Edit tour

Linux Analysis Report
ppc.elf

Overview

General Information

Sample name:ppc.elf
Analysis ID:1649605
MD5:c824fa5ad8c06656ff213f840a5a2706
SHA1:727a9060993ca8d82b6a9a6d5d13e66164cf4265
SHA256:8903fe9cf6c0a39b21500c9379b7f6c2c16a1ae62215a38d73be579674fe8b63
Tags:elfuser-abuse_ch
Infos:
Errors
  • No or unstable Internet during analysis

Detection

Score:52
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1649605
Start date and time:2025-03-26 23:41:15 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 6s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ppc.elf
Detection:MAL
Classification:mal52.troj.linELF@0/2@0/0
  • No or unstable Internet during analysis
  • Excluded IPs from analysis (whitelisted): 8.8.8.8
Command:/tmp/ppc.elf
PID:5569
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • ppc.elf (PID: 5569, Parent: 5486, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/ppc.elf
    • ppc.elf New Fork (PID: 5571, Parent: 5569)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ppc.elfReversingLabs: Detection: 13%

Networking

barindex
Source: global trafficTCP traffic: 104.245.241.64 ports 2,26141,5,6,9,52962
Source: global trafficTCP traffic: 216.73.156.19 ports 29486,2,4,6,8,9
Source: global trafficTCP traffic: 154.205.155.243 ports 35086,0,54780,4,5,7,8
Source: global trafficTCP traffic: 156.244.14.93 ports 50749,2,5,6,9,52962,6958
Source: global trafficTCP traffic: 104.245.241.61 ports 44859,40217,0,1,2,4,7
Source: global trafficTCP traffic: 154.205.155.97 ports 56190,45229,2,4,5,9
Source: global trafficTCP traffic: 192.168.2.14:55882 -> 154.205.155.97:45229
Source: global trafficTCP traffic: 192.168.2.14:38264 -> 104.245.241.61:40217
Source: global trafficTCP traffic: 192.168.2.14:48962 -> 154.205.155.243:54780
Source: global trafficTCP traffic: 192.168.2.14:53446 -> 104.245.241.64:52962
Source: global trafficTCP traffic: 192.168.2.14:47470 -> 156.244.14.93:52962
Source: global trafficTCP traffic: 192.168.2.14:43034 -> 216.73.156.19:29486
Source: /tmp/ppc.elf (PID: 5571)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.97
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.64
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.64
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.64
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.64
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.64
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.64
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 216.73.156.19
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.linELF@0/2@0/0
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3760/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3761/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1583/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/2672/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3759/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1577/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3873/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3758/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1593/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/240/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3094/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/242/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3406/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1/mapsJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/244/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1589/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/245/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3402/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/247/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/806/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/807/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/928/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3420/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/135/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/3412/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/1371/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/ppc.elf (PID: 5569)Queries kernel information via 'uname': Jump to behavior
Source: ppc.elf, 5569.1.00007ffc6bfb8000.00007ffc6bfd9000.rw-.sdmpBinary or memory string: /tmp/qemu-open.xuSLyg
Source: ppc.elf, 5569.1.00007f576c024000.00007f576c02a000.rw-.sdmpBinary or memory string: vmwarep
Source: ppc.elf, 5569.1.000056388ca66000.000056388cb16000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: ppc.elf, 5569.1.00007f576c024000.00007f576c02a000.rw-.sdmpBinary or memory string: vmware
Source: ppc.elf, 5569.1.00007ffc6bfb8000.00007ffc6bfd9000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ppc.elf
Source: ppc.elf, 5569.1.000056388ca66000.000056388cb16000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: ppc.elf, 5569.1.00007ffc6bfb8000.00007ffc6bfd9000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
Source: ppc.elf, 5569.1.00007ffc6bfb8000.00007ffc6bfd9000.rw-.sdmpBinary or memory string: %s/qemu-op
Source: ppc.elf, 5569.1.00007ffc6bfb8000.00007ffc6bfd9000.rw-.sdmpBinary or memory string: 8V/tmp/qemu-open.xuSLyg\$?cX
Source: ppc.elf, 5569.1.00007ffc6bfb8000.00007ffc6bfd9000.rw-.sdmpBinary or memory string: MPDIR%s/qemu-op
Source: ppc.elf, 5569.1.00007f576c024000.00007f576c02a000.rw-.sdmpBinary or memory string: !qemu-arm
Source: ppc.elf, 5569.1.00007f576c024000.00007f576c02a000.rw-.sdmpBinary or memory string: !!a1gAWFxuAXsFWUgBRQAA!!a1gAWFxuAXsAWUgKRXgA!!a1gAWFxuAXsAWEgJR3IA!!a10CWFxuAHsGWVcWQHAA!!a10CWFxuAHsGWVcWQHUA!!aFwAWF9uA3sGW0gLRgAA!!aFwAWFlpG2QBW0gJTwAA!!qemu-arm2QBW0gJTwAA!
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1649605 Sample: ppc.elf Startdate: 26/03/2025 Architecture: LINUX Score: 52 11 216.73.156.19, 29486, 43034 WINDSTREAMUS United States 2->11 13 156.244.14.93, 47470, 50749, 52962 POWERLINE-AS-APPOWERLINEDATACENTERHK Seychelles 2->13 15 4 other IPs or domains 2->15 17 Multi AV Scanner detection for submitted file 2->17 19 Connects to many ports of the same IP (likely port scanning) 2->19 7 ppc.elf 2->7         started        signatures3 process4 process5 9 ppc.elf 7->9         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ppc.elf14%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
104.245.241.64
unknownUnited States
8100ASN-QUADRANET-GLOBALUStrue
154.205.155.243
unknownSeychelles
26484IKGUL-26484UStrue
216.73.156.19
unknownUnited States
7029WINDSTREAMUStrue
156.244.14.93
unknownSeychelles
132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
104.245.241.61
unknownUnited States
8100ASN-QUADRANET-GLOBALUStrue
154.205.155.97
unknownSeychelles
26484IKGUL-26484UStrue
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
104.245.241.64mpsl.elfGet hashmaliciousUnknownBrowse
    arm.elfGet hashmaliciousUnknownBrowse
