Edit tour

Linux Analysis Report
kmips.elf

Overview

General Information

Sample name:kmips.elf
Analysis ID:1647996
MD5:e0ee1e0bf964ac7510a3344879e14f63
SHA1:658551a36a21c375e77f907152ca2d26fe17ae86
SHA256:16e2a3121bebded41767de961a17d4833bd70f5e31ca7e3cb1f92cb9ce40477a
Tags:elfuser-abuse_ch
Infos:
Errors
  • No or unstable Internet during analysis

Detection

Score:60
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1647996
Start date and time:2025-03-25 13:28:44 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 57s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:kmips.elf
Detection:MAL
Classification:mal60.troj.linELF@0/2@0/0
  • No or unstable Internet during analysis
  • Excluded IPs from analysis (whitelisted): 8.8.8.8
Command:/tmp/kmips.elf
PID:5562
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • kmips.elf (PID: 5562, Parent: 5474, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/kmips.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: kmips.elfAvira: detected
Source: kmips.elfReversingLabs: Detection: 13%

Networking

barindex
Source: global trafficTCP traffic: 156.244.45.113 ports 50749,45229,2,4,5,9
Source: global trafficTCP traffic: 216.73.156.19 ports 45229,2,5,6,9,52962
Source: global trafficTCP traffic: 216.146.26.30 ports 3,4,5,6,7,47563
Source: global trafficTCP traffic: 104.245.241.61 ports 40237,40217,0,29486,1,2,4,7
Source: global trafficTCP traffic: 154.205.155.97 ports 44859,29486,4,5,8,9
Source: global trafficTCP traffic: 192.168.2.14:35994 -> 156.244.44.239:50464
Source: global trafficTCP traffic: 192.168.2.14:46850 -> 216.73.156.19:52962
Source: global trafficTCP traffic: 192.168.2.14:50852 -> 156.244.14.93:45229
Source: global trafficTCP traffic: 192.168.2.14:48142 -> 216.146.26.30:47563
Source: global trafficTCP traffic: 192.168.2.14:43058 -> 156.244.45.113:45229
Source: global trafficTCP traffic: 192.168.2.14:39270 -> 154.205.155.97:44859
Source: global trafficTCP traffic: 192.168.2.14:38282 -> 104.245.241.61:40217
Source: /tmp/kmips.elf (PID: 5566)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: kmips.elf, 5562.1.00007f5240456000.00007f5240460000.rw-.sdmpString found in binary or memory: http://0/t/wget.sh
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.linELF@0/2@0/0
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3760/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1583/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/2672/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3759/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3757/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3758/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/5393/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/240/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/242/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/244/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/245/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/247/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/806/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/807/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/928/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3420/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/135/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/3412/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/1371/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/kmips.elf (PID: 5562)Queries kernel information via 'uname': Jump to behavior
Source: kmips.elf, 5562.1.00007fffdbf26000.00007fffdbf47000.rw-.sdmpBinary or memory string: /tmp/qemu-open.VNSRfK
Source: kmips.elf, 5562.1.00007f5240456000.00007f5240460000.rw-.sdmpBinary or memory string: vmwarem
Source: kmips.elf, 5562.1.00007fffdbf26000.00007fffdbf47000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.VNSRfK\
Source: kmips.elf, 5562.1.00007f5240456000.00007f5240460000.rw-.sdmpBinary or memory string: vmware
Source: kmips.elf, 5562.1.00007f5240456000.00007f5240460000.rw-.sdmpBinary or memory string: qemu-arm2QB
Source: kmips.elf, 5562.1.00007f5240456000.00007f5240460000.rw-.sdmpBinary or memory string: qemu-arm
Source: kmips.elf, 5562.1.000055fb06e3c000.000055fb06ee3000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: kmips.elf, 5562.1.000055fb06e3c000.000055fb06ee3000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: kmips.elf, 5562.1.00007fffdbf26000.00007fffdbf47000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/kmips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/kmips.elf
Source: kmips.elf, 5562.1.00007fffdbf26000.00007fffdbf47000.rw-.sdmpBinary or memory string: %s/qemu-op
Source: kmips.elf, 5562.1.00007fffdbf26000.00007fffdbf47000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: kmips.elf, 5562.1.00007fffdbf26000.00007fffdbf47000.rw-.sdmpBinary or memory string: MPDIR%s/qemu-op
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1647996 Sample: kmips.elf Startdate: 25/03/2025 Architecture: LINUX Score: 60 11 216.73.156.19, 45229, 46850, 52962 WINDSTREAMUS United States 2->11 13 216.146.26.30, 47563, 48142 US-TELEPACIFICUS Reserved 2->13 15 5 other IPs or domains 2->15 17 Antivirus / Scanner detection for submitted sample 2->17 19 Multi AV Scanner detection for submitted file 2->19 21 Connects to many ports of the same IP (likely port scanning) 2->21 7 kmips.elf 2->7         started        signatures3 process4 process5 9 kmips.elf 7->9         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
kmips.elf14%ReversingLabsLinux.Trojan.Mirai
kmips.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://0/t/wget.shkmips.elf, 5562.1.00007f5240456000.00007f5240460000.rw-.sdmpfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    216.146.26.30
    unknownReserved
    11915US-TELEPACIFICUStrue
    156.244.45.113
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
    216.73.156.19
    unknownUnited States
    7029WINDSTREAMUStrue
    156.244.14.93
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKfalse
