Edit tour

Linux Analysis Report
boatnet.spc.elf

Overview

General Information

Sample name:boatnet.spc.elf
Analysis ID:1642308
MD5:8079ef3e397bdc16d6187d377fed7a23
SHA1:87d822df1bebdafd5009a2470c8b6a4de5bba405
SHA256:c040aeb560b7156f4c635db4635a69d11ae46c791962708e420d4c899499908a
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1642308
Start date and time:2025-03-19 01:51:44 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 3s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:boatnet.spc.elf
Detection:MAL
Classification:mal76.spre.troj.linELF@0/0@2/0
Command:/tmp/boatnet.spc.elf
PID:5457
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • wrapper-2.0 (PID: 5467, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 5468, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 5469, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 5470, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 5471, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 5472, Parent: 3147, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
boatnet.spc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    boatnet.spc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    boatnet.spc.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    SourceRuleDescriptionAuthorStrings
    5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        Click to see the 7 entries
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: boatnet.spc.elfAvira: detected
        Source: boatnet.spc.elfVirustotal: Detection: 64%Perma Link
        Source: boatnet.spc.elfReversingLabs: Detection: 72%
        Source: global trafficTCP traffic: 192.168.2.13:37600 -> 209.141.59.9:3778
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: unknownTCP traffic detected without corresponding DNS query: 209.141.59.9
        Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com

        System Summary

        barindex
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5457, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5457, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5460, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 5460, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3104, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3161, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3162, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3163, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3164, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3165, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3170, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3182, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3208, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3212, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5467, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5468, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5469, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5470, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5471, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5472, result: successfulJump to behavior
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3104, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3161, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3162, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3163, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3164, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3165, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3170, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3182, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3208, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 3212, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5467, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5468, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5469, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5470, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5471, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)SIGKILL sent: pid: 5472, result: successfulJump to behavior
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5457, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5457, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5460, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 5460, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: classification engineClassification label: mal76.spre.troj.linELF@0/0@2/0
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3122/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3117/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3114/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/914/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/518/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/519/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/917/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3134/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3375/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3132/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3095/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1745/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1866/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1588/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/884/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1982/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/765/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3246/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/767/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/800/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1906/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/802/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/803/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1748/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3647/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/5440/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3420/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1482/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/490/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1480/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1755/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1238/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1875/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/2964/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3413/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1751/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1872/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/2961/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1475/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/656/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/778/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/657/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/658/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/659/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/418/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/936/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/419/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/5438/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/816/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1879/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/5296/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3791/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1891/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3310/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3153/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/780/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/660/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1921/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3704/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3705/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/783/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1765/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3706/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/2974/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1400/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1884/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3424/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/2972/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3147/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/2970/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1881/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3146/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3300/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1805/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1925/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1804/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1648/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1922/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3429/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3703/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/5463/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3442/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3165/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3164/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3163/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3162/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/790/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3161/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/792/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/793/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/672/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1930/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/795/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/674/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3315/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1411/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/2984/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/1410/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/797/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/676/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3434/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3158/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/678/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/679/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5459)File opened: /proc/3170/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 5457)Queries kernel information via 'uname': Jump to behavior
        Source: boatnet.spc.elf, 5457.1.000056268ef56000.000056268efdb000.rw-.sdmp, boatnet.spc.elf, 5460.1.000056268ef56000.000056268efdb000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
        Source: boatnet.spc.elf, 5457.1.000056268ef56000.000056268efdb000.rw-.sdmp, boatnet.spc.elf, 5460.1.000056268ef56000.000056268efdb000.rw-.sdmpBinary or memory string: &V!/etc/qemu-binfmt/sparc
        Source: boatnet.spc.elf, 5457.1.00007ffc55b42000.00007ffc55b63000.rw-.sdmp, boatnet.spc.elf, 5460.1.00007ffc55b42000.00007ffc55b63000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/boatnet.spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.spc.elf
        Source: boatnet.spc.elf, 5457.1.00007ffc55b42000.00007ffc55b63000.rw-.sdmp, boatnet.spc.elf, 5460.1.00007ffc55b42000.00007ffc55b63000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5457, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5460, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 5460.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5457.1.00007f65a4011000.00007f65a401f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5457, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 5460, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Non-Standard Port
        Exfiltration Over Other Network Medium1
        Service Stop
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1642308 Sample: boatnet.spc.elf Startdate: 19/03/2025 Architecture: LINUX Score: 76 22 209.141.59.9, 37600, 37602, 37604 PONYNETUS United States 2->22 24 daisy.ubuntu.com 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Yara detected Mirai 2->32 7 boatnet.spc.elf 2->7         started        9 xfce4-panel wrapper-2.0 2->9         started        11 xfce4-panel wrapper-2.0 2->11         started        13 4 other processes 2->13 signatures3 process4 process5 15 boatnet.spc.elf 7->15         started        18 boatnet.spc.elf 7->18         started        20 boatnet.spc.elf 7->20         started        signatures6 34 Sample tries to kill multiple processes (SIGKILL) 15->34