      arm5.elfGet hashmaliciousUnknownBrowse
        mips.elfGet hashmaliciousUnknownBrowse
          mips.elfGet hashmaliciousUnknownBrowse
            arm5.elfGet hashmaliciousUnknownBrowse
              154.205.155.243mips.elfGet hashmaliciousUnknownBrowse
                SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
                  aarch64.elfGet hashmaliciousUnknownBrowse
                    nimips.elfGet hashmaliciousUnknownBrowse
                      216.73.156.19arm.elfGet hashmaliciousUnknownBrowse
                        kmips.elfGet hashmaliciousUnknownBrowse
                          mips.elfGet hashmaliciousUnknownBrowse
                            156.244.14.93arm.elfGet hashmaliciousUnknownBrowse
                              kmips.elfGet hashmaliciousUnknownBrowse
                                mpsl.elfGet hashmaliciousUnknownBrowse
                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                    aarch64.elfGet hashmaliciousUnknownBrowse
                                      sh4.elfGet hashmaliciousUnknownBrowse
                                        nimips.elfGet hashmaliciousUnknownBrowse
                                          arm6.elfGet hashmaliciousUnknownBrowse
                                            104.245.241.61kmips.elfGet hashmaliciousUnknownBrowse
                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                mips.elfGet hashmaliciousUnknownBrowse
                                                  154.205.155.97sh4.elfGet hashmaliciousUnknownBrowse
                                                    kmips.elfGet hashmaliciousUnknownBrowse
                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                        arm7.elfGet hashmaliciousUnknownBrowse
                                                          arm6.elfGet hashmaliciousUnknownBrowse
                                                            nimips.elfGet hashmaliciousUnknownBrowse
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                                arm.elfGet hashmaliciousUnknownBrowse
                                                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                                                    No context
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    IKGUL-26484USboatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.238.135.139
                                                                    boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.251.85.203
                                                                    boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.251.85.209
                                                                    boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.251.85.206
                                                                    boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.249.132.40
                                                                    boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.238.135.154
                                                                    boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.238.135.196
                                                                    boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.238.135.163
                                                                    sh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 154.205.155.97
                                                                    mips.elfGet hashmaliciousGafgyt, OkiruBrowse
                                                                    • 156.233.94.73
                                                                    POWERLINE-AS-APPOWERLINEDATACENTERHKarm.elfGet hashmaliciousUnknownBrowse
                                                                    • 156.244.14.93
                                                                    UuhANT$345432.exeGet hashmaliciousFormBookBrowse
                                                                    • 202.165.121.125
                                                                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.251.7.178
                                                                    boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.242.206.58
                                                                    boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.251.3.5
                                                                    boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.242.206.57
                                                                    aarch64.elfGet hashmaliciousUnknownBrowse
                                                                    • 156.244.45.113
                                                                    boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.251.7.175
                                                                    boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.242.206.23
                                                                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                    • 156.244.234.131
                                                                    WINDSTREAMUSarm.elfGet hashmaliciousUnknownBrowse
                                                                    • 216.73.156.19
                                                                    g4za.x86Get hashmaliciousUnknownBrowse
                                                                    • 155.212.88.182
                                                                    frosty.sh4.elfGet hashmaliciousUnknownBrowse
                                                                    • 65.23.29.97
                                                                    arm7.elfGet hashmaliciousOkiruBrowse
                                                                    • 173.185.229.87
                                                                    SecuriteInfo.com.Win64.MalwareX-gen.18746.5044.dllGet hashmaliciousUnknownBrowse
                                                                    • 64.52.80.252
                                                                    kmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 216.73.156.19
                                                                    g4za.mips.elfGet hashmaliciousMiraiBrowse
                                                                    • 66.19.208.111
                                                                    g4za.arm.elfGet hashmaliciousMiraiBrowse
                                                                    • 207.94.133.229
