Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1649607
MD5:6e7311ae5648ac9c161f204032258d35
SHA1:74dd4f2d73a98cd34355f93f8949f7bbf181c868
SHA256:fba7bebf259ea5904705b2ce98b73a7ef017b7cf64565779a1afdfc437a46ef0
Tags:elfuser-abuse_ch
Infos:
Errors
  • No or unstable Internet during analysis

Detection

Score:60
Range:0 - 100

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1649607
Start date and time:2025-03-26 23:41:38 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 11s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal60.troj.linELF@0/2@0/0
  • No or unstable Internet during analysis
  • Excluded IPs from analysis (whitelisted): 8.8.8.8
Command:/tmp/mips.elf
PID:5833
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • mips.elf (PID: 5833, Parent: 5759, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 5836, Parent: 5833)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfAvira: detected
Source: mips.elfReversingLabs: Detection: 19%

Networking

barindex
Source: global trafficTCP traffic: 156.244.44.239 ports 44859,35086,40217,0,1,2,26141,4,7
Source: global trafficTCP traffic: 216.146.26.30 ports 50749,0,4,5,7,9,12016
Source: global trafficTCP traffic: 154.205.155.243 ports 29486,2,4,6,8,9
Source: global trafficTCP traffic: 156.244.14.93 ports 50749,56190,0,4,5,7,9
Source: global trafficTCP traffic: 104.245.241.61 ports 41763,1,3,4,6,7,52962
Source: global trafficTCP traffic: 192.168.2.15:55948 -> 156.244.45.113:7679
Source: global trafficTCP traffic: 192.168.2.15:42664 -> 156.244.14.93:50749
Source: global trafficTCP traffic: 192.168.2.15:33364 -> 216.146.26.30:50749
Source: global trafficTCP traffic: 192.168.2.15:38426 -> 154.205.155.243:29486
Source: global trafficTCP traffic: 192.168.2.15:39584 -> 156.244.44.239:40217
Source: global trafficTCP traffic: 192.168.2.15:36398 -> 104.245.241.61:41763
Source: /tmp/mips.elf (PID: 5836)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.45.113
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.44.239
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 156.244.14.93
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: mips.elf, 5833.1.00007fb488456000.00007fb488460000.rw-.sdmpString found in binary or memory: http://0/t/wget.sh
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.troj.linELF@0/2@0/0
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/5818/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1333/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1695/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/911/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/3753/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/914/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1591/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1/mapsJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1585/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/5820/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/802/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/804/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/3407/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1484/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/133/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1479/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/931/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1595/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/812/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/933/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/3419/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/3310/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/262/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/142/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/263/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/264/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/265/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/145/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/266/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/267/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/268/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/3303/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/269/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)File opened: /proc/1486/cmdlineJump to behavior
Source: /tmp/mips.elf (PID: 5833)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 5833.1.00007fb488456000.00007fb488460000.rw-.sdmpBinary or memory string: vmwarem
Source: mips.elf, 5833.1.000056544f33b000.000056544f3e2000.rw-.sdmpBinary or memory string: 5OTV 5OTV!/etc/qemu-binfmt/mips
Source: mips.elf, 5833.1.00007fb488456000.00007fb488460000.rw-.sdmpBinary or memory string: vmware
Source: mips.elf, 5833.1.00007fb488456000.00007fb488460000.rw-.sdmpBinary or memory string: qemu-arm2QB
Source: mips.elf, 5833.1.00007fb488456000.00007fb488460000.rw-.sdmpBinary or memory string: qemu-arm
Source: mips.elf, 5833.1.000056544f33b000.000056544f3e2000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 5833.1.00007fff806e2000.00007fff80703000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 5833.1.00007fff806e2000.00007fff80703000.rw-.sdmpBinary or memory string: %s/qemu-op
