Edit tour

Linux Analysis Report
sync.arm5.elf

Overview

General Information

Sample name:sync.arm5.elf
Analysis ID:1641114
MD5:d35b09a5ac572e68c54a79b7006edd73
SHA1:a3cbd57aceabec241cb09e82832a81d7aa3f30b7
SHA256:732db5ee5bc49949b0d1cdf60db159737a8cf60957d05078bd69e84ab9e53fba
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Performs DNS TXT record lookups
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1641114
Start date and time:2025-03-18 03:13:59 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 47s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sync.arm5.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@15/0
Command:/tmp/sync.arm5.elf
PID:6206
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6195, Parent: 4332)
  • rm (PID: 6195, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.xzj4haK40o /tmp/tmp.0TioHlCk4V /tmp/tmp.Tflw9bOXUP
  • dash New Fork (PID: 6196, Parent: 4332)
  • rm (PID: 6196, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.xzj4haK40o /tmp/tmp.0TioHlCk4V /tmp/tmp.Tflw9bOXUP
  • sync.arm5.elf (PID: 6206, Parent: 6122, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/sync.arm5.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:14:50.085560+010020135141A Network Trojan was detected192.168.2.23460021.1.1.153UDP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sync.arm5.elfVirustotal: Detection: 44%Perma Link
Source: sync.arm5.elfReversingLabs: Detection: 44%

