Edit tour

Linux Analysis Report
sync.arm7.elf

Overview

General Information

Sample name:sync.arm7.elf
Analysis ID:1641120
MD5:94cccc560723cea7f556bc00038ba233
SHA1:3e7d83249d77a6b97d29a90f5d8c9c86caec92d9
SHA256:8220690b2217c42580553cda5d358ce2cefd71a1e62b348b851b735d04a3c9f5
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Performs DNS TXT record lookups
Sample deletes itself
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1641120
Start date and time:2025-03-18 03:19:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sync.arm7.elf
Detection:MAL
Classification:mal64.evad.linELF@0/0@45/0
Command:/tmp/sync.arm7.elf
PID:6271
Exit Code:1
Exit Code Info:
Killed:False
Standard Output:
syncne
Standard Error:
  • system is lnxubuntu20
  • sync.arm7.elf (PID: 6271, Parent: 6195, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/sync.arm7.elf
  • dash New Fork (PID: 6284, Parent: 4331)
  • rm (PID: 6284, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.JliIpc2IE0 /tmp/tmp.Qv2htSVoxj /tmp/tmp.YcGOicyBIg
  • dash New Fork (PID: 6285, Parent: 4331)
  • rm (PID: 6285, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.JliIpc2IE0 /tmp/tmp.Qv2htSVoxj /tmp/tmp.YcGOicyBIg
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:20:30.985475+010020135141A Network Trojan was detected192.168.2.23333921.1.1.153UDP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:22:21.233407+010028486071Malware Command and Control Activity Detected185.194.205.7961003192.168.2.2339492TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-18T03:22:21.028123+010028486061Malware Command and Control Activity Detected192.168.2.2339492185.194.205.7961003TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sync.arm7.elfVirustotal: Detection: 44%Perma Link
Source: sync.arm7.elfReversingLabs: Detection: 44%

Networking

barindex
Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.23:33392 -> 1.1.1.1:53
Source: Network trafficSuricata IDS: 2848606 - Severity 1 - ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Outbound) : 192.168.2.23:39492 -> 185.194.205.79:61003
Source: Network trafficSuricata IDS: 2848607 - Severity 1 - ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Inbound) : 185.194.205.79:61003 -> 192.168.2.23:39492
Source: global trafficTCP traffic: 192.168.2.23:39488 -> 185.194.205.79:61003
Source: unknownDNS traffic detected: query: dnsresolve.socialgains.cf replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownTCP traffic detected without corresponding DNS query: 185.194.205.79
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: dnsresolve.socialgains.cf
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal64.evad.linELF@0/0@45/0
Source: /usr/bin/dash (PID: 6284)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.JliIpc2IE0 /tmp/tmp.Qv2htSVoxj /tmp/tmp.YcGOicyBIgJump to behavior
Source: /usr/bin/dash (PID: 6285)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.JliIpc2IE0 /tmp/tmp.Qv2htSVoxj /tmp/tmp.YcGOicyBIgJump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/sync.arm7.elf (PID: 6271)File: /tmp/sync.arm7.elfJump to behavior
Source: /tmp/sync.arm7.elf (PID: 6275)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm7.elf (PID: 6275)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm7.elf (PID: 6271)Queries kernel information via 'uname': Jump to behavior
Source: sync.arm7.elf, 6271.1.00005586b793a000.00005586b7a89000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: sync.arm7.elf, 6271.1.00005586b793a000.00005586b7a89000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: sync.arm7.elf, 6271.1.00007ffe81f03000.00007ffe81f24000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: sync.arm7.elf, 6271.1.00007ffe81f03000.00007ffe81f24000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/sync.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sync.arm7.elf

