Edit tour

Linux Analysis Report
sync.mipsel.elf

Overview

General Information

Sample name:sync.mipsel.elf
Analysis ID:1641102
MD5:0036ff2dc20833bd6d68b91133c42dd3
SHA1:ddff8d1e9ffd66593e5b99e01373ccdd70b7c070
SHA256:03b671c86d3f9abb797a7f082c7ea09a80be49bdc3ad54bb4706a1ac8a210b07
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Performs DNS TXT record lookups
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1641102
Start date and time:2025-03-18 03:02:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sync.mipsel.elf
Detection:MAL
Classification:mal64.evad.linELF@0/0@15/0
Command:/tmp/sync.mipsel.elf
PID:6250
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
syncne
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6224, Parent: 4331)
  • rm (PID: 6224, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.HJfrEA19sO /tmp/tmp.uRHd3Dh9t3 /tmp/tmp.MBMwPN7LiV
  • dash New Fork (PID: 6225, Parent: 4331)
  • rm (PID: 6225, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.HJfrEA19sO /tmp/tmp.uRHd3Dh9t3 /tmp/tmp.MBMwPN7LiV
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:03:12.127116+010020135141A Network Trojan was detected192.168.2.23563201.0.0.153UDP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:04:13.415328+010028486071Malware Command and Control Activity Detected185.194.205.7961003192.168.2.2339474TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:04:13.205531+010028486061Malware Command and Control Activity Detected192.168.2.2339474185.194.205.7961003TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sync.mipsel.elfVirustotal: Detection: 45%Perma Link
Source: sync.mipsel.elfReversingLabs: Detection: 44%