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        boatnet.spc.elf64%VirustotalBrowse
        boatnet.spc.elf73%ReversingLabsLinux.Backdoor.Mirai
        boatnet.spc.elf100%AviraEXP/ELF.Gafgyt.D
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches

        Download Network PCAP: filteredfull

        NameIPActiveMaliciousAntivirus DetectionReputation
        daisy.ubuntu.com
        162.213.35.25
        truefalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          209.141.59.9
          unknownUnited States
          53667PONYNETUSfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          209.141.59.9boatnet.arm.elfGet hashmaliciousMiraiBrowse
            boatnet.mips.elfGet hashmaliciousMiraiBrowse
              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                  Space.m68k.elfGet hashmaliciousMiraiBrowse
                    Space.x86.elfGet hashmaliciousUnknownBrowse
                      Space.ppc.elfGet hashmaliciousUnknownBrowse
                        Space.i686.elfGet hashmaliciousUnknownBrowse
                          Space.sh4.elfGet hashmaliciousUnknownBrowse
                            SecuriteInfo.com.Linux.Siggen.9999.12860.23499.elfGet hashmaliciousUnknownBrowse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              daisy.ubuntu.comboatnet.arm.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              boatnet.mips.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.25
                              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.25
                              FederalmpslAgent.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              FederalppcAgent.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              Federalarm6Agent.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              Federali486Agent.elfGet hashmaliciousUnknownBrowse
                              • 162.213.35.25
                              Federalx86Agent.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.25
                              Federalarm7Agent.elfGet hashmaliciousMiraiBrowse
                              • 162.213.35.24
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              PONYNETUSboatnet.arm.elfGet hashmaliciousMiraiBrowse
                              • 209.141.59.9
                              boatnet.mips.elfGet hashmaliciousMiraiBrowse
                              • 209.141.59.9
                              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                              • 209.141.59.9
                              boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                              • 209.141.59.9
                              Social_Security_Statement_271454.exeGet hashmaliciousScreenConnect ToolBrowse
                              • 104.194.141.102
                              https://www.xpressreg.net/EmailRedirect2.aspx?id=15&verify=1309283587&scheme=https://click.actmkt.com//s2/001-9d8b5995-11e2-4176-a44d-ac784ffff218/052-1f3d50c8-0ab2-42ca-9d57-414363d82282?enr=naahiaduabyaaoqaf4ac6adsabsqa5aameagsadmabsqa4qafyahgadqabsqa3qaoqagyadzaaxaayyan4ag2abpabjqa2aan4ahaadjabtaa6iaieag4adbaaxqataaneag4adlaaxqanqaheadaabxaa3aapyaomahiadpabzaaziahuagkadsabuqayyafuaggadiab2qa4qammagqabnab2qa4yaeyahiadzabyaaziahuafgaceaataa5iaoiagyab5abuaa5aaoqahaadtaa5aalyaf4agcadoab2aa2iamiag6aduaawqa4aameahiadjabsqa3qaoqac2adnabxqa5ianyahiadbabuqa3qafuadeadcaayqazqafyadaabvabraazqaguadsabvaa2aamaagmagkadgabsqamaaheagmabwaa3aanqamqadmadeaa2qamqafyahoadpabzaa2yamuaheadtaaxaazaamuahmabpab6aa4yanaag6adpab2aa3iamuadaabyaa4qaqaam4ag2adbabuqa3aafyaggadpabwqa7aagqahyad4aayaaniagiac2abrabtaamyamqadkabqabrqaoaafuadaadbabraamqafuadiabsabrqayiafuadsadeaa2qanyafuadiabraa2aamyagyadgadeaa4aamqagiadqabsab6aamaaguadsabnabsqanqammadsabwabraaoiagaac2absabrqanyageac2abuaazqanqamyac2adcaa2qaniagmac2adcaa3aanqamuadcadcabtaaoaag4aggabyabrqa7aagaadaabraawqaoiamqadqadcaa2qaoiaheadkabnaayqamiamuadeabnaa2aamiag4admabnabqqanaagqagiabnabqqayyag4adqabuabtaazqamyagmabsaayqaoaapqahyacbab6aa===&path=/barcode/barcodepage.asp&recId=119377774&query=P2RiPVNBVEUwMzIxJmI9MjE1NTExJmxvZ289aHR0cHM6Ly9jb252LWRhdGEtY2RuLnMzLmFtYXpvbmF3cy5jb20vZXZlbnRzL1NBVEUwMzIxL3NhdGUwMzIxLWVtYWlsLWhlYWRlcjIucG5nGet hashmaliciousHTMLPhisherBrowse
                              • 167.88.165.71
                              mips.elfGet hashmaliciousMiraiBrowse
                              • 107.189.4.201
                              boatnet.spc.elfGet hashmaliciousMiraiBrowse
                              • 209.141.36.93
                              boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                              • 209.141.36.93
                              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                              • 209.141.36.93
                              No context
                              No context
                              No created / dropped files found
                              File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                              Entropy (8bit):6.066283632806456
                              TrID:
                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                              File name:boatnet.spc.elf
                              File size:58'376 bytes
                              MD5:8079ef3e397bdc16d6187d377fed7a23
                              SHA1:87d822df1bebdafd5009a2470c8b6a4de5bba405
                              SHA256:c040aeb560b7156f4c635db4635a69d11ae46c791962708e420d4c899499908a
                              SHA512:90bc6e9f9a1bde035c46e46ea27a0d2cd0a569783c9199d3d3c65191adb8091b21125732789c196fdf81c645239ce7e7e6ab29d84273e22d01dd8acad86d892c
                              SSDEEP:768:RqowmZPu9wtnfbltWgC6BSJsBcfDSbFwuQKqgESnmC/xO+KpAw2:RqtmZPuutfbltZFBSJsBcfDSbFw+BE2
                              TLSH:9F432921B53A1F13D0E0A47D21FB4B59B1A15ADE26A4C64E7D720F4FFF11A80A943DB8
                              File Content Preview:.ELF...........................4...x.....4. ...(.......................................................8...P........dt.Q................................@..(....@.2.................#.....b8..`.....!..... ...@.....".........`......$ ... ...@...........`....