    104.245.241.61
    unknownUnited States
    8100ASN-QUADRANET-GLOBALUStrue
    154.205.155.97
    unknownSeychelles
    26484IKGUL-26484UStrue
    156.244.44.239
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    216.146.26.30mips.elfGet hashmaliciousUnknownBrowse
      SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
        arm5.elfGet hashmaliciousUnknownBrowse
          156.244.45.113mips.elfGet hashmaliciousUnknownBrowse
            ppc.elfGet hashmaliciousUnknownBrowse
              arm.elfGet hashmaliciousUnknownBrowse
                216.73.156.19mips.elfGet hashmaliciousUnknownBrowse
                  156.244.14.93mpsl.elfGet hashmaliciousUnknownBrowse
                    mpsl.elfGet hashmaliciousUnknownBrowse
                      aarch64.elfGet hashmaliciousUnknownBrowse
                        sh4.elfGet hashmaliciousUnknownBrowse
                          nimips.elfGet hashmaliciousUnknownBrowse
                            arm6.elfGet hashmaliciousUnknownBrowse
                              104.245.241.61arm7.elfGet hashmaliciousUnknownBrowse
                                mips.elfGet hashmaliciousUnknownBrowse
                                  154.205.155.97mips.elfGet hashmaliciousUnknownBrowse
                                    arm7.elfGet hashmaliciousUnknownBrowse
                                      arm6.elfGet hashmaliciousUnknownBrowse
                                        nimips.elfGet hashmaliciousUnknownBrowse
                                          mips.elfGet hashmaliciousUnknownBrowse
                                            arm.elfGet hashmaliciousUnknownBrowse
                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                156.244.44.239mips.elfGet hashmaliciousUnknownBrowse
                                                  nimips.elfGet hashmaliciousUnknownBrowse
                                                    sh4.elfGet hashmaliciousUnknownBrowse
                                                      arm7.elfGet hashmaliciousUnknownBrowse
                                                        No context
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        POWERLINE-AS-APPOWERLINEDATACENTERHKmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 156.244.14.93
                                                        payment slip$34566.exeGet hashmaliciousFormBookBrowse
                                                        • 202.165.121.125
                                                        DHL_AWB#6078538091.exeGet hashmaliciousFormBookBrowse
                                                        • 45.202.215.236
                                                        mips.elfGet hashmaliciousUnknownBrowse
                                                        • 156.244.44.239
                                                        mips.elfGet hashmaliciousMiraiBrowse
                                                        • 156.251.7.171
                                                        dlr.x86.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        dlr.mpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        dlr.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        hoho.sparc.elfGet hashmaliciousUnknownBrowse
                                                        • 45.202.220.126
                                                        POWERLINE-AS-APPOWERLINEDATACENTERHKmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 156.244.14.93
                                                        payment slip$34566.exeGet hashmaliciousFormBookBrowse
                                                        • 202.165.121.125
                                                        DHL_AWB#6078538091.exeGet hashmaliciousFormBookBrowse
                                                        • 45.202.215.236
                                                        mips.elfGet hashmaliciousUnknownBrowse
                                                        • 156.244.44.239
                                                        mips.elfGet hashmaliciousMiraiBrowse
                                                        • 156.251.7.171
                                                        dlr.x86.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        dlr.mpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        dlr.mips.elfGet hashmaliciousUnknownBrowse
                                                        • 156.253.227.12
                                                        hoho.sparc.elfGet hashmaliciousUnknownBrowse
                                                        • 45.202.220.126
                                                        WINDSTREAMUSg4za.mips.elfGet hashmaliciousMiraiBrowse
                                                        • 66.19.208.111
                                                        g4za.arm.elfGet hashmaliciousMiraiBrowse
                                                        • 207.94.133.229
                                                        g4za.spc.elfGet hashmaliciousMiraiBrowse
                                                        • 206.252.166.188
                                                        g4za.x86.elfGet hashmaliciousUnknownBrowse
                                                        • 68.143.234.232
                                                        g4za.ppc.elfGet hashmaliciousMiraiBrowse
                                                        • 66.217.147.19
                                                        arm.fkunigr.elfGet hashmaliciousMiraiBrowse
                                                        • 209.231.102.19
                                                        mips.elfGet hashmaliciousUnknownBrowse
                                                        • 216.73.156.19
                                                        owari.spc.elfGet hashmaliciousUnknownBrowse