Networking

barindex
Source: Network trafficSuricata IDS: 2848606 - Severity 1 - ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Outbound) : 192.168.2.23:39474 -> 185.194.205.79:61003
Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.23:56320 -> 1.0.0.1:53
Source: Network trafficSuricata IDS: 2848607 - Severity 1 - ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Inbound) : 185.194.205.79:61003 -> 192.168.2.23:39474
Source: global trafficTCP traffic: 192.168.2.23:39474 -> 185.194.205.79:61003
Source: unknownDNS traffic detected: query: dnsresolve.socialgains.cf replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: global trafficDNS traffic detected: DNS query: dnsresolve.socialgains.cf
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal64.evad.linELF@0/0@15/0
Source: /usr/bin/dash (PID: 6224)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.HJfrEA19sO /tmp/tmp.uRHd3Dh9t3 /tmp/tmp.MBMwPN7LiVJump to behavior
Source: /usr/bin/dash (PID: 6225)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.HJfrEA19sO /tmp/tmp.uRHd3Dh9t3 /tmp/tmp.MBMwPN7LiVJump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/sync.mipsel.elf (PID: 6250)File: /tmp/sync.mipsel.elfJump to behavior
Source: /tmp/sync.mipsel.elf (PID: 6254)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.mipsel.elf (PID: 6254)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.mipsel.elf (PID: 6250)Queries kernel information via 'uname': Jump to behavior
Source: sync.mipsel.elf, 6250.1.00007ffc59320000.00007ffc59341000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/sync.mipsel.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sync.mipsel.elf
Source: sync.mipsel.elf, 6250.1.000055cbcc352000.000055cbcc3d9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: sync.mipsel.elf, 6250.1.000055cbcc352000.000055cbcc3d9000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: sync.mipsel.elf, 6250.1.00007ffc59320000.00007ffc59341000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1641102 Sample: sync.mipsel.elf Startdate: 18/03/2025 Architecture: LINUX Score: 64 17 dnsresolve.socialgains.cf 2->17 19 185.194.205.79, 39474, 61003 HTSENSEFR France 2->19 21 4 other IPs or domains 2->21 23 Suricata IDS alerts for network traffic 2->23 25 Multi AV Scanner detection for submitted file 2->25 8 dash rm sync.mipsel.elf 2->8         started        11 dash rm 2->11         started        signatures3 27 Performs DNS TXT record lookups 17->27 process4 signatures5 29 Sample deletes itself 8->29 13 sync.mipsel.elf 8->13         started        process6 process7 15 sync.mipsel.elf 13->15         started       
SourceDetectionScannerLabelLink
sync.mipsel.elf45%VirustotalBrowse
sync.mipsel.elf44%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
dnsresolve.socialgains.cf
unknown
unknownfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    54.171.230.55
    unknownUnited States
    16509AMAZON-02USfalse
    185.194.205.79
    unknownFrance
    204145HTSENSEFRtrue
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    54.171.230.55na.elfGet hashmaliciousPrometeiBrowse
      main_mips.elfGet hashmaliciousMiraiBrowse
        na.elfGet hashmaliciousPrometeiBrowse
          na.elfGet hashmaliciousPrometeiBrowse
            na.elfGet hashmaliciousPrometeiBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                na.elfGet hashmaliciousPrometeiBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    na.elfGet hashmaliciousPrometeiBrowse
                      hgfs.arm6.elfGet hashmaliciousUnknownBrowse
                        185.194.205.79sync.arm5.elfGet hashmaliciousUnknownBrowse
                          sync.arm4.elfGet hashmaliciousUnknownBrowse
                            sync.x86_64.elfGet hashmaliciousUnknownBrowse
                              sync.arm4.elfGet hashmaliciousUnknownBrowse
                                sync.sh4.elfGet hashmaliciousUnknownBrowse
                                  sync.x86.elfGet hashmaliciousUnknownBrowse
                                    sync.x86.elfGet hashmaliciousUnknownBrowse
                                      sync.sh4.elfGet hashmaliciousUnknownBrowse
                                        sync.arm5.elfGet hashmaliciousUnknownBrowse
                                          sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 34.249.145.219
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 54.171.230.55
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 52.43.119.120
                                            HTSENSEFRsync.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.arm4.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.arm4.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.x86.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.x86.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 185.194.205.79
                                            INIT7CHsync.arm6.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            sync.mips.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            gigab.mips.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.452172182068348
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:sync.mipsel.elf
                                            File size:80'444 bytes
                                            MD5:0036ff2dc20833bd6d68b91133c42dd3
                                            SHA1:ddff8d1e9ffd66593e5b99e01373ccdd70b7c070
                                            SHA256:03b671c86d3f9abb797a7f082c7ea09a80be49bdc3ad54bb4706a1ac8a210b07
                                            SHA512:cf24e938fc65a0a69896f789399987b5a57b95da3f610cf579fbb67f1ea56e51844c5fae46a9cd87cd740f8bab5b8e375cc145f62b4ef0a2f5b1ce2d5e83a176
                                            SSDEEP:768:Wdf2Adf+Z75g8/2eiaW1tDqYaZYhJdepwWey+XfZXOLw34PvMZ151Xixg9Q9ewTN:tng81m1tiYh/8wWCvD8MZ15zQ9jToos
                                            TLSH:CE73A71AEFA10FEBE86FCD3305B85B0535CC690A12B53B757A38CD18B65B14B46E3864
                                            File Content Preview:.ELF....................`.@.4...\8......4. ...(...............@...@.p)..p)...............0...0E..0E..... ...........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<x..'!.............9

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:79964
                                            Section Header Size:40
                                            Number of Section Headers:12
                                            Header String Table Index:11
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200x10bf00x00x6AX0016
                                            .finiPROGBITS0x410d100x10d100x5c0x00x6AX004
                                            .rodataPROGBITS0x410d700x10d700x1c000x00x2A0016
                                            .ctorsPROGBITS0x4530000x130000x80x00x3WA004
                                            .dtorsPROGBITS0x4530080x130080x80x00x3WA004
                                            .dataPROGBITS0x4530200x130200x4500x00x3WA0016
                                            .gotPROGBITS0x4534700x134700x3a00x40x10000003WAp0016
                                            .sbssNOBITS0x4538100x138100xc0x00x10000003WAp004
                                            .bssNOBITS0x4538200x138100xa3000x00x3WA0016
                                            .shstrtabSTRTAB0x00x138100x490x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000x129700x129705.55420x5R E0x10000.init .text .fini .rodata
                                            LOAD0x130000x4530000x4530000x8100xab204.12550x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                            Download Network PCAP: filteredfull