Source: mips.elf, 5833.1.00007fff806e2000.00007fff80703000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
Source: mips.elf, 5833.1.00007fff806e2000.00007fff80703000.rw-.sdmpBinary or memory string: KTV/tmp/qemu-open.do8eLe\
Source: mips.elf, 5833.1.00007fff806e2000.00007fff80703000.rw-.sdmpBinary or memory string: /tmp/qemu-open.do8eLe
Source: mips.elf, 5833.1.00007fff806e2000.00007fff80703000.rw-.sdmpBinary or memory string: MPDIR%s/qemu-op
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1649607 Sample: mips.elf Startdate: 26/03/2025 Architecture: LINUX Score: 60 11 216.146.26.30, 12016, 33364, 46732 US-TELEPACIFICUS Reserved 2->11 13 156.244.14.93, 42664, 44476, 50749 POWERLINE-AS-APPOWERLINEDATACENTERHK Seychelles 2->13 15 4 other IPs or domains 2->15 17 Antivirus / Scanner detection for submitted sample 2->17 19 Multi AV Scanner detection for submitted file 2->19 21 Connects to many ports of the same IP (likely port scanning) 2->21 7 mips.elf 2->7         started        signatures3 process4 process5 9 mips.elf 7->9         started       
SourceDetectionScannerLabelLink
mips.elf19%ReversingLabsLinux.Trojan.Mirai
mips.elf100%AviraEXP/ELF.Agent.J.8
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://0/t/wget.shmips.elf, 5833.1.00007fb488456000.00007fb488460000.rw-.sdmpfalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    216.146.26.30
    unknownReserved
    11915US-TELEPACIFICUStrue
    156.244.45.113
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKfalse
    154.205.155.243
    unknownSeychelles
    26484IKGUL-26484UStrue
    156.244.14.93
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
    104.245.241.61
    unknownUnited States
    8100ASN-QUADRANET-GLOBALUStrue
    156.244.44.239
    unknownSeychelles
    132839POWERLINE-AS-APPOWERLINEDATACENTERHKtrue
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    216.146.26.30kmips.elfGet hashmaliciousUnknownBrowse
      mips.elfGet hashmaliciousUnknownBrowse
        SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
          arm5.elfGet hashmaliciousUnknownBrowse
            156.244.45.113aarch64.elfGet hashmaliciousUnknownBrowse
              kmips.elfGet hashmaliciousUnknownBrowse
                mips.elfGet hashmaliciousUnknownBrowse
                  ppc.elfGet hashmaliciousUnknownBrowse
                    arm.elfGet hashmaliciousUnknownBrowse
                      154.205.155.243ppc.elfGet hashmaliciousUnknownBrowse
                        mips.elfGet hashmaliciousUnknownBrowse
                          SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
                            aarch64.elfGet hashmaliciousUnknownBrowse
                              nimips.elfGet hashmaliciousUnknownBrowse
                                156.244.14.93ppc.elfGet hashmaliciousUnknownBrowse
                                  arm.elfGet hashmaliciousUnknownBrowse
                                    kmips.elfGet hashmaliciousUnknownBrowse
                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                        mpsl.elfGet hashmaliciousUnknownBrowse
                                          aarch64.elfGet hashmaliciousUnknownBrowse
                                            sh4.elfGet hashmaliciousUnknownBrowse
                                              nimips.elfGet hashmaliciousUnknownBrowse
                                                arm6.elfGet hashmaliciousUnknownBrowse
                                                  No context
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  IKGUL-26484USppc.elfGet hashmaliciousUnknownBrowse
                                                  • 154.205.155.97
                                                  boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 156.238.135.139
                                                  boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                  • 156.251.85.203
                                                  boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                  • 156.251.85.209
                                                  boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                  • 156.251.85.206
                                                  boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 156.249.132.40
                                                  boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                  • 156.238.135.154
                                                  boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                  • 156.238.135.196
                                                  boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                  • 156.238.135.163
                                                  sh4.elfGet hashmaliciousUnknownBrowse
                                                  • 154.205.155.97
                                                  POWERLINE-AS-APPOWERLINEDATACENTERHKppc.elfGet hashmaliciousUnknownBrowse
                                                  • 156.244.14.93
                                                  arm.elfGet hashmaliciousUnknownBrowse
