Edit tour

Linux Analysis Report
arm5.elf

Overview

General Information

Sample name:arm5.elf
Analysis ID:1654171
MD5:8aca8ee3da7442fdf5355a40b67623ef
SHA1:9d7772aab8b3ccdacff0ae2b87244c3c51670bcc
SHA256:8b0d61491fff9ffeb51c305cc5857a8a3adbf9a6be735bb3f2c6da686186c69a
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100

Signatures

Connects to many ports of the same IP (likely port scanning)
Performs DNS TXT record lookups
Uses STUN server to do NAT traversial
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox version:42.0.0 Malachite
Analysis ID:1654171
Start date and time:2025-04-02 02:48:17 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 44s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm5.elf
Detection:MAL
Classification:mal52.troj.evad.linELF@0/2@6/0
  • VT rate limit hit for: kamru.ru
Command:/tmp/arm5.elf
PID:6214
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
For God so loved the world
Standard Error:
  • system is lnxubuntu20
  • arm5.elf (PID: 6214, Parent: 6134, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm5.elf
    • arm5.elf New Fork (PID: 6216, Parent: 6214)
  • dash New Fork (PID: 6294, Parent: 4332)
  • rm (PID: 6294, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.B8Wk9S6ndI /tmp/tmp.fLcSLLYedY /tmp/tmp.kz78GZHCez
  • dash New Fork (PID: 6295, Parent: 4332)
  • rm (PID: 6295, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.B8Wk9S6ndI /tmp/tmp.fLcSLLYedY /tmp/tmp.kz78GZHCez
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Networking

barindex
Source: global trafficTCP traffic: 154.205.155.243 ports 50749,0,4,5,7,9
Source: unknownDNS query: name: stun.l.google.com
Source: global trafficTCP traffic: 192.168.2.23:41648 -> 104.245.241.61:49722
Source: global trafficTCP traffic: 192.168.2.23:60382 -> 154.205.155.243:50749
Source: global trafficTCP traffic: 192.168.2.23:35720 -> 216.146.26.30:44859
Source: global trafficUDP traffic: 192.168.2.23:47830 -> 74.125.250.129:19302
Source: /tmp/arm5.elf (PID: 6216)Socket: 127.0.0.1:22448Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 104.245.241.61
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 154.205.155.243
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownTCP traffic detected without corresponding DNS query: 216.146.26.30
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.220.220
Source: unknownUDP traffic detected without corresponding DNS query: 208.67.222.222
Source: global trafficDNS traffic detected: DNS query: kamru.ru
Source: global trafficDNS traffic detected: DNS query: stun.l.google.com
Source: arm5.elf, 6214.1.00007f5da0034000.00007f5da003a000.rw-.sdmpString found in binary or memory: https://motd.ubuntu.com
Source: arm5.elf, 6214.1.00007f5da0034000.00007f5da003a000.rw-.sdmpString found in binary or memory: https://motd.ubuntu.comhe
Source: unknownNetwork traffic detected: HTTP traffic on port 39244 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39244
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal52.troj.evad.linELF@0/2@6/0
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/910/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1344/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1465/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1586/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1463/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1900/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/491/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1599/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1477/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/379/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1476/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1475/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/936/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/30/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/2208/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/35/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1809/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/1494/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/260/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/261/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/141/cmdlineJump to behavior
Source: /tmp/arm5.elf (PID: 6214)File opened: /proc/262/cmdlineJump to behavior
Source: /usr/bin/dash (PID: 6294)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.B8Wk9S6ndI /tmp/tmp.fLcSLLYedY /tmp/tmp.kz78GZHCezJump to behavior
Source: /usr/bin/dash (PID: 6295)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.B8Wk9S6ndI /tmp/tmp.fLcSLLYedY /tmp/tmp.kz78GZHCezJump to behavior
Source: /tmp/arm5.elf (PID: 6214)Queries kernel information via 'uname': Jump to behavior
Source: arm5.elf, 6214.1.00007fffd01d4000.00007fffd01f5000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm5.elf
Source: arm5.elf, 6214.1.00007f5da0034000.00007f5da003a000.rw-.sdmpBinary or memory string: vmware
Source: arm5.elf, 6214.1.00007f5da0034000.00007f5da003a000.rw-.sdmpBinary or memory string: qemu-arm
Source: arm5.elf, 6214.1.00007fffd01d4000.00007fffd01f5000.rw-.sdmpBinary or memory string: /tmp/qemu-open.xX3yK6
Source: arm5.elf, 6214.1.000056303f1df000.000056303f32e000.rw-.sdmpBinary or memory string: ?0V!/etc/qemu-binfmt/arm
Source: arm5.elf, 6214.1.000056303f1df000.000056303f32e000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm5.elf, 6214.1.00007fffd01d4000.00007fffd01f5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: arm5.elf, 6214.1.00007fffd01d4000.00007fffd01f5000.rw-.sdmpBinary or memory string: ;0V/tmp/qemu-open.xX3yK6:U
Source: arm5.elf, 6214.1.00007f5da0034000.00007f5da003a000.rw-.sdmpBinary or memory string: !!a1gAWFxuAXsFWUgBRQAA!!a1gAWFxuAXsAWUgKRXgA!!a1gAWFxuAXsAWEgJR3IA!!a10CWFxuAHsGWVcWQHAA!!a10CWFxuAHsGWVcWQHUA!!aFwAWF9uA3sGW0gLRgAA!!aFwAWFlpG2QBW0gJTwAA!!qemu-arm2QBW0gJTwAA!