                                                                    g4za.spc.elfGet hashmaliciousMiraiBrowse
                                                                    • 206.252.166.188
                                                                    g4za.x86.elfGet hashmaliciousUnknownBrowse
                                                                    • 68.143.234.232
                                                                    ASN-QUADRANET-GLOBALUSmpsl.elfGet hashmaliciousUnknownBrowse
                                                                    • 104.245.241.64
                                                                    arm.elfGet hashmaliciousUnknownBrowse
                                                                    • 104.245.241.64
                                                                    phish_alert_sp2_2.0.0.0.emlGet hashmaliciousHTMLPhisherBrowse
                                                                    • 185.174.100.20
                                                                    #Ud83d#Udd0aAudio_Msg Junklessfoods.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                    • 185.174.100.76
                                                                    #Ud83d#Udd0aAudio_Msg Junklessfoods.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                    • 185.174.100.76
                                                                    kmips.elfGet hashmaliciousUnknownBrowse
                                                                    • 104.245.241.61
                                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                                    • 104.245.241.64
                                                                    #Ud83d#Udd0aAudio_Msg Overlakehospital.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                    • 185.174.100.76
                                                                    #Ud83d#Udd0aAudio_Msg Umanitoba.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                    • 185.174.100.76
                                                                    Play_VM-Now(apply)VWAV.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                    • 185.174.100.76
                                                                    No context
                                                                    No context
                                                                    Process:/tmp/ppc.elf
                                                                    File Type:ASCII text, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):13
                                                                    Entropy (8bit):3.1808329872054406
                                                                    Encrypted:false
                                                                    SSDEEP:3:Tg/cA3:TgkG
                                                                    MD5:B4B673815F84B3C325AF4B636EF3F7E8
                                                                    SHA1:0D795B3294AE13B67B5977896D2C28B777A2216A
                                                                    SHA-256:BA14832061879D30329B0378D53F56199440D741567578D0482343247629A00C
                                                                    SHA-512:DC4969EF1C3132480F4001EB78586B888D6E75CE84121CDF2B9679DA13062DC56604B4E7F1B1BBD205F9CC707B4BF311AAA9C19F0C67224026F270C18FDCD7EF
                                                                    Malicious:false
                                                                    Reputation:moderate, very likely benign file
                                                                    Preview:/tmp/ppc.elf.
                                                                    Process:/tmp/ppc.elf
                                                                    File Type:ASCII text, with no line terminators
                                                                    Category:dropped
                                                                    Size (bytes):13
                                                                    Entropy (8bit):3.1808329872054406
                                                                    Encrypted:false
                                                                    SSDEEP:3:Tg/cA3:TgkG
                                                                    MD5:B4B673815F84B3C325AF4B636EF3F7E8
                                                                    SHA1:0D795B3294AE13B67B5977896D2C28B777A2216A
                                                                    SHA-256:BA14832061879D30329B0378D53F56199440D741567578D0482343247629A00C
                                                                    SHA-512:DC4969EF1C3132480F4001EB78586B888D6E75CE84121CDF2B9679DA13062DC56604B4E7F1B1BBD205F9CC707B4BF311AAA9C19F0C67224026F270C18FDCD7EF
                                                                    Malicious:false
                                                                    Reputation:moderate, very likely benign file
                                                                    Preview:/tmp/ppc.elf.
                                                                    File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                                                                    Entropy (8bit):6.303859193269811
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                    File name:ppc.elf
                                                                    File size:74'612 bytes
                                                                    MD5:c824fa5ad8c06656ff213f840a5a2706
                                                                    SHA1:727a9060993ca8d82b6a9a6d5d13e66164cf4265
                                                                    SHA256:8903fe9cf6c0a39b21500c9379b7f6c2c16a1ae62215a38d73be579674fe8b63
                                                                    SHA512:b7f4759f573e8be3ac7c6290909c65dd350941d76764afba8caff6a80cf7d7f6d8cabe7f3f256df5acf4fa3379c46ddfebb9afd9aba5ed0675452f3a828cc285
                                                                    SSDEEP:1536:oYdQdFswX3rxK0QMNK67aL48QfwjfOXjYNUHrrC:py3PljsaC
                                                                    TLSH:D9734B41B71D0587D2B36DF03B3F2BE1D3EA8D8221A46644784FBB8596B1E321846EDD
                                                                    File Content Preview:.ELF...........................4..!......4. ...(...................... 8.. 8.............. ... ... .......F.........dt.Q.............................!..|......$H...H......$8!. |...N.. .!..|.......?.........!x..../...@..`= ..;. ......+../...A..$8...}).....