                                                  • 156.244.14.93
                                                  UuhANT$345432.exeGet hashmaliciousFormBookBrowse
                                                  • 202.165.121.125
                                                  boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                  • 156.251.7.178
                                                  boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                  • 156.242.206.58
                                                  boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                  • 156.251.3.5
                                                  boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 156.242.206.57
                                                  aarch64.elfGet hashmaliciousUnknownBrowse
                                                  • 156.244.45.113
                                                  boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                  • 156.251.7.175
                                                  boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                  • 156.242.206.23
                                                  US-TELEPACIFICUSkmips.elfGet hashmaliciousUnknownBrowse
                                                  • 216.146.26.30
                                                  mips.elfGet hashmaliciousUnknownBrowse
                                                  • 216.146.26.30
                                                  byte.mips.elfGet hashmaliciousOkiruBrowse
                                                  • 64.140.24.148
                                                  ppc.elfGet hashmaliciousUnknownBrowse
                                                  • 69.178.148.199
                                                  SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
                                                  • 216.146.26.30
                                                  arm5.elfGet hashmaliciousUnknownBrowse
                                                  • 216.146.26.30
                                                  cbr.x86.elfGet hashmaliciousMiraiBrowse
                                                  • 65.60.78.35
                                                  jklmips.elfGet hashmaliciousUnknownBrowse
                                                  • 66.81.80.166
                                                  nklmips.elfGet hashmaliciousUnknownBrowse
                                                  • 64.60.67.186
                                                  jklm68k.elfGet hashmaliciousUnknownBrowse
                                                  • 216.146.25.253
                                                  No context
                                                  No context
                                                  Process:/tmp/mips.elf
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):14
                                                  Entropy (8bit):3.378783493486176
                                                  Encrypted:false
                                                  SSDEEP:3:TgaLGn:TgAG
                                                  MD5:640E98E7A87EC50F267F24DBC141D4DD
                                                  SHA1:BC19B1CF25759386125D933665A8B429D9AE7E26
                                                  SHA-256:6976993806B7CE05EA0AAA6BC975462833B19CF0D6DD4C9480F26FBAF66AF31D
                                                  SHA-512:3887FBDFA33FF58EF35DDD9B1A2C9BDD611208904D8D371B2AFFE6E97F4C2EDA7A5BAA9786BDD3857AB6B31FE933CBE7290E7D9223671670A9BC739D457D4BA9
                                                  Malicious:false
                                                  Reputation:moderate, very likely benign file
                                                  Preview:/tmp/mips.elf.
                                                  Process:/tmp/mips.elf
                                                  File Type:data
                                                  Category:dropped
                                                  Size (bytes):14
                                                  Entropy (8bit):3.378783493486176
                                                  Encrypted:false
                                                  SSDEEP:3:TgaLGn:TgAG
                                                  MD5:640E98E7A87EC50F267F24DBC141D4DD
                                                  SHA1:BC19B1CF25759386125D933665A8B429D9AE7E26
                                                  SHA-256:6976993806B7CE05EA0AAA6BC975462833B19CF0D6DD4C9480F26FBAF66AF31D
                                                  SHA-512:3887FBDFA33FF58EF35DDD9B1A2C9BDD611208904D8D371B2AFFE6E97F4C2EDA7A5BAA9786BDD3857AB6B31FE933CBE7290E7D9223671670A9BC739D457D4BA9
                                                  Malicious:false
                                                  Reputation:moderate, very likely benign file
                                                  Preview:/tmp/mips.elf.