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: kamru.ru
Source: TrafficDNS traffic detected: queries for: kamru.ru
Source: TrafficDNS traffic detected: queries for: kamru.ru
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
File Deletion
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1654171 Sample: arm5.elf Startdate: 02/04/2025 Architecture: LINUX Score: 52 15 kamru.ru 2->15 17 stun.l.google.com 2->17 19 8 other IPs or domains 2->19 21 Connects to many ports of the same IP (likely port scanning) 2->21 7 arm5.elf 2->7         started        9 dash rm 2->9         started        11 dash rm 2->11         started        signatures3 23 Performs DNS TXT record lookups 15->23 25 Uses STUN server to do NAT traversial 17->25 process4 process5 13 arm5.elf 7->13         started       
SourceDetectionScannerLabelLink
arm5.elf11%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches

Download Network PCAP: filteredfull

NameIPActiveMaliciousAntivirus DetectionReputation
stun.l.google.com
74.125.250.129
truefalse
    high
    kamru.ru
    unknown
    unknowntrue
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      https://motd.ubuntu.comarm5.elf, 6214.1.00007f5da0034000.00007f5da003a000.rw-.sdmpfalse
        high
        https://motd.ubuntu.comhearm5.elf, 6214.1.00007f5da0034000.00007f5da003a000.rw-.sdmpfalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          216.146.26.30
          unknownReserved
          11915US-TELEPACIFICUSfalse
          34.249.145.219
          unknownUnited States
          16509AMAZON-02USfalse
          154.205.155.243
          unknownSeychelles
          26484IKGUL-26484UStrue
          104.245.241.61
          unknownUnited States
          8100ASN-QUADRANET-GLOBALUSfalse
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          74.125.250.129
          stun.l.google.comUnited States
          15169GOOGLEUSfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          216.146.26.30mips.elfGet hashmaliciousUnknownBrowse
            kmips.elfGet hashmaliciousUnknownBrowse
              mips.elfGet hashmaliciousUnknownBrowse
                SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
                  arm5.elfGet hashmaliciousUnknownBrowse
                    34.249.145.219na.elfGet hashmaliciousPrometeiBrowse
                      na.elfGet hashmaliciousPrometeiBrowse
                        na.elfGet hashmaliciousPrometeiBrowse
                          na.elfGet hashmaliciousPrometeiBrowse
                            na.elfGet hashmaliciousPrometeiBrowse
                              na.elfGet hashmaliciousPrometeiBrowse
                                na.elfGet hashmaliciousPrometeiBrowse
                                  drea4.elfGet hashmaliciousUnknownBrowse
                                    FederalAgent.arm6.elfGet hashmaliciousMiraiBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        154.205.155.243arm5.elfGet hashmaliciousUnknownBrowse
                                          mips.elfGet hashmaliciousUnknownBrowse
                                            ppc.elfGet hashmaliciousUnknownBrowse
                                              mips.elfGet hashmaliciousUnknownBrowse
                                                SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
                                                  aarch64.elfGet hashmaliciousUnknownBrowse
                                                    nimips.elfGet hashmaliciousUnknownBrowse
                                                      104.245.241.61mips.elfGet hashmaliciousUnknownBrowse
                                                        ppc.elfGet hashmaliciousUnknownBrowse
                                                          kmips.elfGet hashmaliciousUnknownBrowse
                                                            arm7.elfGet hashmaliciousUnknownBrowse
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                                                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                IKGUL-26484US.i.elfGet hashmaliciousMiraiBrowse
                                                                • 154.205.157.45
                                                                m68k.elfGet hashmaliciousUnknownBrowse
                                                                • 154.219.20.172
                                                                weje64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                • 156.233.39.216
                                                                arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 154.205.155.97
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 154.205.155.243
                                                                ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 154.205.155.97
                                                                boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                                • 156.238.135.139