                                                        • 66.147.120.234
                                                        owari.arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 66.217.112.244
                                                        owari.i486.elfGet hashmaliciousUnknownBrowse
                                                        • 70.46.105.191
                                                        US-TELEPACIFICUSmips.elfGet hashmaliciousUnknownBrowse
                                                        • 216.146.26.30
                                                        byte.mips.elfGet hashmaliciousOkiruBrowse
                                                        • 64.140.24.148
                                                        ppc.elfGet hashmaliciousUnknownBrowse
                                                        • 69.178.148.199
                                                        SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
                                                        • 216.146.26.30
                                                        arm5.elfGet hashmaliciousUnknownBrowse
                                                        • 216.146.26.30
                                                        cbr.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 65.60.78.35
                                                        jklmips.elfGet hashmaliciousUnknownBrowse
                                                        • 66.81.80.166
                                                        nklmips.elfGet hashmaliciousUnknownBrowse
                                                        • 64.60.67.186
                                                        jklm68k.elfGet hashmaliciousUnknownBrowse
                                                        • 216.146.25.253
                                                        nabmpsl.elfGet hashmaliciousUnknownBrowse
                                                        • 208.57.85.236
                                                        No context
                                                        No context
                                                        Process:/tmp/kmips.elf
                                                        File Type:ASCII text, with no line terminators
                                                        Category:dropped
                                                        Size (bytes):15
                                                        Entropy (8bit):3.5068905956085192
                                                        Encrypted:false
                                                        SSDEEP:3:TgnPCn:TgPC
                                                        MD5:6FB1605EBC2A92CEDFE73B9B290AFE9C
                                                        SHA1:BFD35FBD4EA921668F0FEA9EF6FF3DD7C022C42D
                                                        SHA-256:DBF56F8F11BC960F054D68E3ACD7DF83A76BA74A6A30FE8EAAB453DC72D63809
                                                        SHA-512:33A5778A558988E98FC92703D836D1BE02B8BBBACCD25E4E6F2451561BC1A6380EBCF63551B5EE7D2E336D81D16541A5EE874C57059E9BC679E946C8F1407E5F
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:/tmp/kmips.elf.
                                                        Process:/tmp/kmips.elf
                                                        File Type:ASCII text, with no line terminators
                                                        Category:dropped
                                                        Size (bytes):15
                                                        Entropy (8bit):3.5068905956085192
                                                        Encrypted:false
                                                        SSDEEP:3:TgnPCn:TgPC
                                                        MD5:6FB1605EBC2A92CEDFE73B9B290AFE9C
                                                        SHA1:BFD35FBD4EA921668F0FEA9EF6FF3DD7C022C42D
                                                        SHA-256:DBF56F8F11BC960F054D68E3ACD7DF83A76BA74A6A30FE8EAAB453DC72D63809
                                                        SHA-512:33A5778A558988E98FC92703D836D1BE02B8BBBACCD25E4E6F2451561BC1A6380EBCF63551B5EE7D2E336D81D16541A5EE874C57059E9BC679E946C8F1407E5F
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:/tmp/kmips.elf.
                                                        File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                        Entropy (8bit):5.506623369613711
                                                        TrID:
                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                        File name:kmips.elf
                                                        File size:89'244 bytes
                                                        MD5:e0ee1e0bf964ac7510a3344879e14f63
                                                        SHA1:658551a36a21c375e77f907152ca2d26fe17ae86
                                                        SHA256:16e2a3121bebded41767de961a17d4833bd70f5e31ca7e3cb1f92cb9ce40477a
                                                        SHA512:dd21d2e988542c24beab9ea9976b8b0ab49260957607f6452a24b20bf7bffb4512b4c07009fcad9b63043b13329e41adf06a9ced47d9fc28a666d60ab3f196d5
                                                        SSDEEP:1536:CSpVLUdBwb8qcaSKY8vhQ0K1XCfdbVkD3oICUJCxIbKytQa177XhDwSsPZ8C/y6g:CSpVLUdBwb8qcAYMhJfdbVkD3oICUJCi
                                                        TLSH:C393D94F2E35CFADF26DC33447B74A31A7A923C622E1C685D26CD1151F6024EA45FBA8
                                                        File Content Preview:.ELF.....................@.`...4..Z......4. ...(.............@...@....N ..N ..............P..EP..EP....p..lT........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'..h...!........'94