                                                  File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                  Entropy (8bit):5.527375229379303
                                                  TrID:
                                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                  File name:mips.elf
                                                  File size:89'956 bytes
                                                  MD5:6e7311ae5648ac9c161f204032258d35
                                                  SHA1:74dd4f2d73a98cd34355f93f8949f7bbf181c868
                                                  SHA256:fba7bebf259ea5904705b2ce98b73a7ef017b7cf64565779a1afdfc437a46ef0
                                                  SHA512:058a3fd7870bcfbb24ce687c22aab2ef5148ce17b094412e61a6f3d08586c9751c22e229332b6531381be3efccd3e39216c92fc8d5480cd95f3acb768e8b3739
                                                  SSDEEP:1536:vVBgYjZ1KHfakBPjwFW1r0/1Rq8+znTray7WeGKdNc2:vVBZjGHfakBkFW1B8+znj7BdD
                                                  TLSH:B193D74E2E75CFADF369C33447B74A31A3A923C522E1C685D2ACD1151F7024EA41FBA8
                                                  File Content Preview:.ELF.....................@.`...4..]......4. ...(.............@...@....R...R...............R..ER..ER....T..l@........dt.Q............................<...'......!'.......................<...'..x...!... ....'9... ......................<...'..H...!........'99

                                                  ELF header

                                                  Class:ELF32
                                                  Data:2's complement, big endian
                                                  Version:1 (current)
                                                  Machine:MIPS R3000
                                                  Version Number:0x1
                                                  Type:EXEC (Executable file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x400260
                                                  Flags:0x1007
                                                  ELF Header Size:52
                                                  Program Header Offset:52
                                                  Program Header Size:32
                                                  Number of Program Headers:3
                                                  Section Header Offset:89476
                                                  Section Header Size:40
                                                  Number of Section Headers:12
                                                  Header String Table Index:11
                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                  NULL0x00x00x00x00x0000
                                                  .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                  .textPROGBITS0x4001200x1200x138a00x00x6AX0016
                                                  .finiPROGBITS0x4139c00x139c00x5c0x00x6AX004
                                                  .rodataPROGBITS0x413a200x13a200x18c00x00x2A0016
                                                  .ctorsPROGBITS0x4552e40x152e40x80x00x3WA004
                                                  .dtorsPROGBITS0x4552ec0x152ec0x80x00x3WA004
                                                  .dataPROGBITS0x4553000x153000x4400x00x3WA0016
                                                  .gotPROGBITS0x4557400x157400x5f80x40x10000003WAp0016
                                                  .sbssNOBITS0x455d380x15d380x1c0x00x10000003WAp004
                                                  .bssNOBITS0x455d600x15d380x61c40x00x3WA0016
                                                  .shstrtabSTRTAB0x00x15d380x490x00x0001
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  LOAD0x00x4000000x4000000x152e00x152e05.56210x5R E0x10000.init .text .fini .rodata
                                                  LOAD0x152e40x4552e40x4552e40xa540x6c403.69290x6RW 0x10000.ctors .dtors .data .got .sbss .bss
                                                  GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                  Download Network PCAP: filteredfull

                                                  • Total Packets: 110
                                                  • 2 Ports have been hidden.
                                                  • 53 (DNS)
                                                  • 7679 undefined
                                                  • 12016 undefined
                                                  • 26141 undefined
                                                  • 29486 undefined
                                                  • 35086 undefined
                                                  • 40217 undefined
                                                  • 41763 undefined
                                                  • 44859 undefined
                                                  • 50749 undefined
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Mar 26, 2025 23:42:54.728703976 CET559487679192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:42:54.885998964 CET767955948156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:42:54.886076927 CET559487679192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:42:55.043667078 CET767955948156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:42:55.043971062 CET559487679192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:42:55.201464891 CET767955948156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:42:55.201864004 CET559487679192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:01.903973103 CET559487679192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:02.061362982 CET767955948156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:02.061394930 CET767955948156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:02.061846972 CET559487679192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:02.221658945 CET767955948156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:03.064368010 CET4266450749192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:03.223440886 CET5074942664156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:03.223885059 CET4266450749192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:03.383402109 CET5074942664156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:03.383640051 CET4266450749192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:03.544037104 CET5074942664156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:03.544178009 CET4266450749192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:10.233547926 CET4266450749192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:10.395262003 CET5074942664156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:10.395328045 CET5074942664156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:10.395639896 CET4266450749192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:10.557399988 CET5074942664156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:11.398881912 CET3336450749192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:43:11.907267094 CET5074933364216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:43:11.907463074 CET3336450749192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:43:12.416418076 CET5074933364216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:43:12.416737080 CET3336450749192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:43:12.926847935 CET5074933364216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:43:12.927026987 CET3336450749192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:43:18.915134907 CET3336450749192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:43:19.424338102 CET5074933364216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:43:19.424371004 CET5074933364216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:43:19.424967051 CET3336450749192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:43:19.939029932 CET5074933364216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:43:20.428719044 CET3842629486192.168.2.15154.205.155.243