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1641120 Sample: sync.arm7.elf Startdate: 18/03/2025 Architecture: LINUX Score: 64 19 dnsresolve.socialgains.cf 2->19 21 185.194.205.79, 39488, 39490, 39492 HTSENSEFR France 2->21 23 3 other IPs or domains 2->23 25 Suricata IDS alerts for network traffic 2->25 27 Multi AV Scanner detection for submitted file 2->27 8 sync.arm7.elf 2->8         started        11 dash rm 2->11         started        13 dash rm 2->13         started        signatures3 29 Performs DNS TXT record lookups 19->29 process4 signatures5 31 Sample deletes itself 8->31 15 sync.arm7.elf 8->15         started        process6 process7 17 sync.arm7.elf 15->17         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
sync.arm7.elf44%VirustotalBrowse
sync.arm7.elf44%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
dnsresolve.socialgains.cf
unknown
unknownfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    34.249.145.219
    unknownUnited States
    16509AMAZON-02USfalse
    185.194.205.79
    unknownFrance
    204145HTSENSEFRtrue
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    34.249.145.219na.elfGet hashmaliciousPrometeiBrowse
      na.elfGet hashmaliciousPrometeiBrowse
        main_ppc.elfGet hashmaliciousMiraiBrowse
          main_arm6.elfGet hashmaliciousMiraiBrowse
            main_sh4.elfGet hashmaliciousMiraiBrowse
              rebirth.arm4.elfGet hashmaliciousGafgytBrowse
                boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                  Space.x86.elfGet hashmaliciousUnknownBrowse
                    boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                      test.bot.mips.elfGet hashmaliciousUnknownBrowse
                        185.194.205.79sync.arm5.elfGet hashmaliciousUnknownBrowse
                          sync.arm4.elfGet hashmaliciousUnknownBrowse
                            sync.x86_64.elfGet hashmaliciousUnknownBrowse
                              sync.sh4.elfGet hashmaliciousUnknownBrowse
                                sync.superh.elfGet hashmaliciousUnknownBrowse
                                  sync.x86.elfGet hashmaliciousUnknownBrowse
                                    sync.superh.elfGet hashmaliciousUnknownBrowse
                                      sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                        sync.arm5.elfGet hashmaliciousUnknownBrowse
                                          sync.arm4.elfGet hashmaliciousUnknownBrowse
                                            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                            91.189.91.42sync.arm5.elfGet hashmaliciousUnknownBrowse
                                              sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                  sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                    sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                      sync.mips.elfGet hashmaliciousUnknownBrowse
                                                        gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                          na.elfGet hashmaliciousPrometeiBrowse
                                                            na.elfGet hashmaliciousPrometeiBrowse
                                                              na.elfGet hashmaliciousPrometeiBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                                                • 185.125.190.26
                                                                sync.arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.sparc.elfGet hashmaliciousUnknownBrowse
                                                                • 185.125.190.26
                                                                sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 185.125.190.26
                                                                sync.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 91.189.91.42
                                                                HTSENSEFRsync.arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.sh4.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.superh.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.superh.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                sync.arm4.elfGet hashmaliciousUnknownBrowse
                                                                • 185.194.205.79
                                                                INIT7CHsync.arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.x86_64.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.arm6.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                sync.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                gigab.mips.elfGet hashmaliciousUnknownBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 109.202.202.202
                                                                AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                                                • 52.43.119.120
                                                                sync.x86.elfGet hashmaliciousUnknownBrowse
                                                                • 54.171.230.55
                                                                sync.mipsel.elfGet hashmaliciousUnknownBrowse
                                                                • 54.171.230.55
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 52.43.119.120
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 52.43.119.120
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 52.43.119.120
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 52.43.119.120
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 34.249.145.219
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 52.43.119.120
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 52.43.119.120
                                                                No context
                                                                No context
                                                                No created / dropped files found
                                                                File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                                Entropy (8bit):6.096499087808796
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:sync.arm7.elf
                                                                File size:87'572 bytes
                                                                MD5:94cccc560723cea7f556bc00038ba233
                                                                SHA1:3e7d83249d77a6b97d29a90f5d8c9c86caec92d9
                                                                SHA256:8220690b2217c42580553cda5d358ce2cefd71a1e62b348b851b735d04a3c9f5
                                                                SHA512:f49c43673af951d8cbd62185f4ee4f0d063c67e0b5de61a516ba2817afb20fb1b22f210de5db38f9a6ca83b271145bc0642e10d263759c8a36a565a07db1e75c
                                                                SSDEEP:1536:fAn/MQK1KiDKcoKqUKAKRw+BjMej0Tdau+Zca4B6LPsSXdlsmizGfe0BY79VL:rQK1KiDK7KqUKAKR8ejQdb+Zca4B6LPa
                                                                TLSH:3383394AF8816B11D4D925BEFE0E1189335347BDE3EE7112DE244B2037DAA6B0F76912
                                                                File Content Preview:.ELF..............(.........4....S......4. ...(........p.M...........................................N...N...............P...P...P..H....................P...P...P..................Q.td..................................-...L..................@-.,@...0....S