                                                        ELF header

                                                        Class:ELF32
                                                        Data:2's complement, big endian
                                                        Version:1 (current)
                                                        Machine:MIPS R3000
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:UNIX - System V
                                                        ABI Version:0
                                                        Entry Point Address:0x400260
                                                        Flags:0x1007
                                                        ELF Header Size:52
                                                        Program Header Offset:52
                                                        Program Header Size:32
                                                        Number of Program Headers:3
                                                        Section Header Offset:88764
                                                        Section Header Size:40
                                                        Number of Section Headers:12
                                                        Header String Table Index:11
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                        .textPROGBITS0x4001200x1200x133a00x00x6AX0016
                                                        .finiPROGBITS0x4134c00x134c00x5c0x00x6AX004
                                                        .rodataPROGBITS0x4135200x135200x19000x00x2A0016
                                                        .ctorsPROGBITS0x4550000x150000x80x00x3WA004
                                                        .dtorsPROGBITS0x4550080x150080x80x00x3WA004
                                                        .dataPROGBITS0x4550200x150200x4400x00x3WA0016
                                                        .gotPROGBITS0x4554600x154600x6100x40x10000003WAp0016
                                                        .sbssNOBITS0x455a700x15a700x1c0x00x10000003WAp004
                                                        .bssNOBITS0x455a900x15a700x61c40x00x3WA0016
                                                        .shstrtabSTRTAB0x00x15a700x490x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x4000000x4000000x14e200x14e205.56450x5R E0x10000.init .text .fini .rodata
                                                        LOAD0x150000x4550000x4550000xa700x6c543.60480x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                        Download Network PCAP: filteredfull