                                                  Mar 26, 2025 23:43:20.588051081 CET2948638426154.205.155.243192.168.2.15
                                                  Mar 26, 2025 23:43:20.588323116 CET3842629486192.168.2.15154.205.155.243
                                                  Mar 26, 2025 23:43:20.747797966 CET2948638426154.205.155.243192.168.2.15
                                                  Mar 26, 2025 23:43:20.748054981 CET3842629486192.168.2.15154.205.155.243
                                                  Mar 26, 2025 23:43:20.908318996 CET2948638426154.205.155.243192.168.2.15
                                                  Mar 26, 2025 23:43:20.908617973 CET3842629486192.168.2.15154.205.155.243
                                                  Mar 26, 2025 23:43:27.597690105 CET3842629486192.168.2.15154.205.155.243
                                                  Mar 26, 2025 23:43:27.756694078 CET2948638426154.205.155.243192.168.2.15
                                                  Mar 26, 2025 23:43:27.756719112 CET2948638426154.205.155.243192.168.2.15
                                                  Mar 26, 2025 23:43:27.757066965 CET3842629486192.168.2.15154.205.155.243
                                                  Mar 26, 2025 23:43:27.916224957 CET2948638426154.205.155.243192.168.2.15
                                                  Mar 26, 2025 23:43:28.762232065 CET5970635086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:28.921164989 CET3508659706156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:28.921479940 CET5970635086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:29.080447912 CET3508659706156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:29.080782890 CET5970635086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:29.239200115 CET3508659706156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:29.239645004 CET5970635086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:35.933760881 CET5970635086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:36.092403889 CET3508659706156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:36.092437029 CET3508659706156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:36.092978001 CET5970635086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:43:36.251559973 CET3508659706156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:43:37.098130941 CET3958440217192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:43:37.257586002 CET4021739584156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:43:37.257833958 CET3958440217192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:43:37.417252064 CET4021739584156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:43:37.417392969 CET3958440217192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:43:37.576670885 CET4021739584156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:43:37.576961994 CET3958440217192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:43:44.266957045 CET3958440217192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:43:44.426707983 CET4021739584156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:43:44.426754951 CET4021739584156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:43:44.427516937 CET3958440217192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:43:44.586909056 CET4021739584156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:43:45.434916973 CET3639841763192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:43:45.832554102 CET4176336398104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:43:45.833175898 CET3639841763192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:43:46.232450008 CET4176336398104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:43:46.232618093 CET3639841763192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:43:46.630223989 CET4176336398104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:43:46.630665064 CET3639841763192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:43:52.846031904 CET3639841763192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:43:53.243508101 CET4176336398104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:43:53.243558884 CET4176336398104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:43:53.244188070 CET3639841763192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:43:53.641294956 CET4176336398104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:43:54.250494957 CET4447656190192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:54.410640001 CET5619044476156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:54.410996914 CET4447656190192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:54.569989920 CET5619044476156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:54.570389986 CET4447656190192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:43:54.729429007 CET5619044476156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:43:54.729840994 CET4447656190192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:44:01.424505949 CET4447656190192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:44:01.583610058 CET5619044476156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:44:01.583635092 CET5619044476156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:44:01.584217072 CET4447656190192.168.2.15156.244.14.93
                                                  Mar 26, 2025 23:44:01.744683027 CET5619044476156.244.14.93192.168.2.15
                                                  Mar 26, 2025 23:44:02.589586020 CET4673212016192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:44:03.086661100 CET1201646732216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:44:03.087066889 CET4673212016192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:44:03.583992958 CET1201646732216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:44:03.584378004 CET4673212016192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:44:04.080696106 CET1201646732216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:44:04.081078053 CET4673212016192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:44:08.647301912 CET1201646732216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:44:08.647702932 CET4673212016192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:44:10.097963095 CET4673212016192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:44:10.594285011 CET1201646732216.146.26.30192.168.2.15
                                                  Mar 26, 2025 23:44:10.594611883 CET4673212016192.168.2.15216.146.26.30