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:ARM
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x8194
                                                                Flags:0x4000002
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:5
                                                                Section Header Offset:86972
                                                                Section Header Size:40
                                                                Number of Section Headers:15
                                                                Header String Table Index:14
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x80d40xd40x100x00x6AX004
                                                                .textPROGBITS0x80f00xf00x131400x00x6AX0016
                                                                .finiPROGBITS0x1b2300x132300x100x00x6AX004
                                                                .rodataPROGBITS0x1b2400x132400x1b580x00x2A008
                                                                .ARM.extabPROGBITS0x1cd980x14d980x180x00x2A004
                                                                .ARM.exidxARM_EXIDX0x1cdb00x14db00x1180x00x82AL204
                                                                .eh_framePROGBITS0x250000x150000x40x00x3WA004
                                                                .tbssNOBITS0x250040x150040x80x00x403WAT004
                                                                .init_arrayINIT_ARRAY0x250040x150040x40x00x3WA004
                                                                .fini_arrayFINI_ARRAY0x250080x150080x40x00x3WA004
                                                                .gotPROGBITS0x250100x150100xa80x40x3WA004
                                                                .dataPROGBITS0x250b80x150b80x2900x00x3WA004
                                                                .bssNOBITS0x253480x153480xb0940x00x3WA004
                                                                .shstrtabSTRTAB0x00x153480x730x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                EXIDX0x14db00x1cdb00x1cdb00x1180x1184.51840x4R 0x4.ARM.exidx
                                                                LOAD0x00x80000x80000x14ec80x14ec86.12340x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                                                                LOAD0x150000x250000x250000x3480xb3dc4.74720x6RW 0x8000.eh_frame .tbss .init_array .fini_array .got .data .bss
                                                                TLS0x150040x250040x250040x00x80.00000x4R 0x4.tbss
                                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                Download Network PCAP: filteredfull