                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2025-03-18T03:03:12.127116+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.23563201.0.0.153UDP
                                            2025-03-18T03:04:13.205531+01002848606ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Outbound)1192.168.2.2339474185.194.205.7961003TCP
                                            2025-03-18T03:04:13.415328+01002848607ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Inbound)1185.194.205.7961003192.168.2.2339474TCP
                                            • Total Packets: 28
                                            • 61003 undefined
                                            • 443 (HTTPS)
                                            • 80 (HTTP)
                                            • 53 (DNS)
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 18, 2025 03:02:56.786921024 CET4433360654.171.230.55192.168.2.23
                                            Mar 18, 2025 03:02:56.787163019 CET33606443192.168.2.2354.171.230.55
                                            Mar 18, 2025 03:02:56.791812897 CET4433360654.171.230.55192.168.2.23
                                            Mar 18, 2025 03:02:58.463331938 CET43928443192.168.2.2391.189.91.42
                                            Mar 18, 2025 03:03:03.838548899 CET42836443192.168.2.2391.189.91.43
                                            Mar 18, 2025 03:03:05.630409956 CET4251680192.168.2.23109.202.202.202
                                            Mar 18, 2025 03:03:13.153503895 CET3947461003192.168.2.23185.194.205.79
                                            Mar 18, 2025 03:03:13.159995079 CET6100339474185.194.205.79192.168.2.23
                                            Mar 18, 2025 03:03:13.160058022 CET3947461003192.168.2.23185.194.205.79
                                            Mar 18, 2025 03:03:13.160178900 CET3947461003192.168.2.23185.194.205.79
                                            Mar 18, 2025 03:03:13.166575909 CET6100339474185.194.205.79192.168.2.23
                                            Mar 18, 2025 03:03:18.940584898 CET43928443192.168.2.2391.189.91.42
                                            Mar 18, 2025 03:03:31.226805925 CET42836443192.168.2.2391.189.91.43
                                            Mar 18, 2025 03:03:35.322264910 CET4251680192.168.2.23109.202.202.202
                                            Mar 18, 2025 03:03:59.894860029 CET43928443192.168.2.2391.189.91.42
                                            Mar 18, 2025 03:04:13.205530882 CET3947461003192.168.2.23185.194.205.79
                                            Mar 18, 2025 03:04:13.210336924 CET6100339474185.194.205.79192.168.2.23
                                            Mar 18, 2025 03:04:13.415328026 CET6100339474185.194.205.79192.168.2.23
                                            Mar 18, 2025 03:04:13.415622950 CET3947461003192.168.2.23185.194.205.79
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 18, 2025 03:02:57.437158108 CET3816853192.168.2.231.0.0.1
                                            Mar 18, 2025 03:02:57.461148024 CET53381681.0.0.1192.168.2.23
                                            Mar 18, 2025 03:02:58.472497940 CET5346653192.168.2.238.8.4.4
                                            Mar 18, 2025 03:02:58.487277031 CET53534668.8.4.4192.168.2.23
                                            Mar 18, 2025 03:02:59.488776922 CET4355353192.168.2.231.1.1.1
                                            Mar 18, 2025 03:02:59.625919104 CET53435531.1.1.1192.168.2.23
                                            Mar 18, 2025 03:03:00.627764940 CET4580653192.168.2.238.8.8.8
                                            Mar 18, 2025 03:03:00.644531965 CET53458068.8.8.8192.168.2.23
                                            Mar 18, 2025 03:03:01.646234035 CET4448353192.168.2.238.8.8.8
                                            Mar 18, 2025 03:03:01.660887003 CET53444838.8.8.8192.168.2.23
                                            Mar 18, 2025 03:03:02.662684917 CET5440253192.168.2.231.1.1.1
                                            Mar 18, 2025 03:03:02.688534021 CET53544021.1.1.1192.168.2.23
                                            Mar 18, 2025 03:03:03.690248966 CET3835953192.168.2.238.8.8.8
                                            Mar 18, 2025 03:03:03.705607891 CET53383598.8.8.8192.168.2.23
                                            Mar 18, 2025 03:03:04.707333088 CET4321153192.168.2.231.1.1.1
                                            Mar 18, 2025 03:03:04.879375935 CET53432111.1.1.1192.168.2.23
                                            Mar 18, 2025 03:03:05.881892920 CET4556653192.168.2.238.8.8.8
                                            Mar 18, 2025 03:03:05.910355091 CET53455668.8.8.8192.168.2.23
                                            Mar 18, 2025 03:03:06.912343025 CET3600553192.168.2.238.8.8.8
                                            Mar 18, 2025 03:03:06.927660942 CET53360058.8.8.8192.168.2.23
                                            Mar 18, 2025 03:03:07.930025101 CET6004553192.168.2.238.8.8.8