                                                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                • 156.251.85.203
                                                                boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                                • 156.251.85.209
                                                                boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                • 156.251.85.206
                                                                ASN-QUADRANET-GLOBALUSRevised - Periskop ag 2025 Handbook17834.docGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                                • 104.245.240.188
                                                                CELL_REC0_RPLY_MV.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                • 185.174.100.76
                                                                http://adp.kikibasket.shop/graFe5BM2Fe5dy9s3Rallanx0qs3Rybgdy9s3RWO3BM2Get hashmaliciousUnknownBrowse
                                                                • 45.66.218.107
                                                                #Ud83d#Udd0aAudio_Msg56 tsitouch.com.......xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                • 185.174.100.76
                                                                #Ud83d#Udd0aAudio_Msg56 camsmgt.com.......xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                • 185.174.100.76
                                                                https://www.google.com/url?q=https%3A%2F%2Fdryneedleinstitute.org%2F874jsu9&sa=D&sntz=1&usg=AOvVaw3kE5QygjqqKl28m257UzveGet hashmaliciousUnknownBrowse
                                                                • 104.245.240.188
                                                                https://www.google.com/url?q=https%3A%2F%2Flisachubb.com%2Fjsuhsks%2F&sa=D&sntz=1&usg=AOvVaw0F2q7kVD-KIPGQS9mKbD8h#?AynbDClvCqs9djvzki8kdrm19expwx==j8If1EgPfB7jihNIp005uIzL8bVQdPW2iYEqZ~JQ~1pwu5ro8b7dregga8ni8pcjy70e8jw2c#~JQ~LnJusWbClYIbJ4IuevwUc1s1rzg==CHHbFZTEMTyV0CrlRZJA4WrAlGrGet hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                                                • 104.245.240.188
                                                                #Ud83d#Udd0aAudio_Msg Pharma.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                • 185.174.100.76
                                                                #Ud83d#Udd0aAudio_Msg Pharma.xhtmlGet hashmaliciousHTMLPhisherBrowse
                                                                • 185.174.100.76
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 104.245.241.61
                                                                US-TELEPACIFICUSi486.elfGet hashmaliciousUnknownBrowse
                                                                • 64.60.20.173
                                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                                • 66.85.120.63
                                                                k03ldc.i686.elfGet hashmaliciousUnknownBrowse
                                                                • 198.211.201.34
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 216.146.26.30
                                                                kmips.elfGet hashmaliciousUnknownBrowse
                                                                • 216.146.26.30
                                                                mips.elfGet hashmaliciousUnknownBrowse
                                                                • 216.146.26.30
                                                                byte.mips.elfGet hashmaliciousOkiruBrowse
                                                                • 64.140.24.148
                                                                ppc.elfGet hashmaliciousUnknownBrowse
                                                                • 69.178.148.199
                                                                SecuriteInfo.com.ELF.Mirai-CXE.14004.27270.elfGet hashmaliciousUnknownBrowse
                                                                • 216.146.26.30
                                                                arm5.elfGet hashmaliciousUnknownBrowse
                                                                • 216.146.26.30
                                                                AMAZON-02USna.elfGet hashmaliciousPrometeiBrowse
                                                                • 34.249.145.219
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 54.171.230.55
                                                                https://notifications.copilot.app/i/dNpLl6hHRGet hashmaliciousUnknownBrowse
                                                                • 44.234.198.184
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 34.249.145.219
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 34.249.145.219
                                                                http://free-calendar.suGet hashmaliciousUnknownBrowse
