Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
botnt.arm5.elf

Overview

General Information

Sample name:botnt.arm5.elf
Analysis ID:1502201
MD5:d7daf7738a75e997ebb9c2aca4a4bdfe
SHA1:1d84958698faa73834f3d83c287b312097c0cffc
SHA256:5c3cee247a19e0eca63e825fa03d77e8c7b326a1f112e037dd893c640cb637a6
Tags:botntelf
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Sleeps for long times indicative of sandbox evasion
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1502201
Start date and time:2024-08-31 14:48:07 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:botnt.arm5.elf
Detection:MAL
Classification:mal48.linELF@0/0@1/0
Command:/tmp/botnt.arm5.elf
PID:5590
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:Segmentation fault
  • system is lnxubuntu20
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: botnt.arm5.elfReversingLabs: Detection: 13%
Source: global trafficTCP traffic: 192.168.2.15:43766 -> 92.38.135.247:4444
Source: /tmp/botnt.arm5.elf (PID: 5592)Socket: 127.0.0.1:2174Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 23.224.130.196
Source: unknownTCP traffic detected without corresponding DNS query: 23.224.130.196
Source: unknownTCP traffic detected without corresponding DNS query: 23.224.130.196
Source: unknownTCP traffic detected without corresponding DNS query: 23.224.130.196
Source: unknownTCP traffic detected without corresponding DNS query: 23.224.130.196
Source: unknownTCP traffic detected without corresponding DNS query: 23.224.130.196
Source: unknownTCP traffic detected without corresponding DNS query: 23.225.63.251
Source: unknownTCP traffic detected without corresponding DNS query: 23.225.63.251
Source: unknownTCP traffic detected without corresponding DNS query: 23.224.130.196
Source: unknownTCP traffic detected without corresponding DNS query: 23.225.63.251
Source: unknownTCP traffic detected without corresponding DNS query: 154.214.7.222
Source: unknownTCP traffic detected without corresponding DNS query: 154.214.7.222
Source: unknownTCP traffic detected without corresponding DNS query: 0.159.99.4
Source: unknownTCP traffic detected without corresponding DNS query: 0.159.99.4
Source: unknownTCP traffic detected without corresponding DNS query: 0.159.99.4
Source: unknownTCP traffic detected without corresponding DNS query: 0.159.99.4
Source: unknownTCP traffic detected without corresponding DNS query: 154.214.7.220
Source: unknownTCP traffic detected without corresponding DNS query: 154.214.7.220
Source: unknownTCP traffic detected without corresponding DNS query: 0.159.99.4
Source: unknownTCP traffic detected without corresponding DNS query: 154.214.7.220
Source: unknownTCP traffic detected without corresponding DNS query: 172.247.148.76
Source: global trafficDNS traffic detected: DNS query: k.parasjha.one
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@1/0
Source: submitted sampleStderr: Segmentation fault: exit code = 0
Source: /tmp/botnt.arm5.elf (PID: 5663)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/botnt.arm5.elf (PID: 5590)Queries kernel information via 'uname': Jump to behavior
Source: botnt.arm5.elf, 5590.1.000055fd7c57e000.000055fd7c6cc000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: botnt.arm5.elf, 5590.1.000055fd7c57e000.000055fd7c6cc000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: botnt.arm5.elf, 5590.1.00007ffd42e6d000.00007ffd42e8e000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: botnt.arm5.elf, 5590.1.00007ffd42e6d000.00007ffd42e8e000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/botnt.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/botnt.arm5.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1502201 Sample: botnt.arm5.elf Startdate: 31/08/2024 Architecture: LINUX Score: 48 17 92.38.135.247, 43766, 4444 GCOREAT Austria 2->17 19 154.214.7.220, 38680, 80 CNSERVERSUS Seychelles 2->19 21 6 other IPs or domains 2->21 23 Multi AV Scanner detection for submitted file 2->23 9 botnt.arm5.elf 2->9         started        signatures3 process4 process5 11 botnt.arm5.elf 9->11         started        process6 13 botnt.arm5.elf 11->13         started        process7 15 botnt.arm5.elf 13->15         started       