                                                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                2025-03-18T03:20:30.985475+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.23333921.1.1.153UDP
                                                                2025-03-18T03:22:21.028123+01002848606ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Outbound)1192.168.2.2339492185.194.205.7961003TCP
                                                                2025-03-18T03:22:21.233407+01002848607ETPRO MALWARE ELF/DarkNexus CnC Beacon Keep-Alive (Inbound)1185.194.205.7961003192.168.2.2339492TCP
                                                                • Total Packets: 63
                                                                • 61003 undefined
                                                                • 443 (HTTPS)
                                                                • 80 (HTTP)
                                                                • 53 (DNS)
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Mar 18, 2025 03:20:23.391756058 CET43928443192.168.2.2391.189.91.42
                                                                Mar 18, 2025 03:20:35.856458902 CET4433925634.249.145.219192.168.2.23
                                                                Mar 18, 2025 03:20:35.856704950 CET39256443192.168.2.2334.249.145.219
                                                                Mar 18, 2025 03:20:35.861458063 CET4433925634.249.145.219192.168.2.23
                                                                Mar 18, 2025 03:20:37.606239080 CET3948861003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:20:37.611057043 CET6100339488185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:20:37.611118078 CET3948861003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:20:37.611217976 CET3948861003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:20:37.615863085 CET6100339488185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:20:39.322242022 CET6100339488185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:20:39.323016882 CET3948861003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:20:39.327706099 CET6100339488185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:20:40.029490948 CET4251680192.168.2.23109.202.202.202
                                                                Mar 18, 2025 03:20:44.124944925 CET43928443192.168.2.2391.189.91.42
                                                                Mar 18, 2025 03:20:56.368324041 CET3949061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:20:56.373102903 CET6100339490185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:20:56.373162985 CET3949061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:20:56.373178959 CET3949061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:20:56.377814054 CET6100339490185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:21:04.064527035 CET6100339490185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:21:04.064739943 CET3949061003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:21:04.069432020 CET6100339490185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:21:20.973366022 CET3949261003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:21:20.979459047 CET6100339492185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:21:20.979546070 CET3949261003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:21:20.979614019 CET3949261003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:21:20.984232903 CET6100339492185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:21:25.079201937 CET43928443192.168.2.2391.189.91.42
                                                                Mar 18, 2025 03:22:21.028122902 CET3949261003192.168.2.23185.194.205.79
                                                                Mar 18, 2025 03:22:21.032828093 CET6100339492185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:22:21.233407021 CET6100339492185.194.205.79192.168.2.23
                                                                Mar 18, 2025 03:22:21.233699083 CET3949261003192.168.2.23185.194.205.79
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Mar 18, 2025 03:20:21.492578030 CET5736753192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:20:21.506896973 CET53573678.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:20:22.515311003 CET5794153192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:22.530493975 CET53579418.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:23.532140970 CET4421753192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:23.547197104 CET53442178.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:24.548919916 CET5119653192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:20:24.576920986 CET53511968.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:20:25.578854084 CET5999053192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:25.747641087 CET53599901.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:20:26.749629021 CET5750753192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:26.932559967 CET53575071.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:20:27.934806108 CET5858353192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:27.949318886 CET53585838.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:28.951216936 CET5036153192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:28.966548920 CET53503618.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:29.968446016 CET4832153192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:29.983483076 CET53483218.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:30.985475063 CET3339253192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:20:31.105421066 CET53333921.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:20:32.107336044 CET4511753192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:32.244395018 CET53451171.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:20:33.246787071 CET4254653192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:20:33.430299044 CET53425461.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:20:34.432332993 CET5672153192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:20:34.447257996 CET53567218.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:20:35.449048996 CET3403353192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:20:35.586015940 CET53340331.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:20:36.587915897 CET3617553192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:20:36.604419947 CET53361758.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:20:40.326402903 CET3361053192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:20:40.351320982 CET53336101.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:20:41.354397058 CET3660753192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:20:41.480242014 CET53366071.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:20:42.483190060 CET4516753192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:42.674335003 CET53451671.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:20:43.677721977 CET5172253192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:43.807729006 CET53517221.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:20:44.810841084 CET5692253192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:20:44.825655937 CET53569228.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:20:45.828442097 CET5554953192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:45.854628086 CET53555498.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:46.858001947 CET5988053192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:46.873023987 CET53598808.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:47.876333952 CET5938153192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:47.891845942 CET53593818.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:48.895168066 CET5909653192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:48.910454035 CET53590968.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:49.912965059 CET3279653192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:20:49.937560081 CET53327961.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:20:50.939965963 CET5314953192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:20:50.954482079 CET53531498.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:20:51.956860065 CET5162153192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:52.095004082 CET53516211.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:20:53.098046064 CET3279653192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:53.215761900 CET53327961.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:20:54.218136072 CET5903753192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:20:54.243535995 CET53590371.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:20:55.245691061 CET3354053192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:20:55.366369009 CET53335401.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:21:05.067405939 CET5750753192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:05.094786882 CET53575071.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:06.097321987 CET3440253192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:21:06.112886906 CET53344028.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:21:07.115319014 CET5201653192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:07.139655113 CET53520161.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:08.142030001 CET5865753192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:08.267151117 CET53586571.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:09.270236015 CET4454053192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:21:09.285315990 CET53445408.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:21:10.288172960 CET5219453192.168.2.238.8.8.8
                                                                Mar 18, 2025 03:21:10.313841105 CET53521948.8.8.8192.168.2.23
                                                                Mar 18, 2025 03:21:11.316854000 CET3822753192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:21:11.332542896 CET53382278.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:21:12.335342884 CET3284253192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:12.453027010 CET53328421.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:13.456223965 CET4938153192.168.2.231.0.0.1