                                                                    ELF header

                                                                    Class:ELF32
                                                                    Data:2's complement, big endian
                                                                    Version:1 (current)
                                                                    Machine:PowerPC
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:UNIX - System V
                                                                    ABI Version:0
                                                                    Entry Point Address:0x100001f8
                                                                    Flags:0x0
                                                                    ELF Header Size:52
                                                                    Program Header Offset:52
                                                                    Program Header Size:32
                                                                    Number of Program Headers:3
                                                                    Section Header Offset:74132
                                                                    Section Header Size:40
                                                                    Number of Section Headers:12
                                                                    Header String Table Index:11
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .initPROGBITS0x100000940x940x240x00x6AX004
                                                                    .textPROGBITS0x100000b80xb80x10b640x00x6AX004
                                                                    .finiPROGBITS0x10010c1c0x10c1c0x200x00x6AX004
                                                                    .rodataPROGBITS0x10010c400x10c400x13f80x00x2A008
                                                                    .ctorsPROGBITS0x100220a80x120a80x80x00x3WA004
                                                                    .dtorsPROGBITS0x100220b00x120b00x80x00x3WA004
                                                                    .dataPROGBITS0x100220bc0x120bc0x840x00x3WA004
                                                                    .sdataPROGBITS0x100221400x121400x90x00x3WA004
                                                                    .sbssNOBITS0x1002214c0x121490x280x00x3WA004
                                                                    .bssNOBITS0x100221780x121490x46280x00x3WA008
                                                                    .shstrtabSTRTAB0x00x121490x4b0x00x0001
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    LOAD0x00x100000000x100000000x120380x120386.32710x5R E0x10000.init .text .fini .rodata
                                                                    LOAD0x120a80x100220a80x100220a80xa10x46f84.18910x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4