                                                        • Total Packets: 83
                                                        • 52962 undefined
                                                        • 50749 undefined
                                                        • 50464 undefined
                                                        • 47563 undefined
                                                        • 45229 undefined
                                                        • 44859 undefined
                                                        • 40237 undefined
                                                        • 40217 undefined
                                                        • 29486 undefined
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Mar 25, 2025 13:29:46.844547987 CET3599450464192.168.2.14156.244.44.239
                                                        Mar 25, 2025 13:29:47.003969908 CET5046435994156.244.44.239192.168.2.14
                                                        Mar 25, 2025 13:29:47.004039049 CET3599450464192.168.2.14156.244.44.239
                                                        Mar 25, 2025 13:29:47.160908937 CET5046435994156.244.44.239192.168.2.14
                                                        Mar 25, 2025 13:29:47.160995960 CET3599450464192.168.2.14156.244.44.239
                                                        Mar 25, 2025 13:29:47.317661047 CET5046435994156.244.44.239192.168.2.14
                                                        Mar 25, 2025 13:29:47.317859888 CET3599450464192.168.2.14156.244.44.239
                                                        Mar 25, 2025 13:29:54.016697884 CET3599450464192.168.2.14156.244.44.239
                                                        Mar 25, 2025 13:29:54.180527925 CET5046435994156.244.44.239192.168.2.14
                                                        Mar 25, 2025 13:29:54.181097031 CET3599450464192.168.2.14156.244.44.239
                                                        Mar 25, 2025 13:29:54.183283091 CET5046435994156.244.44.239192.168.2.14
                                                        Mar 25, 2025 13:29:54.183340073 CET3599450464192.168.2.14156.244.44.239
                                                        Mar 25, 2025 13:29:54.337487936 CET5046435994156.244.44.239192.168.2.14
                                                        Mar 25, 2025 13:29:55.182876110 CET4685052962192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:29:55.344408035 CET5296246850216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:29:55.344789028 CET4685052962192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:29:55.505234957 CET5296246850216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:29:55.505381107 CET4685052962192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:29:55.664376974 CET5296246850216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:29:55.664480925 CET4685052962192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:30:02.352634907 CET4685052962192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:30:02.511259079 CET5296246850216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:30:02.511286020 CET5296246850216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:30:02.511466980 CET4685052962192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:30:02.670414925 CET5296246850216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:30:03.513744116 CET5085245229192.168.2.14156.244.14.93
                                                        Mar 25, 2025 13:30:03.670211077 CET4522950852156.244.14.93192.168.2.14
                                                        Mar 25, 2025 13:30:03.670541048 CET5085245229192.168.2.14156.244.14.93
                                                        Mar 25, 2025 13:30:03.826860905 CET4522950852156.244.14.93192.168.2.14
                                                        Mar 25, 2025 13:30:03.827069998 CET5085245229192.168.2.14156.244.14.93
                                                        Mar 25, 2025 13:30:03.986196041 CET4522950852156.244.14.93192.168.2.14
                                                        Mar 25, 2025 13:30:03.986485004 CET5085245229192.168.2.14156.244.14.93
                                                        Mar 25, 2025 13:30:10.677314043 CET5085245229192.168.2.14156.244.14.93
                                                        Mar 25, 2025 13:30:10.832622051 CET4522950852156.244.14.93192.168.2.14
                                                        Mar 25, 2025 13:30:10.832644939 CET4522950852156.244.14.93192.168.2.14
                                                        Mar 25, 2025 13:30:10.832818031 CET5085245229192.168.2.14156.244.14.93
                                                        Mar 25, 2025 13:30:10.988051891 CET4522950852156.244.14.93192.168.2.14
                                                        Mar 25, 2025 13:30:11.836193085 CET4814247563192.168.2.14216.146.26.30
                                                        Mar 25, 2025 13:30:12.333035946 CET4756348142216.146.26.30192.168.2.14
                                                        Mar 25, 2025 13:30:12.333142042 CET4814247563192.168.2.14216.146.26.30
                                                        Mar 25, 2025 13:30:12.828381062 CET4756348142216.146.26.30192.168.2.14
                                                        Mar 25, 2025 13:30:12.828475952 CET4814247563192.168.2.14216.146.26.30
                                                        Mar 25, 2025 13:30:13.324837923 CET4756348142216.146.26.30192.168.2.14
                                                        Mar 25, 2025 13:30:13.324963093 CET4814247563192.168.2.14216.146.26.30
                                                        Mar 25, 2025 13:30:19.341007948 CET4814247563192.168.2.14216.146.26.30
                                                        Mar 25, 2025 13:30:19.838654041 CET4756348142216.146.26.30192.168.2.14
                                                        Mar 25, 2025 13:30:19.838712931 CET4756348142216.146.26.30192.168.2.14
                                                        Mar 25, 2025 13:30:19.838898897 CET4814247563192.168.2.14216.146.26.30
                                                        Mar 25, 2025 13:30:20.335700035 CET4756348142216.146.26.30192.168.2.14
                                                        Mar 25, 2025 13:30:20.841777086 CET4305845229192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:30:21.000432014 CET4522943058156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:30:21.000662088 CET4305845229192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:30:21.163260937 CET4522943058156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:30:21.163511038 CET4305845229192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:30:21.324502945 CET4522943058156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:30:21.324765921 CET4305845229192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:30:28.009025097 CET4305845229192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:30:28.168040037 CET4522943058156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:30:28.168086052 CET4522943058156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:30:28.168302059 CET4305845229192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:30:28.325037956 CET4522943058156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:30:29.170443058 CET3927044859192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:30:29.327714920 CET4485939270154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:30:29.327864885 CET3927044859192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:30:29.486331940 CET4485939270154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:30:29.486475945 CET3927044859192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:30:29.643809080 CET4485939270154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:30:29.643968105 CET3927044859192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:30:36.334784985 