                                                                • 18.246.119.221
                                                                https://www.pdfskillsapp.comGet hashmaliciousUnknownBrowse
                                                                • 18.238.55.96
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 13.213.51.196
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 34.249.145.219
                                                                na.elfGet hashmaliciousPrometeiBrowse
                                                                • 13.213.51.196
                                                                No context
                                                                No context
                                                                Process:/tmp/arm5.elf
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):14
                                                                Entropy (8bit):3.521640636343319
                                                                Encrypted:false
                                                                SSDEEP:3:TggLAJ5:Tgg03
                                                                MD5:A737667E3E61E716C83359F35BC141DA
                                                                SHA1:E7C3DBC96B90E28F18CFB1CADE0C7AF673FFAA57
                                                                SHA-256:2D8A0F430A3339E16B223D653251534539D95B1DF7142834F68D9172B1656E37
                                                                SHA-512:0ACAFC3F3F40EDEF3D9F2F1CCE09BAF5004FD8488434F4903F18B9B7E77B4A6CDF7F84A47856CB2FDAA4B1B0F70FC2A3EDDE82BD29831FF54CB75F4E4C74FE74
                                                                Malicious:false
                                                                Reputation:moderate, very likely benign file
                                                                Preview:/tmp/arm5.elf.
                                                                Process:/tmp/arm5.elf
                                                                File Type:data
                                                                Category:dropped
                                                                Size (bytes):14
                                                                Entropy (8bit):3.521640636343319
                                                                Encrypted:false
                                                                SSDEEP:3:TggLAJ5:Tgg03
                                                                MD5:A737667E3E61E716C83359F35BC141DA
                                                                SHA1:E7C3DBC96B90E28F18CFB1CADE0C7AF673FFAA57
                                                                SHA-256:2D8A0F430A3339E16B223D653251534539D95B1DF7142834F68D9172B1656E37
                                                                SHA-512:0ACAFC3F3F40EDEF3D9F2F1CCE09BAF5004FD8488434F4903F18B9B7E77B4A6CDF7F84A47856CB2FDAA4B1B0F70FC2A3EDDE82BD29831FF54CB75F4E4C74FE74
                                                                Malicious:false
                                                                Reputation:moderate, very likely benign file
                                                                Preview:/tmp/arm5.elf.
                                                                File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                                Entropy (8bit):6.101088875131795
                                                                TrID:
                                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                File name:arm5.elf
                                                                File size:82'692 bytes
                                                                MD5:8aca8ee3da7442fdf5355a40b67623ef
                                                                SHA1:9d7772aab8b3ccdacff0ae2b87244c3c51670bcc
                                                                SHA256:8b0d61491fff9ffeb51c305cc5857a8a3adbf9a6be735bb3f2c6da686186c69a
                                                                SHA512:72bfe9e74842d9d13a376c3f7c1e14c938564f04c182bfece01b4db7cc9ac7a092297185eba259afc8852d5aca685e1789fbbcba76f023542ab92b53a319f8d5
                                                                SSDEEP:1536:J/nrCipdLrDjtw6xYOak/NR6UIJ2q91SY32SrwOUyALulE2OeJYIhQc5sr:NdXLrDjtwwNJR6UoHUJulE2DJhJE
                                                                TLSH:62831896B8419B16D5D006BBFE1E528E33132FB8F2EA3202DD156F2077CE95A0E3B551
                                                                File Content Preview:.ELF..............(.....l...4...$A......4. ...(........p.>...........................................?...?...............@...@...@.......G..........Q.td.............................@-..@............/..@-.,@...0....S..... 0....S.........../..0...0...@..../