                                                                    Download Network PCAP: filteredfull

                                                                    • Total Packets: 99
                                                                    • 2 Ports have been hidden.
                                                                    • 53 (DNS)
                                                                    • 6958 undefined
                                                                    • 26141 undefined
                                                                    • 29486 undefined
                                                                    • 35086 undefined
                                                                    • 40217 undefined
                                                                    • 44859 undefined
                                                                    • 45229 undefined
                                                                    • 50749 undefined
                                                                    • 52962 undefined
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Mar 26, 2025 23:42:21.886835098 CET5588245229192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:42:22.048295975 CET4522955882154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:42:22.048507929 CET5588245229192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:42:22.206661940 CET4522955882154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:42:22.206857920 CET5588245229192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:42:22.366022110 CET4522955882154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:42:22.366162062 CET5588245229192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:42:29.066129923 CET5588245229192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:42:29.223786116 CET4522955882154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:42:29.223843098 CET4522955882154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:42:29.224242926 CET5588245229192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:42:29.381285906 CET4522955882154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:42:30.225677013 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:31.247576952 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:33.263554096 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:33.654254913 CET4021738264104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:42:33.654699087 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:34.045017958 CET4021738264104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:42:34.045326948 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:34.435336113 CET4021738264104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:42:34.435686111 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:40.485655069 CET4021738264104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:42:40.485877991 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:40.663127899 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:41.054192066 CET4021738264104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:42:41.054544926 CET3826440217192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:42:55.679423094 CET4896254780192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:42:55.838419914 CET5478048962154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:42:55.838809013 CET4896254780192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:42:56.000634909 CET5478048962154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:42:56.000735044 CET4896254780192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:42:56.159796000 CET5478048962154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:42:56.160049915 CET4896254780192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:43:02.848433971 CET4896254780192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:43:03.007891893 CET5478048962154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:43:03.007925034 CET5478048962154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:43:03.008498907 CET4896254780192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:43:03.168668032 CET5478048962154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:43:04.011760950 CET5344652962192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:04.416667938 CET5296253446104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:04.417079926 CET5344652962192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:04.807713985 CET5296253446104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:04.808132887 CET5344652962192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:05.198743105 CET5296253446104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:05.199302912 CET5344652962192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:11.427453041 CET5344652962192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:11.821192026 CET5296253446104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:11.821261883 CET5296253446104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:11.821746111 CET5344652962192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:12.215579987 CET5296253446104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:12.824855089 CET4747052962192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:12.984116077 CET5296247470156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:12.984430075 CET4747052962192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:13.143050909 CET5296247470156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:13.143388987 CET4747052962192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:13.306993961 CET5296247470156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:13.307372093 CET4747052962192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:19.996365070 CET4747052962192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:20.155011892 CET5296247470156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:20.155258894 CET5296247470156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:20.155670881 CET4747052962192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:20.314404964 CET5296247470156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:21.160604954 CET4303429486192.168.2.14216.73.156.19
                                                                    Mar 26, 2025 23:43:21.316817045 CET2948643034216.73.156.19192.168.2.14
                                                                    Mar 26, 2025 23:43:21.317106009 CET4303429486192.168.2.14216.73.156.19
                                                                    Mar 26, 2025 23:43:21.473540068 CET2948643034216.73.156.19192.168.2.14
                                                                    Mar 26, 2025 23:43:21.473707914 CET4303429486192.168.2.14216.73.156.19
                                                                    Mar 26, 2025 23:43:21.629941940 CET2948643034216.73.156.19192.168.2.14
                                                                    Mar 26, 2025 23:43:21.630405903 CET4303429486192.168.2.14216.73.156.19
                                                                    Mar 26, 2025 23:43:28.326246977 CET4303429486192.168.2.14216.73.156.19
                                                                    Mar 26, 2025 23:43:28.483354092 CET2948643034216.73.156.19192.168.2.14
                                                                    Mar 26, 2025 23:43:28.483378887 CET2948643034216.73.156.19192.168.2.14
                                                                    Mar 26, 2025 23:43:28.484023094 CET4303429486192.168.2.14216.73.156.19
                                                                    Mar 26, 2025 23:43:28.640269041 CET2948643034216.73.156.19192.168.2.14
                                                                    Mar 26, 2025 23:43:29.489707947 CET3620844859192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:43:29.886056900 CET4485936208104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:43:29.886523962 CET3620844859192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:43:30.282684088 CET4485936208104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:43:30.283170938 CET3620844859192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:43:30.678764105 CET4485936208104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:43:30.679223061 CET3620844859192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:43:36.898816109 CET3620844859192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:43:37.296077967 CET4485936208104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:43:37.296112061 CET4485936208104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:43:37.296688080 CET3620844859192.168.2.14104.245.241.61