                                            Mar 18, 2025 03:03:07.958844900 CET53600458.8.8.8192.168.2.23
                                            Mar 18, 2025 03:03:08.961289883 CET4484053192.168.2.238.8.4.4
                                            Mar 18, 2025 03:03:08.976696968 CET53448408.8.4.4192.168.2.23
                                            Mar 18, 2025 03:03:09.979074955 CET5283653192.168.2.231.1.1.1
                                            Mar 18, 2025 03:03:10.097407103 CET53528361.1.1.1192.168.2.23
                                            Mar 18, 2025 03:03:11.100162983 CET4266753192.168.2.231.1.1.1
                                            Mar 18, 2025 03:03:11.125238895 CET53426671.1.1.1192.168.2.23
                                            Mar 18, 2025 03:03:12.127115965 CET5632053192.168.2.231.0.0.1
                                            Mar 18, 2025 03:03:12.151385069 CET53563201.0.0.1192.168.2.23
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Mar 18, 2025 03:02:57.437158108 CET192.168.2.231.0.0.10xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:02:58.472497940 CET192.168.2.238.8.4.40xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:02:59.488776922 CET192.168.2.231.1.1.10xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:00.627764940 CET192.168.2.238.8.8.80xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:01.646234035 CET192.168.2.238.8.8.80xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:02.662684917 CET192.168.2.231.1.1.10xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:03.690248966 CET192.168.2.238.8.8.80xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:04.707333088 CET192.168.2.231.1.1.10xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:05.881892920 CET192.168.2.238.8.8.80xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:06.912343025 CET192.168.2.238.8.8.80xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:07.930025101 CET192.168.2.238.8.8.80xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:08.961289883 CET192.168.2.238.8.4.40xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:09.979074955 CET192.168.2.231.1.1.10xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:11.100162983 CET192.168.2.231.1.1.10xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 18, 2025 03:03:12.127115965 CET192.168.2.231.0.0.10xfe44Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Mar 18, 2025 03:02:57.461148024 CET1.0.0.1192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:02:58.487277031 CET8.8.4.4192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:02:59.625919104 CET1.1.1.1192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:00.644531965 CET8.8.8.8192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:01.660887003 CET8.8.8.8192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:02.688534021 CET1.1.1.1192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:03.705607891 CET8.8.8.8192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:04.879375935 CET1.1.1.1192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:05.910355091 CET8.8.8.8192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:06.927660942 CET8.8.8.8192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:07.958844900 CET8.8.8.8192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:08.976696968 CET8.8.4.4192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:10.097407103 CET1.1.1.1192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:11.125238895 CET1.1.1.1192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 18, 2025 03:03:12.151385069 CET1.0.0.1192.168.2.230xfe44Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):02:02:56
                                            Start date (UTC):18/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):02:02:56
                                            Start date (UTC):18/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.HJfrEA19sO /tmp/tmp.uRHd3Dh9t3 /tmp/tmp.MBMwPN7LiV
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):02:02:56
                                            Start date (UTC):18/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):02:02:56
                                            Start date (UTC):18/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.HJfrEA19sO /tmp/tmp.uRHd3Dh9t3 /tmp/tmp.MBMwPN7LiV
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):02:02:56
                                            Start date (UTC):18/03/2025
                                            Path:/tmp/sync.mipsel.elf
                                            Arguments:/tmp/sync.mipsel.elf
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                            Start time (UTC):02:02:56
                                            Start date (UTC):18/03/2025
                                            Path:/tmp/sync.mipsel.elf
                                            Arguments:-
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                            Start time (UTC):02:02:56
                                            Start date (UTC):18/03/2025
                                            Path:/tmp/sync.mipsel.elf
                                            Arguments:-
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9