Networking

barindex
Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.23:46002 -> 1.1.1.1:53
Source: global trafficTCP traffic: 192.168.2.23:39470 -> 185.194.205.79:61003
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownDNS traffic detected: query: dnsresolve.socialgains.cf replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: global trafficDNS traffic detected: DNS query: dnsresolve.socialgains.cf
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.evad.linELF@0/0@15/0
Source: /usr/bin/dash (PID: 6195)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.xzj4haK40o /tmp/tmp.0TioHlCk4V /tmp/tmp.Tflw9bOXUPJump to behavior
Source: /usr/bin/dash (PID: 6196)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.xzj4haK40o /tmp/tmp.0TioHlCk4V /tmp/tmp.Tflw9bOXUPJump to behavior
Source: /tmp/sync.arm5.elf (PID: 6208)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm5.elf (PID: 6208)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm5.elf (PID: 6206)Queries kernel information via 'uname': Jump to behavior
Source: sync.arm5.elf, 6206.1.00005634677cd000.000056346791c000.rw-.sdmpBinary or memory string: C~g4VPE~g4VPB~g4V!/etc/qemu-binfmt/arm
Source: sync.arm5.elf, 6206.1.00007ffcde16a000.00007ffcde18b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/sync.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sync.arm5.elf
Source: sync.arm5.elf, 6206.1.00005634677cd000.000056346791c000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: sync.arm5.elf, 6206.1.00007ffcde16a000.00007ffcde18b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1641114 Sample: sync.arm5.elf Startdate: 18/03/2025 Architecture: LINUX Score: 60 13 dnsresolve.socialgains.cf 2->13 15 109.202.202.202, 80 INIT7CH Switzerland 2->15 17 3 other IPs or domains 2->17 19 Suricata IDS alerts for network traffic 2->19 21 Multi AV Scanner detection for submitted file 2->21 7 dash rm sync.arm5.elf 2->7         started        9 dash rm 2->9         started        signatures3 23 Performs DNS TXT record lookups 13->23 process4 process5 11 sync.arm5.elf 7->11         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
sync.arm5.elf44%VirustotalBrowse
sync.arm5.elf44%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
dnsresolve.socialgains.cf
unknown
unknownfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    185.194.205.79
    unknownFrance
    204145HTSENSEFRfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    185.194.205.79sync.arm4.elfGet hashmaliciousUnknownBrowse
      sync.x86_64.elfGet hashmaliciousUnknownBrowse
        sync.sh4.elfGet hashmaliciousUnknownBrowse
          sync.superh.elfGet hashmaliciousUnknownBrowse
            sync.x86.elfGet hashmaliciousUnknownBrowse
              sync.superh.elfGet hashmaliciousUnknownBrowse
                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                  sync.arm5.elfGet hashmaliciousUnknownBrowse
                    sync.arm4.elfGet hashmaliciousUnknownBrowse
                      sync.x86_64.elfGet hashmaliciousUnknownBrowse
                        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                        91.189.91.43sync.x86_64.elfGet hashmaliciousUnknownBrowse
                          sync.x86.elfGet hashmaliciousUnknownBrowse
                            sync.mipsel.elfGet hashmaliciousUnknownBrowse
                              sync.arm6.elfGet hashmaliciousUnknownBrowse
                                sync.mips.elfGet hashmaliciousUnknownBrowse
                                  gigab.mips.elfGet hashmaliciousUnknownBrowse
                                    na.elfGet hashmaliciousPrometeiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        na.elfGet hashmaliciousPrometeiBrowse
                                          na.elfGet hashmaliciousPrometeiBrowse
                                            91.189.91.42sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                              sync.x86.elfGet hashmaliciousUnknownBrowse
                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                  sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                    sync.mips.elfGet hashmaliciousUnknownBrowse
                                                      gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                        na.elfGet hashmaliciousPrometeiBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBsync.sparc.elfGet hashmaliciousUnknownBrowse
                                                                • 185.125.190.26
                                                                sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 185.125.190.26
                                                                sync.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                CANONICAL-ASGBsync.sparc.elfGet hashmaliciousUnknownBrowse
                                                                • 185.125.190.26
                                                                sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 185.125.190.26
                                                                sync.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 91.189.91.42
                                                                HTSENSEFRsync.arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.sh4.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.superh.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.superh.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                INIT7CHsync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                                Entropy (8bit):6.174808171705935
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:sync.arm5.elf
                                                                File size:67'008 bytes
                                                                MD5:d35b09a5ac572e68c54a79b7006edd73
                                                                SHA1:a3cbd57aceabec241cb09e82832a81d7aa3f30b7
                                                                SHA256:732db5ee5bc49949b0d1cdf60db159737a8cf60957d05078bd69e84ab9e53fba
                                                                SHA512:86b2207f1712684f48e58bcaf752c3daf4578eeb8fd35282feeca107c159f8f2380579b3b6404eb097e4f00f4af605e92ef98a16128f5caf7c2c1ee7962fcf28
                                                                SSDEEP:768:m+xRFJeV/56/ZNSiiwzPlrYDIgMtM5Iv9wIVBnaD8kMOyZyxBLEdIRWn17AhkwG5:hRDbzPROdMy5Iv9wICOO2tdIUnehFG
                                                                TLSH:93635A52F9C1A212C0E01776FA4F4289732557A9E2EF3603DD298F3137EB56A0F97612
                                                                File Content Preview:.ELF...a..........(.........4...0.......4. ...(.....................................................................Q.td..................................-...L.".../5..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:ARM
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:ARM - ABI
                                                                ABI Version:0
                                                                Entry Point Address:0x8190
                                                                Flags:0x2
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:3
                                                                Section Header Offset:66608
                                                                Section Header Size:40
                                                                Number of Section Headers:10
                                                                Header String Table Index:9
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x80940x940x180x00x6AX004
                                                                .textPROGBITS0x80b00xb00xd4f40x00x6AX0016
                                                                .finiPROGBITS0x155a40xd5a40x140x00x6AX004
                                                                .rodataPROGBITS0x155b80xd5b80x290c0x00x2A004
                                                                .ctorsPROGBITS0x180000x100000x80x00x3WA004
                                                                .dtorsPROGBITS0x180080x100080x80x00x3WA004
                                                                .dataPROGBITS0x180140x100140x3dc0x00x3WA004
                                                                .bssNOBITS0x183f00x103f00xa2ac0x00x3WA004
                                                                .shstrtabSTRTAB0x00x103f00x3e0x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                LOAD0x00x80000x80000xfec40xfec46.22500x5R E0x8000.init .text .fini .rodata
                                                                LOAD0x100000x180000x180000x3f00xa69c3.49770x6RW 0x8000.ctors .dtors .data .bss
                                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                Download Network PCAP: filteredfull