                                                                ELF header

                                                                Class:ELF32
                                                                Data:2's complement, little endian
                                                                Version:1 (current)
                                                                Machine:ARM
                                                                Version Number:0x1
                                                                Type:EXEC (Executable file)
                                                                OS/ABI:UNIX - System V
                                                                ABI Version:0
                                                                Entry Point Address:0x816c
                                                                Flags:0x4000002
                                                                ELF Header Size:52
                                                                Program Header Offset:52
                                                                Program Header Size:32
                                                                Number of Program Headers:4
                                                                Section Header Offset:82212
                                                                Section Header Size:40
                                                                Number of Section Headers:12
                                                                Header String Table Index:11
                                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                NULL0x00x00x00x00x0000
                                                                .initPROGBITS0x80b40xb40x140x00x6AX001
                                                                .textPROGBITS0x80c80xc80x12b000x00x6AX004
                                                                .finiPROGBITS0x1abc80x12bc80x140x00x6AX001
                                                                .rodataPROGBITS0x1abdc0x12bdc0x13000x00x2A004
                                                                .ARM.exidxARM_EXIDX0x1bedc0x13edc0xc80x00x82AL204
                                                                .init_arrayINIT_ARRAY0x240040x140040x40x00x3WA004
                                                                .fini_arrayFINI_ARRAY0x240080x140080x40x00x3WA004
                                                                .gotPROGBITS0x240100x140100x280x40x3WA004
                                                                .dataPROGBITS0x240380x140380x940x00x3WA004
                                                                .bssNOBITS0x240d00x140cc0x46500x00x3WA008
                                                                .shstrtabSTRTAB0x00x140cc0x580x00x0001
                                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                EXIDX0x13edc0x1bedc0x1bedc0xc80xc84.34860x4R 0x4.ARM.exidx
                                                                LOAD0x00x80000x80000x13fa40x13fa46.11740x5R E0x8000.init .text .fini .rodata .ARM.exidx
                                                                LOAD0x140040x240040x240040xc80x471c3.55090x6RW 0x8000.init_array .fini_array .got .data .bss
                                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4