                              ELF header

                              Class:ELF32
                              Data:2's complement, big endian
                              Version:1 (current)
                              Machine:Sparc
                              Version Number:0x1
                              Type:EXEC (Executable file)
                              OS/ABI:UNIX - System V
                              ABI Version:0
                              Entry Point Address:0x101a4
                              Flags:0x0
                              ELF Header Size:52
                              Program Header Offset:52
                              Program Header Size:32
                              Number of Program Headers:3
                              Section Header Offset:57976
                              Section Header Size:40
                              Number of Section Headers:10
                              Header String Table Index:9
                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                              NULL0x00x00x00x00x0000
                              .initPROGBITS0x100940x940x1c0x00x6AX004
                              .textPROGBITS0x100b00xb00xc8880x00x6AX004
                              .finiPROGBITS0x1c9380xc9380x140x00x6AX004
                              .rodataPROGBITS0x1c9500xc9500x11b00x00x2A008
                              .ctorsPROGBITS0x2e0000xe0000x80x00x3WA004
                              .dtorsPROGBITS0x2e0080xe0080x80x00x3WA004
                              .dataPROGBITS0x2e0180xe0180x2200x00x3WA008
                              .bssNOBITS0x2e2380xe2380x3180x00x3WA004
                              .shstrtabSTRTAB0x00xe2380x3e0x00x0001
                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                              LOAD0x00x100000x100000xdb000xdb006.17280x5R E0x10000.init .text .fini .rodata
                              LOAD0xe0000x2e0000x2e0000x2380x5502.92290x6RW 0x10000.ctors .dtors .data .bss
                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                              Download Network PCAP: filteredfull