                                                                    Mar 26, 2025 23:43:37.692148924 CET4485936208104.245.241.61192.168.2.14
                                                                    Mar 26, 2025 23:43:38.300699949 CET555506958192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:38.460064888 CET695855550156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:38.460671902 CET555506958192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:38.621933937 CET695855550156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:38.622396946 CET555506958192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:38.781733990 CET695855550156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:38.782202959 CET555506958192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:45.472531080 CET555506958192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:45.631537914 CET695855550156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:45.631561041 CET695855550156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:45.632133007 CET555506958192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:45.791124105 CET695855550156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:46.636142969 CET5352250749192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:46.795394897 CET5074953522156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:46.795939922 CET5352250749192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:46.957643986 CET5074953522156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:46.957943916 CET5352250749192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:47.117415905 CET5074953522156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:47.117723942 CET5352250749192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:53.807652950 CET5352250749192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:53.968327045 CET5074953522156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:53.968372107 CET5074953522156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:53.969063997 CET5352250749192.168.2.14156.244.14.93
                                                                    Mar 26, 2025 23:43:54.127947092 CET5074953522156.244.14.93192.168.2.14
                                                                    Mar 26, 2025 23:43:54.975379944 CET5784226141192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:55.372520924 CET2614157842104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:55.373049974 CET5784226141192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:55.771826982 CET2614157842104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:55.772157907 CET5784226141192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:43:56.169224977 CET2614157842104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:43:56.169842958 CET5784226141192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:44:02.386601925 CET5784226141192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:44:02.788259029 CET2614157842104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:44:02.788276911 CET2614157842104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:44:02.788858891 CET5784226141192.168.2.14104.245.241.64
                                                                    Mar 26, 2025 23:44:03.187666893 CET2614157842104.245.241.64192.168.2.14
                                                                    Mar 26, 2025 23:44:03.793646097 CET4879856190192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:44:03.952231884 CET5619048798154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:44:03.952687979 CET4879856190192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:44:04.111198902 CET5619048798154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:44:04.111483097 CET4879856190192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:44:04.269841909 CET5619048798154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:44:04.270057917 CET4879856190192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:44:08.864209890 CET5619048798154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:44:08.864521980 CET4879856190192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:44:10.963191032 CET4879856190192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:44:11.122323036 CET5619048798154.205.155.97192.168.2.14
                                                                    Mar 26, 2025 23:44:11.122605085 CET4879856190192.168.2.14154.205.155.97
                                                                    Mar 26, 2025 23:44:26.969264030 CET5447435086192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:44:27.128240108 CET3508654474154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:44:27.128468037 CET5447435086192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:44:27.287528992 CET3508654474154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:44:27.288072109 CET5447435086192.168.2.14154.205.155.243
                                                                    Mar 26, 2025 23:44:27.447129011 CET3508654474154.205.155.243192.168.2.14
                                                                    Mar 26, 2025 23:44:27.447402954 CET5447435086192.168.2.14154.205.155.243
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Mar 26, 2025 23:42:25.060100079 CET4468553192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:42:27.062297106 CET4403453192.168.2.14208.67.220.220
                                                                    Mar 26, 2025 23:42:34.656645060 CET6047353192.168.2.14208.67.220.220
                                                                    Mar 26, 2025 23:42:38.660968065 CET5587553192.168.2.14208.67.220.220
                                                                    Mar 26, 2025 23:42:56.841505051 CET4564153192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:42:58.843766928 CET5918853192.168.2.14208.67.220.220
                                                                    Mar 26, 2025 23:43:00.845956087 CET5631853192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:43:05.420351982 CET5957853192.168.2.14208.67.220.220
                                                                    Mar 26, 2025 23:43:07.422583103 CET5671053192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:43:09.424678087 CET4424553192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:43:13.989442110 CET4520153192.168.2.14208.67.220.220
                                                                    Mar 26, 2025 23:43:15.991601944 CET5113553192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:43:17.993963957 CET4864053192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:43:22.319402933 CET5763053192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:43:24.321866035 CET4787953192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:43:30.891402960 CET5202253192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:43:32.894018888 CET4428753192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:43:34.896245003 CET5909153192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:43:41.467616081 CET5958953192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:43:49.803165913 CET3490653192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:43:51.805362940 CET3489153192.168.2.14208.67.220.220
                                                                    Mar 26, 2025 23:43:56.379687071 CET4611953192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:43:58.382054090 CET6036953192.168.2.14208.67.222.222
                                                                    Mar 26, 2025 23:44:00.384079933 CET4078853192.168.2.148.8.4.4
                                                                    Mar 26, 2025 23:44:04.956809998 CET4169653192.168.2.14208.67.222.222

                                                                    System Behavior

                                                                    Start time (UTC):22:42:21
                                                                    Start date (UTC):26/03/2025
                                                                    Path:/tmp/ppc.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6