                                                                Download Network PCAP: filteredfull

                                                                • Total Packets: 52
                                                                • 50749 undefined
                                                                • 49722 undefined
                                                                • 44859 undefined
                                                                • 19302 undefined
                                                                • 443 (HTTPS)
                                                                • 80 (HTTP)
                                                                • 53 (DNS)
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Apr 2, 2025 02:49:02.479266882 CEST43928443192.168.2.2391.189.91.42
                                                                Apr 2, 2025 02:49:04.633143902 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:05.646682978 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:07.662372112 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:08.110383987 CEST42836443192.168.2.2391.189.91.43
                                                                Apr 2, 2025 02:49:08.878192902 CEST4251680192.168.2.23109.202.202.202
                                                                Apr 2, 2025 02:49:09.065386057 CEST4972241648104.245.241.61192.168.2.23
                                                                Apr 2, 2025 02:49:09.065649986 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:11.082160950 CEST4972241648104.245.241.61192.168.2.23
                                                                Apr 2, 2025 02:49:11.082389116 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:11.477325916 CEST4972241648104.245.241.61192.168.2.23
                                                                Apr 2, 2025 02:49:11.477664948 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:11.478441000 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:11.874924898 CEST4972241648104.245.241.61192.168.2.23
                                                                Apr 2, 2025 02:49:11.874950886 CEST4972241648104.245.241.61192.168.2.23
                                                                Apr 2, 2025 02:49:11.875169992 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:11.875169992 CEST4164849722192.168.2.23104.245.241.61
                                                                Apr 2, 2025 02:49:22.956068993 CEST43928443192.168.2.2391.189.91.42
                                                                Apr 2, 2025 02:49:25.124449015 CEST39244443192.168.2.2334.249.145.219
                                                                Apr 2, 2025 02:49:25.124546051 CEST4433924434.249.145.219192.168.2.23
                                                                Apr 2, 2025 02:49:25.124948025 CEST39244443192.168.2.2334.249.145.219
                                                                Apr 2, 2025 02:49:25.125647068 CEST39244443192.168.2.2334.249.145.219
                                                                Apr 2, 2025 02:49:25.125720024 CEST4433924434.249.145.219192.168.2.23
                                                                Apr 2, 2025 02:49:26.667325974 CEST6038250749192.168.2.23154.205.155.243
                                                                Apr 2, 2025 02:49:26.821225882 CEST5074960382154.205.155.243192.168.2.23
                                                                Apr 2, 2025 02:49:26.821511030 CEST6038250749192.168.2.23154.205.155.243
                                                                Apr 2, 2025 02:49:26.975078106 CEST5074960382154.205.155.243192.168.2.23
                                                                Apr 2, 2025 02:49:26.975331068 CEST6038250749192.168.2.23154.205.155.243
                                                                Apr 2, 2025 02:49:27.128678083 CEST5074960382154.205.155.243192.168.2.23
                                                                Apr 2, 2025 02:49:27.129004955 CEST6038250749192.168.2.23154.205.155.243
                                                                Apr 2, 2025 02:49:28.030540943 CEST6038250749192.168.2.23154.205.155.243
                                                                Apr 2, 2025 02:49:28.184288025 CEST5074960382154.205.155.243192.168.2.23
                                                                Apr 2, 2025 02:49:28.184307098 CEST5074960382154.205.155.243192.168.2.23
                                                                Apr 2, 2025 02:49:28.184977055 CEST6038250749192.168.2.23154.205.155.243
                                                                Apr 2, 2025 02:49:28.338079929 CEST5074960382154.205.155.243192.168.2.23
                                                                Apr 2, 2025 02:49:29.293677092 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:29.775283098 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:49:29.775525093 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:30.257611990 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:49:30.257761955 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:30.739759922 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:49:30.739907026 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:30.971966028 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:31.453466892 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:49:35.242537022 CEST42836443192.168.2.2391.189.91.43
                                                                Apr 2, 2025 02:49:35.607604980 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:49:35.607961893 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:39.337861061 CEST4251680192.168.2.23109.202.202.202
                                                                Apr 2, 2025 02:49:50.618182898 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:51.102530956 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:49:51.103069067 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:49:51.586246014 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:50:03.910373926 CEST43928443192.168.2.2391.189.91.42
                                                                Apr 2, 2025 02:50:10.245981932 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:50:10.728878975 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:50:10.729382992 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:50:11.211637974 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:50:25.117115021 CEST39244443192.168.2.2334.249.145.219
                                                                Apr 2, 2025 02:50:25.164277077 CEST4433924434.249.145.219192.168.2.23
                                                                Apr 2, 2025 02:50:28.157568932 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:50:28.641273975 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:50:28.641412973 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:50:29.123725891 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:50:45.376243114 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:50:45.858843088 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:50:45.859004974 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:50:46.342597961 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:51:04.335005999 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:51:04.694946051 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:51:04.695334911 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:51:04.818672895 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:51:04.818944931 CEST3572044859192.168.2.23216.146.26.30