                              • Total Packets: 140
                              • 3778 undefined
                              • 53 (DNS)
                              TimestampSource PortDest PortSource IPDest IP
                              Mar 19, 2025 01:52:34.180566072 CET376003778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.185333014 CET377837600209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:34.185391903 CET376003778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.202043056 CET376003778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.206832886 CET377837600209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:34.206912041 CET376003778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.211596966 CET377837600209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:34.804344893 CET377837600209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:34.804572105 CET376003778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.804672003 CET376003778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.807125092 CET376023778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.811851978 CET377837602209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:34.811929941 CET376023778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.818361044 CET376023778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.823064089 CET377837602209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:34.823107958 CET376023778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:34.827975035 CET377837602209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:35.447367907 CET377837602209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:35.447719097 CET376023778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:35.447719097 CET376023778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:35.455053091 CET376043778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:35.459847927 CET377837604209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:35.459943056 CET376043778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:35.463150978 CET376043778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:35.469204903 CET377837604209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:35.469263077 CET376043778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:35.475631952 CET377837604209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.075026035 CET377837604209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.075124025 CET376043778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.075124025 CET376043778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.077174902 CET376063778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.081938982 CET377837606209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.082007885 CET376063778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.083972931 CET376063778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.088607073 CET377837606209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.088648081 CET376063778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.093311071 CET377837606209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.682610035 CET377837606209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.682730913 CET376063778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.682780027 CET376063778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.683621883 CET376083778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.688272953 CET377837608209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.688344955 CET376083778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.690073967 CET376083778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.694717884 CET377837608209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:36.694761992 CET376083778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:36.699373007 CET377837608209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.310252905 CET377837608209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.310420990 CET376083778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.310420990 CET376083778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.326659918 CET376103778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.331352949 CET377837610209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.331479073 CET376103778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.354990005 CET376103778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.359795094 CET377837610209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.359885931 CET376103778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.364594936 CET377837610209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.980901003 CET377837610209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.980973959 CET376103778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.981071949 CET376103778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.982147932 CET376123778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.986877918 CET377837612209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.986958981 CET376123778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.989502907 CET376123778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.994174957 CET377837612209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:37.994224072 CET376123778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:37.998985052 CET377837612209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:38.628134012 CET377837612209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:38.628217936 CET376123778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:38.628267050 CET376123778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:38.632338047 CET376143778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:38.637058020 CET377837614209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:38.637222052 CET376143778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:38.640084028 CET376143778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:38.644723892 CET377837614209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:38.644788980 CET376143778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:38.649415970 CET377837614209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.275722980 CET377837614209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.276027918 CET376143778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.276057959 CET376143778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.276688099 CET376163778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.281491995 CET377837616209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.281560898 CET376163778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.282963991 CET376163778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.287609100 CET377837616209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.287951946 CET376163778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.292587042 CET377837616209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.920280933 CET377837616209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.920383930 CET376163778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.920418978 CET376163778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.920999050 CET376183778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.925704002 CET377837618209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.925766945 CET376183778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.927774906 CET376183778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.932450056 CET377837618209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:39.932503939 CET376183778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:39.937191010 CET377837618209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:40.584908962 CET377837618209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:40.585086107 CET376183778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:40.585140944 CET376183778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:40.586136103 CET376203778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:40.591641903 CET377837620209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:40.591711998 CET376203778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:40.595896006 CET376203778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:40.600572109 CET377837620209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:40.600611925 CET376203778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:40.605217934 CET377837620209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.213855028 CET377837620209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.213932991 CET376203778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.214032888 CET376203778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.214613914 CET376223778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.219286919 CET377837622209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.219351053 CET376223778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.220825911 CET376223778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.225475073 CET377837622209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.225518942 CET376223778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.230210066 CET377837622209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.844624996 CET377837622209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.844754934 CET376223778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.844754934 CET376223778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.845707893 CET376243778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.850419044 CET377837624209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.850629091 CET376243778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.853339911 CET376243778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.859194040 CET377837624209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:41.859766960 CET376243778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:41.864588022 CET377837624209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:42.490737915 CET377837624209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:42.490802050 CET376243778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:42.490844011 CET376243778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:42.491744995 CET376263778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:42.496450901 