CET3927044859192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:30:36.490688086 CET4485939270154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:30:36.490750074 CET4485939270154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:30:36.490852118 CET3927044859192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:30:36.984251022 CET3927044859192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:30:37.143106937 CET4485939270154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:30:37.494067907 CET3828240217192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:37.892537117 CET4021738282104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:37.892888069 CET3828240217192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:38.290021896 CET4021738282104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:38.290344000 CET3828240217192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:38.689172983 CET4021738282104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:38.689498901 CET3828240217192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:44.900450945 CET3828240217192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:45.325298071 CET4021738282104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:45.325330973 CET4021738282104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:45.325522900 CET3828240217192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:45.728895903 CET4021738282104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:46.327260971 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:46.729414940 CET4023735464104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:46.729561090 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:47.137428999 CET4023735464104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:47.137641907 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:47.535381079 CET4023735464104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:47.536278009 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:53.736737967 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:54.775644064 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:55.992289066 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:58.423377991 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:58.821639061 CET4023735464104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:58.821669102 CET4023735464104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:58.822035074 CET3546440237192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:30:59.221270084 CET4023735464104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:30:59.824505091 CET4923650749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:30:59.980393887 CET5074949236156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:30:59.980621099 CET4923650749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:00.136583090 CET5074949236156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:00.136743069 CET4923650749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:00.291878939 CET5074949236156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:00.292354107 CET4923650749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:06.989685059 CET4923650749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:07.199640036 CET5074949236156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:07.199671984 CET5074949236156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:07.200047970 CET4923650749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:07.703053951 CET4923650749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:07.883933067 CET5074949236156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:08.202327967 CET5589229486192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:31:08.358733892 CET2948655892154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:31:08.358900070 CET5589229486192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:31:08.516326904 CET2948655892154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:31:08.516521931 CET5589229486192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:31:08.672934055 CET2948655892154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:31:08.673105001 CET5589229486192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:31:15.367538929 CET5589229486192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:31:15.523921967 CET2948655892154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:31:15.523951054 CET2948655892154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:31:15.524139881 CET5589229486192.168.2.14154.205.155.97
                                                        Mar 25, 2025 13:31:15.681482077 CET2948655892154.205.155.97192.168.2.14
                                                        Mar 25, 2025 13:31:16.526462078 CET4397629486192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:31:16.926640034 CET2948643976104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:31:16.926848888 CET4397629486192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:31:17.328069925 CET2948643976104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:31:17.328280926 CET4397629486192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:31:17.728961945 CET2948643976104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:31:17.729178905 CET4397629486192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:31:23.443677902 CET2948643976104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:31:23.443797112 CET4397629486192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:31:23.934956074 CET4397629486192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:31:24.344326973 CET2948643976104.245.241.61192.168.2.14
                                                        Mar 25, 2025 13:31:24.344436884 CET4397629486192.168.2.14104.245.241.61
                                                        Mar 25, 2025 13:31:38.950761080 CET4924250749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:39.106345892 CET5074949242156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:39.106667995 CET4924250749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:39.263746977 CET5074949242156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:39.263906002 CET4924250749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:39.420466900 CET5074949242156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:39.420762062 CET4924250749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:46.111885071 CET4924250749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:46.271254063 CET5074949242156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:46.271281958 CET5074949242156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:46.271467924 CET4924250749192.168.2.14156.244.45.113
                                                        Mar 25, 2025 13:31:46.428200960 CET5074949242156.244.45.113192.168.2.14
                                                        Mar 25, 2025 13:31:47.273885965 CET5586045229192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:31:47.448424101 CET4522955860216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:31:47.448846102 CET5586045229192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:31:47.611140966 CET4522955860216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:31:47.611562014 CET5586045229192.168.2.14216.73.156.19
                                                        Mar 25, 2025 13:31:47.782105923 CET4522955860216.73.156.19192.168.2.14
                                                        Mar 25, 2025 13:31:47.782263041 CET5586045229192.168.2.14216.73.156.19

                                                        System Behavior

                                                        Start time (UTC):12:29:45
                                                        Start date (UTC):25/03/2025
                                                        Path:/tmp/kmips.elf
                                                        Arguments:-
                                                        File size:5777432 bytes
                                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c