar 18, 2025 03:01:27.278065920 CET4681753192.168.2.148.8.4.4
                        Mar 18, 2025 03:01:27.293414116 CET53468178.8.4.4192.168.2.14
                        Mar 18, 2025 03:01:28.295572042 CET3748053192.168.2.141.0.0.1
                        Mar 18, 2025 03:01:28.432346106 CET53374801.0.0.1192.168.2.14
                        Mar 18, 2025 03:01:29.434592009 CET4248253192.168.2.148.8.8.8
                        Mar 18, 2025 03:01:29.754686117 CET53424828.8.8.8192.168.2.14
                        Mar 18, 2025 03:01:30.757004023 CET5944453192.168.2.141.1.1.1
                        Mar 18, 2025 03:01:30.876632929 CET53594441.1.1.1192.168.2.14
                        Mar 18, 2025 03:01:31.878899097 CET5218753192.168.2.141.0.0.1
                        Mar 18, 2025 03:01:32.061697960 CET53521871.0.0.1192.168.2.14
                        Mar 18, 2025 03:01:33.064497948 CET4416553192.168.2.141.0.0.1
                        Mar 18, 2025 03:01:33.195985079 CET53441651.0.0.1192.168.2.14
                        Mar 18, 2025 03:01:34.198029041 CET5596853192.168.2.148.8.8.8
                        Mar 18, 2025 03:01:34.212656021 CET53559688.8.8.8192.168.2.14
                        Mar 18, 2025 03:01:35.215118885 CET4650053192.168.2.141.0.0.1
                        Mar 18, 2025 03:01:35.239940882 CET53465001.0.0.1192.168.2.14
                        Mar 18, 2025 03:01:36.242151022 CET5190953192.168.2.148.8.4.4
                        Mar 18, 2025 03:01:36.259350061 CET53519098.8.4.4192.168.2.14
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Mar 18, 2025 03:01:20.813493967 CET192.168.2.141.1.1.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:21.936352968 CET192.168.2.141.0.0.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:23.075293064 CET192.168.2.148.8.8.80x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:24.103750944 CET192.168.2.141.1.1.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:25.130521059 CET192.168.2.141.0.0.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:26.250250101 CET192.168.2.148.8.4.40x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:27.278065920 CET192.168.2.148.8.4.40x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:28.295572042 CET192.168.2.141.0.0.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:29.434592009 CET192.168.2.148.8.8.80x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:30.757004023 CET192.168.2.141.1.1.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:31.878899097 CET192.168.2.141.0.0.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:33.064497948 CET192.168.2.141.0.0.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:34.198029041 CET192.168.2.148.8.8.80x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:35.215118885 CET192.168.2.141.0.0.10x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        Mar 18, 2025 03:01:36.242151022 CET192.168.2.148.8.4.40x587dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Mar 18, 2025 03:01:20.933434963 CET1.1.1.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:22.073039055 CET1.0.0.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:23.101413012 CET8.8.8.8192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:24.128459930 CET1.1.1.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:25.248120070 CET1.0.0.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:26.276056051 CET8.8.4.4192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:27.293414116 CET8.8.4.4192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:28.432346106 CET1.0.0.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:29.754686117 CET8.8.8.8192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:30.876632929 CET1.1.1.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:32.061697960 CET1.0.0.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:33.195985079 CET1.0.0.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:34.212656021 CET8.8.8.8192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:35.239940882 CET1.0.0.1192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                        Mar 18, 2025 03:01:36.259350061 CET8.8.4.4192.168.2.140x587dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false

                        System Behavior

                        Start time (UTC):02:01:19
                        Start date (UTC):18/03/2025
                        Path:/tmp/sync.arm4.elf
                        Arguments:/tmp/sync.arm4.elf
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):02:01:20
                        Start date (UTC):18/03/2025
                        Path:/tmp/sync.arm4.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                        Start time (UTC):02:01:20
                        Start date (UTC):18/03/2025
                        Path:/tmp/sync.arm4.elf
                        Arguments:-
                        File size:4956856 bytes
                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1