                                                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                2025-03-18T03:14:50.085560+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.23460021.1.1.153UDP
                                                                • Total Packets: 27
                                                                • 61003 undefined
                                                                • 443 (HTTPS)
                                                                • 80 (HTTP)
                                                                • 53 (DNS)
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Mar 18, 2025 03:14:40.862452984 CET43928443192.168.2.2391.189.91.42
                                                                Mar 18, 2025 03:14:46.237754107 CET42836443192.168.2.2391.189.91.43
                                                                Mar 18, 2025 03:14:48.029496908 CET4251680192.168.2.23109.202.202.202
                                                                Mar 18, 2025 03:14:57.485276937 CET3947061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:14:57.490089893 CET6100339470185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:14:57.490245104 CET3947061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:14:57.490291119 CET3947061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:14:57.494983912 CET6100339470185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:15:02.619443893 CET43928443192.168.2.2391.189.91.42
                                                                Mar 18, 2025 03:15:12.858043909 CET42836443192.168.2.2391.189.91.43
                                                                Mar 18, 2025 03:15:19.001156092 CET4251680192.168.2.23109.202.202.202
                                                                Mar 18, 2025 03:15:26.483108997 CET3947061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:15:26.490405083 CET6100339470185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:15:26.490462065 CET3947061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:15:43.573787928 CET43928443192.168.2.2391.189.91.42
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Mar 18, 2025 03:14:41.461421013 CET3909253192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:14:41.598481894 CET53390921.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:14:42.600367069 CET5855053192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:14:42.628684044 CET53585508.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:14:43.630093098 CET5003053192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:14:43.666246891 CET53500308.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:14:44.667634010 CET4368253192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:14:44.683172941 CET53436828.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:14:45.684712887 CET5009653192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:14:45.699971914 CET53500968.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:14:46.701548100 CET3303553192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:14:47.024760962 CET53330351.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:14:48.026874065 CET4331053192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:14:48.055752993 CET53433108.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:14:49.058032990 CET4343353192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:14:49.083468914 CET53434331.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:14:50.085560083 CET4600253192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:14:50.223515034 CET53460021.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:14:51.225656986 CET5064153192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:14:51.253740072 CET53506418.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:14:52.255359888 CET5318553192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:14:52.279882908 CET53531851.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:14:53.282166958 CET4392453192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:14:53.412587881 CET53439241.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:14:54.414479017 CET5171453192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:14:54.439001083 CET53517141.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:14:55.440408945 CET5465653192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:14:55.456867933 CET53546568.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:14:56.458333969 CET5632053192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:14:56.483906984 CET53563208.8.8.8192.168.2.23
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Mar 18, 2025 03:14:41.461421013 CET192.168.2.231.0.0.10x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:42.600367069 CET192.168.2.238.8.4.40x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:43.630093098 CET192.168.2.238.8.8.80x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:44.667634010 CET192.168.2.238.8.4.40x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:45.684712887 CET192.168.2.238.8.8.80x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:46.701548100 CET192.168.2.231.0.0.10x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:48.026874065 CET192.168.2.238.8.4.40x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:49.058032990 CET192.168.2.231.0.0.10x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:50.085560083 CET192.168.2.231.1.1.10x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:51.225656986 CET192.168.2.238.8.4.40x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:52.255359888 CET192.168.2.231.0.0.10x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:53.282166958 CET192.168.2.231.1.1.10x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:54.414479017 CET192.168.2.231.0.0.10x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:55.440408945 CET192.168.2.238.8.4.40x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:14:56.458333969 CET192.168.2.238.8.8.80x8dbeStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Mar 18, 2025 03:14:41.598481894 CET1.0.0.1192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:42.628684044 CET8.8.4.4192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:43.666246891 CET8.8.8.8192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:44.683172941 CET8.8.4.4192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:45.699971914 CET8.8.8.8192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:47.024760962 CET1.0.0.1192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:48.055752993 CET8.8.4.4192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:49.083468914 CET1.0.0.1192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:50.223515034 CET1.1.1.1192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:51.253740072 CET8.8.4.4192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:52.279882908 CET1.0.0.1192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:53.412587881 CET1.1.1.1192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:54.439001083 CET1.0.0.1192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:55.456867933 CET8.8.4.4192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:14:56.483906984 CET8.8.8.8192.168.2.230x8dbeName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false

                                                                System Behavior

                                                                Start time (UTC):02:14:33
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):02:14:33
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.xzj4haK40o /tmp/tmp.0TioHlCk4V /tmp/tmp.Tflw9bOXUP
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):02:14:33
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):02:14:33
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.xzj4haK40o /tmp/tmp.0TioHlCk4V /tmp/tmp.Tflw9bOXUP
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):02:14:40
                                                                Start date (UTC):18/03/2025
                                                                Path:/tmp/sync.arm5.elf
                                                                Arguments:/tmp/sync.arm5.elf
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):02:14:41
                                                                Start date (UTC):18/03/2025
                                                                Path:/tmp/sync.arm5.elf
                                                                Arguments:-
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1