CET377837626209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:42.496654987 CET376263778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:42.498461008 CET376263778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:42.503071070 CET377837626209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:42.503120899 CET376263778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:42.507742882 CET377837626209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.099530935 CET377837626209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.102397919 CET376263778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.102435112 CET376263778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.110393047 CET376283778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.115078926 CET377837628209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.115147114 CET376283778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.116590023 CET376283778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.121210098 CET377837628209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.121282101 CET376283778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.125977993 CET377837628209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.762913942 CET377837628209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.763047934 CET376283778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.763083935 CET376283778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.768670082 CET376303778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.773375988 CET377837630209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.773432016 CET376303778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.785526991 CET376303778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.790196896 CET377837630209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:43.794477940 CET376303778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:43.799166918 CET377837630209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:44.423548937 CET377837630209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:44.423650026 CET376303778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:44.423677921 CET376303778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:44.424372911 CET376323778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:44.429054976 CET377837632209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:44.429214954 CET376323778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:44.430324078 CET376323778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:44.434948921 CET377837632209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:44.434998989 CET376323778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:44.439624071 CET377837632209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.023637056 CET377837632209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.023782969 CET376323778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.023833036 CET376323778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.024496078 CET376343778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.029186964 CET377837634209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.029306889 CET376343778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.030213118 CET376343778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.034862041 CET377837634209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.034933090 CET376343778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.039587975 CET377837634209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.668524981 CET377837634209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.668651104 CET376343778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.668693066 CET376343778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.669187069 CET376363778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.673938990 CET377837636209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.674015045 CET376363778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.674792051 CET376363778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.679403067 CET377837636209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:45.679449081 CET376363778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:45.684168100 CET377837636209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:46.342468977 CET377837636209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:46.342573881 CET376363778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:46.342612028 CET376363778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:46.343144894 CET376383778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:46.347760916 CET377837638209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:46.347814083 CET376383778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:46.348555088 CET376383778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:46.353230953 CET377837638209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:46.353286982 CET376383778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:46.357944965 CET377837638209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.007317066 CET377837638209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.007437944 CET376383778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.007496119 CET376383778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.008280039 CET376403778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.012981892 CET377837640209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.013035059 CET376403778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.014592886 CET376403778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.019311905 CET377837640209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.019357920 CET376403778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.024077892 CET377837640209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.614001989 CET377837640209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.614141941 CET376403778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.614234924 CET376403778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.615632057 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.620367050 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.620465994 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.621524096 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.626132011 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:47.626188993 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:47.630886078 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:57.631000996 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:52:57.635756969 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:57.796569109 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:52:57.796694040 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:53:57.844885111 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:53:57.849661112 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:53:58.013434887 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:53:58.013746023 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:54:58.060718060 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:54:58.065581083 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:54:58.227781057 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:54:58.227844954 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:55:58.276443005 CET376423778192.168.2.13209.141.59.9
                              Mar 19, 2025 01:55:58.281569958 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:55:58.446180105 CET377837642209.141.59.9192.168.2.13
                              Mar 19, 2025 01:55:58.446338892 CET376423778192.168.2.13209.141.59.9
                              TimestampSource PortDest PortSource IPDest IP
                              Mar 19, 2025 01:55:16.394879103 CET5585853192.168.2.138.8.8.8
                              Mar 19, 2025 01:55:16.395001888 CET5921653192.168.2.138.8.8.8
                              Mar 19, 2025 01:55:16.401256084 CET53558588.8.8.8192.168.2.13
                              Mar 19, 2025 01:55:16.401410103 CET53592168.8.8.8192.168.2.13
                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                              Mar 19, 2025 01:55:16.394879103 CET192.168.2.138.8.8.80x6a1aStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                              Mar 19, 2025 01:55:16.395001888 CET192.168.2.138.8.8.80x10e1Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                              Mar 19, 2025 01:55:16.401256084 CET8.8.8.8192.168.2.130x6a1aNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                              Mar 19, 2025 01:55:16.401256084 CET8.8.8.8192.168.2.130x6a1aNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                              System Behavior

                              Start time (UTC):00:52:32
                              Start date (UTC):19/03/2025
                              Path:/tmp/boatnet.spc.elf
                              Arguments:/tmp/boatnet.spc.elf
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):00:52:32
                              Start date (UTC):19/03/2025
                              Path:/tmp/boatnet.spc.elf
                              Arguments:-
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):00:52:32
                              Start date (UTC):19/03/2025
                              Path:/tmp/boatnet.spc.elf
                              Arguments:-
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):00:52:32
                              Start date (UTC):19/03/2025
                              Path:/tmp/boatnet.spc.elf
                              Arguments:-
                              File size:4379400 bytes
                              MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/bin/xfce4-panel
                              Arguments:-
                              File size:375768 bytes
                              MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                              Start time (UTC):00:52:33
                              Start date (UTC):19/03/2025
                              Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                              Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                              File size:35136 bytes
                              MD5 hash:ac0b8a906f359a8ae102244738682e76