                                                                Apr 2, 2025 02:51:05.300373077 CEST4485935720216.146.26.30192.168.2.23
                                                                Apr 2, 2025 02:51:08.411793947 CEST4433924434.249.145.219192.168.2.23
                                                                TimestampSource PortDest PortSource IPDest IP
                                                                Apr 2, 2025 02:49:04.530391932 CEST5803253192.168.2.238.8.8.8
                                                                Apr 2, 2025 02:49:04.630425930 CEST53580328.8.8.8192.168.2.23
                                                                Apr 2, 2025 02:49:10.067648888 CEST4875253192.168.2.23208.67.220.220
                                                                Apr 2, 2025 02:49:10.166270018 CEST5348752208.67.220.220192.168.2.23
                                                                Apr 2, 2025 02:49:10.166794062 CEST4783019302192.168.2.2374.125.250.129
                                                                Apr 2, 2025 02:49:10.262151003 CEST193024783074.125.250.129192.168.2.23
                                                                Apr 2, 2025 02:49:26.492244959 CEST5146953192.168.2.23208.67.220.220
                                                                Apr 2, 2025 02:49:26.665015936 CEST5351469208.67.220.220192.168.2.23
                                                                Apr 2, 2025 02:49:27.823291063 CEST3839753192.168.2.238.8.4.4
                                                                Apr 2, 2025 02:49:27.931750059 CEST53383978.8.4.4192.168.2.23
                                                                Apr 2, 2025 02:49:27.932333946 CEST4289519302192.168.2.2374.125.250.129
                                                                Apr 2, 2025 02:49:28.029462099 CEST193024289574.125.250.129192.168.2.23
                                                                Apr 2, 2025 02:49:29.187875986 CEST3809453192.168.2.238.8.8.8
                                                                Apr 2, 2025 02:49:29.292334080 CEST53380948.8.8.8192.168.2.23
                                                                Apr 2, 2025 02:49:30.778211117 CEST3364353192.168.2.23208.67.222.222
                                                                Apr 2, 2025 02:49:30.875349045 CEST5333643208.67.222.222192.168.2.23
                                                                Apr 2, 2025 02:49:30.875773907 CEST3716119302192.168.2.2374.125.250.129
                                                                Apr 2, 2025 02:49:30.971158981 CEST193023716174.125.250.129192.168.2.23
                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                Apr 2, 2025 02:49:04.530391932 CEST192.168.2.238.8.8.80x48afStandard query (0)kamru.ru16IN (0x0001)false
                                                                Apr 2, 2025 02:49:10.067648888 CEST192.168.2.23208.67.220.2200xe44eStandard query (0)stun.l.google.comA (IP address)IN (0x0001)false
                                                                Apr 2, 2025 02:49:26.492244959 CEST192.168.2.23208.67.220.2200x1ea6Standard query (0)kamru.ru16IN (0x0001)false
                                                                Apr 2, 2025 02:49:27.823291063 CEST192.168.2.238.8.4.40x4445Standard query (0)stun.l.google.comA (IP address)IN (0x0001)false
                                                                Apr 2, 2025 02:49:29.187875986 CEST192.168.2.238.8.8.80x46c0Standard query (0)kamru.ru16IN (0x0001)false
                                                                Apr 2, 2025 02:49:30.778211117 CEST192.168.2.23208.67.222.2220x3f89Standard query (0)stun.l.google.comA (IP address)IN (0x0001)false
                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                Apr 2, 2025 02:49:04.630425930 CEST8.8.8.8192.168.2.230x48afNo error (0)kamru.ruTXT (Text strings)IN (0x0001)false
                                                                Apr 2, 2025 02:49:10.166270018 CEST208.67.220.220192.168.2.230xe44eNo error (0)stun.l.google.com74.125.250.129A (IP address)IN (0x0001)false
                                                                Apr 2, 2025 02:49:26.665015936 CEST208.67.220.220192.168.2.230x1ea6No error (0)kamru.ruTXT (Text strings)IN (0x0001)false
                                                                Apr 2, 2025 02:49:27.931750059 CEST8.8.4.4192.168.2.230x4445No error (0)stun.l.google.com74.125.250.129A (IP address)IN (0x0001)false
                                                                Apr 2, 2025 02:49:29.292334080 CEST8.8.8.8192.168.2.230x46c0No error (0)kamru.ruTXT (Text strings)IN (0x0001)false
                                                                Apr 2, 2025 02:49:30.875349045 CEST208.67.222.222192.168.2.230x3f89No error (0)stun.l.google.com74.125.250.129A (IP address)IN (0x0001)false

                                                                System Behavior

                                                                Start time (UTC):00:49:03
                                                                Start date (UTC):02/04/2025
                                                                Path:/tmp/arm5.elf
                                                                Arguments:-
                                                                File size:4956856 bytes
                                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                Start time (UTC):00:50:24
                                                                Start date (UTC):02/04/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):00:50:24
                                                                Start date (UTC):02/04/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.B8Wk9S6ndI /tmp/tmp.fLcSLLYedY /tmp/tmp.kz78GZHCez
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                Start time (UTC):00:50:24
                                                                Start date (UTC):02/04/2025
                                                                Path:/usr/bin/dash
                                                                Arguments:-
                                                                File size:129816 bytes
                                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                Start time (UTC):00:50:24
                                                                Start date (UTC):02/04/2025
                                                                Path:/usr/bin/rm
                                                                Arguments:rm -f /tmp/tmp.B8Wk9S6ndI /tmp/tmp.fLcSLLYedY /tmp/tmp.kz78GZHCez
                                                                File size:72056 bytes
                                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b