                                                                Mar 18, 2025 03:21:13.480938911 CET53493811.0.0.1192.168.2.23
                                                                Mar 18, 2025 03:21:14.483778954 CET3545553192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:21:14.634608984 CET53354558.8.4.4192.168.2.23
                                                                Mar 18, 2025 03:21:15.638026953 CET4775353192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:15.662965059 CET53477531.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:16.666434050 CET4380853192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:16.787014008 CET53438081.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:17.790214062 CET5558253192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:17.923665047 CET53555821.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:18.926760912 CET5418953192.168.2.231.1.1.1
                                                                Mar 18, 2025 03:21:18.951020956 CET53541891.1.1.1192.168.2.23
                                                                Mar 18, 2025 03:21:19.953738928 CET4868253192.168.2.238.8.4.4
                                                                Mar 18, 2025 03:21:19.970978022 CET53486828.8.4.4192.168.2.23
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Mar 18, 2025 03:20:21.492578030 CET192.168.2.238.8.8.80xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:22.515311003 CET192.168.2.238.8.4.40xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:23.532140970 CET192.168.2.238.8.4.40xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:24.548919916 CET192.168.2.238.8.8.80xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:25.578854084 CET192.168.2.231.0.0.10xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:26.749629021 CET192.168.2.231.0.0.10xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:27.934806108 CET192.168.2.238.8.4.40xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:28.951216936 CET192.168.2.238.8.4.40xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:29.968446016 CET192.168.2.238.8.4.40xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:30.985475063 CET192.168.2.231.1.1.10xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:32.107336044 CET192.168.2.231.0.0.10xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:33.246787071 CET192.168.2.231.1.1.10xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:34.432332993 CET192.168.2.238.8.8.80xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:35.449048996 CET192.168.2.231.1.1.10xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:36.587915897 CET192.168.2.238.8.8.80xf26cStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:40.326402903 CET192.168.2.231.1.1.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:41.354397058 CET192.168.2.231.1.1.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:42.483190060 CET192.168.2.231.0.0.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:43.677721977 CET192.168.2.231.0.0.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:44.810841084 CET192.168.2.238.8.8.80x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:45.828442097 CET192.168.2.238.8.4.40x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:46.858001947 CET192.168.2.238.8.4.40x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:47.876333952 CET192.168.2.238.8.4.40x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:48.895168066 CET192.168.2.238.8.4.40x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:49.912965059 CET192.168.2.231.1.1.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:50.939965963 CET192.168.2.238.8.4.40x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:51.956860065 CET192.168.2.231.0.0.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:53.098046064 CET192.168.2.231.0.0.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:54.218136072 CET192.168.2.231.1.1.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:20:55.245691061 CET192.168.2.231.0.0.10x1746Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:05.067405939 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:06.097321987 CET192.168.2.238.8.8.80x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:07.115319014 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:08.142030001 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:09.270236015 CET192.168.2.238.8.8.80x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:10.288172960 CET192.168.2.238.8.8.80x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:11.316854000 CET192.168.2.238.8.4.40x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:12.335342884 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:13.456223965 CET192.168.2.231.0.0.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:14.483778954 CET192.168.2.238.8.4.40x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:15.638026953 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:16.666434050 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:17.790214062 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:18.926760912 CET192.168.2.231.1.1.10x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                Mar 18, 2025 03:21:19.953738928 CET192.168.2.238.8.4.40x350dStandard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Mar 18, 2025 03:20:21.506896973 CET8.8.8.8192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:22.530493975 CET8.8.4.4192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:23.547197104 CET8.8.4.4192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:24.576920986 CET8.8.8.8192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:25.747641087 CET1.0.0.1192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:26.932559967 CET1.0.0.1192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:27.949318886 CET8.8.4.4192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:28.966548920 CET8.8.4.4192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:29.983483076 CET8.8.4.4192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:31.105421066 CET1.1.1.1192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:32.244395018 CET1.0.0.1192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:33.430299044 CET1.1.1.1192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:34.447257996 CET8.8.8.8192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:35.586015940 CET1.1.1.1192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:36.604419947 CET8.8.8.8192.168.2.230xf26cName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:40.351320982 CET1.1.1.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:41.480242014 CET1.1.1.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:42.674335003 CET1.0.0.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:43.807729006 CET1.0.0.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:44.825655937 CET8.8.8.8192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:45.854628086 CET8.8.4.4192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:46.873023987 CET8.8.4.4192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:47.891845942 CET8.8.4.4192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:48.910454035 CET8.8.4.4192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:49.937560081 CET1.1.1.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:50.954482079 CET8.8.4.4192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:52.095004082 CET1.0.0.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:53.215761900 CET1.0.0.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:54.243535995 CET1.1.1.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:20:55.366369009 CET1.0.0.1192.168.2.230x1746Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:05.094786882 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:06.112886906 CET8.8.8.8192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:07.139655113 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:08.267151117 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:09.285315990 CET8.8.8.8192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:10.313841105 CET8.8.8.8192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:11.332542896 CET8.8.4.4192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:12.453027010 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:13.480938911 CET1.0.0.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:14.634608984 CET8.8.4.4192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:15.662965059 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:16.787014008 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:17.923665047 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:18.951020956 CET1.1.1.1192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                                                Mar 18, 2025 03:21:19.970978022 CET8.8.4.4192.168.2.230x350dName error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false

                                                                System Behavior

                                                                Start time (UTC):02:20:20
                                                                Start date (UTC):18/03/2025
                                                                Path:/tmp/sync.arm7.elf
                                                                Arguments:/tmp/sync.arm7.elf
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):02:20:20
                                                                Start date (UTC):18/03/2025
                                                                Path:/tmp/sync.arm7.elf
                                                                Arguments:-
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):02:20:20
                                                                Start date (UTC):18/03/2025
                                                                Path:/tmp/sync.arm7.elf
                                                                Arguments:-
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):02:20:34
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):02:20:34
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.JliIpc2IE0 /tmp/tmp.Qv2htSVoxj /tmp/tmp.YcGOicyBIg
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):02:20:34
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):02:20:34
                                                                Start date (UTC):18/03/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.JliIpc2IE0 /tmp/tmp.Qv2htSVoxj /tmp/tmp.YcGOicyBIg
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b