                                                  Mar 26, 2025 23:44:25.115266085 CET3349052962192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:44:25.507771969 CET5296233490104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:44:25.508284092 CET3349052962192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:44:25.900991917 CET5296233490104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:44:25.901281118 CET3349052962192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:44:26.294784069 CET5296233490104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:44:26.295032024 CET3349052962192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:44:32.519563913 CET3349052962192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:44:32.912312984 CET5296233490104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:44:32.912379026 CET5296233490104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:44:32.912986994 CET3349052962192.168.2.15104.245.241.61
                                                  Mar 26, 2025 23:44:33.305638075 CET5296233490104.245.241.61192.168.2.15
                                                  Mar 26, 2025 23:44:33.920221090 CET4133626141192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:34.078593969 CET2614141336156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:34.079140902 CET4133626141192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:34.236901045 CET2614141336156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:34.237392902 CET4133626141192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:34.395004988 CET2614141336156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:34.395416975 CET4133626141192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:41.091449976 CET4133626141192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:41.250171900 CET2614141336156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:41.250684977 CET2614141336156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:41.251090050 CET4133626141192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:41.408488035 CET2614141336156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:42.255589008 CET5972035086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:44:42.414190054 CET3508659720156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:44:42.414747000 CET5972035086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:44:42.573384047 CET3508659720156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:44:42.573977947 CET5972035086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:44:42.733549118 CET3508659720156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:44:42.734154940 CET5972035086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:44:49.426646948 CET5972035086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:44:49.585236073 CET3508659720156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:44:49.585283995 CET3508659720156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:44:49.586071014 CET5972035086192.168.2.15156.244.45.113
                                                  Mar 26, 2025 23:44:49.744685888 CET3508659720156.244.45.113192.168.2.15
                                                  Mar 26, 2025 23:44:50.592206001 CET4841035086192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:50.751580000 CET3508648410156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:50.751929045 CET4841035086192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:50.911425114 CET3508648410156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:50.911680937 CET4841035086192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:51.070628881 CET3508648410156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:51.070966005 CET4841035086192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:57.764691114 CET4841035086192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:57.923832893 CET3508648410156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:57.923865080 CET3508648410156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:57.924606085 CET4841035086192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:58.083606958 CET3508648410156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:58.929074049 CET4640644859192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:59.088063955 CET4485946406156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:59.088454008 CET4640644859192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:59.247992992 CET4485946406156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:59.248259068 CET4640644859192.168.2.15156.244.44.239
                                                  Mar 26, 2025 23:44:59.407603979 CET4485946406156.244.44.239192.168.2.15
                                                  Mar 26, 2025 23:44:59.407763004 CET4640644859192.168.2.15156.244.44.239
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Mar 26, 2025 23:42:57.893579006 CET3969553192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:42:59.895884037 CET5541453192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:43:04.226950884 CET4112353192.168.2.15208.67.220.220
                                                  Mar 26, 2025 23:43:06.229341984 CET4432053192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:43:08.231439114 CET5945253192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:14.912617922 CET4263753192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:43:16.912847996 CET3292053192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:21.590353966 CET3451053192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:43:23.592611074 CET3931753192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:43:29.926527977 CET4866053192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:31.929013968 CET3312553192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:38.261544943 CET4456853192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:40.263981104 CET5469153192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:42.264324903 CET4092953192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:46.838907957 CET5144353192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:48.841423988 CET5615153192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:43:55.417262077 CET4550253192.168.2.15208.67.220.220
                                                  Mar 26, 2025 23:43:57.419816971 CET5585253192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:43:59.421962976 CET5592653192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:44:06.094038010 CET4282153192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:44:26.512605906 CET5727453192.168.2.15208.67.220.220
                                                  Mar 26, 2025 23:44:35.084455013 CET5107753192.168.2.158.8.4.4
                                                  Mar 26, 2025 23:44:37.086973906 CET4681353192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:44:43.419655085 CET5528253192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:44:47.424252987 CET5325653192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:44:53.759989023 CET3563153192.168.2.15208.67.222.222
                                                  Mar 26, 2025 23:44:55.762342930 CET3461553192.168.2.158.8.4.4

                                                  System Behavior

                                                  Start time (UTC):22:42:53
                                                  Start date (UTC):26/03/2025
                                                  Path:/tmp/mips.elf
                                                  Arguments:-
                                                  File size:5777432 bytes
                                                  MD5 hash:0083f1f0e77be34ad27f849842bbb00c