SourceDetectionScannerLabelLink
botnt.arm5.elf13%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
k.parasjha.one
92.223.30.118
truefalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    0.159.99.4
    unknownunknown
    unknownunknownfalse
    23.225.63.251
    unknownUnited States
    40065CNSERVERSUSfalse
    172.247.148.76
    unknownUnited States
    40065CNSERVERSUSfalse
    92.38.135.247
    unknownAustria
    199524GCOREATfalse
    154.214.7.220
    unknownSeychelles
    40065CNSERVERSUSfalse
    154.214.7.222
    unknownSeychelles
    40065CNSERVERSUSfalse
    23.224.130.196
    unknownUnited States
    40065CNSERVERSUSfalse
    No context
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    CNSERVERSUSSecuriteInfo.com.Linux.Siggen.9999.28313.2324.elfGet hashmaliciousMiraiBrowse
    • 172.247.204.254
    estado de cuenta adjunto.exeGet hashmaliciousFormBookBrowse
    • 198.16.50.171
    http://relay.csgoze520.com/Get hashmaliciousUnknownBrowse
    • 23.224.143.196
    Izvod racuna u prilogu.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    z1209627360293827.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    709876765465.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    SecuriteInfo.com.Win32.MalwareX-gen.15470.29062.exeGet hashmaliciousBlackMoonBrowse
    • 23.224.49.82
    PO#4510065525.exeGet hashmaliciousFormBookBrowse
    • 43.242.202.169
    700987654656676.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    firmware.i586.elfGet hashmaliciousUnknownBrowse
    • 162.209.190.131
    GCOREAThttp://techcrunchabc.homesGet hashmaliciousUnknownBrowse
    • 92.223.97.97
    https://eu5qwt3o.beauty/offer/4?imp=amakyvlljhftr1723918476202&rurl=https%3A%2F%2Fgentlyrevitalizedarchitect.com%2F%3Fa%3D103098%26c%3D143007%26s1%3D79%26s2%3Damakyvlljhftr1723918476202%26s3%3Dwww.foxnews.comGet hashmaliciousUnknownBrowse
    • 92.223.21.23
    https://fwealthm.comGet hashmaliciousUnknownBrowse
    • 92.223.127.156
    https://www.globalepic.co.kr/view.php?ud=202408011057515744edd3030223_29Get hashmaliciousUnknownBrowse
    • 92.38.168.190
    SLL8zVmaGj.elfGet hashmaliciousUnknownBrowse
    • 92.38.145.145
    cJTpn6cF6x.elfGet hashmaliciousUnknownBrowse
    • 92.38.145.126
    FcMd5XxxZ0.elfGet hashmaliciousMiraiBrowse
    • 5.8.68.127
    http://url7525.miamiadvisors.com/ls/click?upn=u001.wJ6z96nUyPZ-2FP3pZYKQ4grlWRA-2BI-2F1rqfNlBRYAOK617ycFr5ImTLyXCmxLJcv6yLgMV_ILgzAGh9pPX7AoSafK9Gs8M95O4IkW7nxJpWXnZg2bNLwLz1rEKfmulLU5eU2IirbR6maz-2FOZfMUy-2BVMayO5oF0VxEf9RkpuvjpEWS917JL-2FlEdZLcy0N2moO5kBZyyWhfQeoUYQPbgRy3uWBpJdT4j9-2F407DT7CERAfdu0Wr9UIAsPY80QOswLOO9LadRo7o9vTiRpEd3AFhdViJcbk78c3ObscDblx2YbYK370JiDJPOfWBXXkAUnEm2Wq1PAUFMy2RL1TLrpX-2BYOCyu7UVmosfks-2FJaeND37qWXN7DjKocYXqRw8VBcV-2FZ7Xg3jhU5i-2B-2FDbjqlm7brQEoCUMUF7jEkYCjnKmcLdnbXpPH40uORTZdzy7gL13vFbnK72rl0v05q1jJgNfU3GOafg1xS3KJXhmpkNx2tJEKjWveC9jHtKw8ToyuE8jCy2wmMEMNC8vwpFbJBhk3VFkb7Td02PVhoad-2BCAnQPF2zfzGH9Goj2yCsgv1q-2BY6ye6NIj2q-2BU3Z92rukjRCCduWWpPYw1CBSWRNYRPd5-2BNdjauwjm6cGkzjt8mEiiMOnPDGoqado8m6xxiX1UhT6mSHKSrtbCKh1BBWUObYrPHzLD38q9li2rTZzkBQDmIjJ6Z0vV0cU74Yu-2B7r3oIQRd5r3Ak6qWyLDqsZjmXneZ1H9YvUwSWayHYysIY8FbSfpiYd1-2BRgOweM89t0nlR2ZLjDPI5zSLLu-2FPeaTD-2BxJZEFIHsedZkjl1H7pjD-2B-2FpEmiC2KWlGRJXBJKvc2oEJOMug91loOprYIUMulBGJzHGpHAe9nq4-2B87dsS3cDnjA4MQYiXWyp-2FXhk5WFIxiGlR5IqHdGDHxUeU5UDGAHJgWMcGhkV2blFM-3DGet hashmaliciousUnknownBrowse
    • 92.223.97.97
    https://cutt.ly/Netz3TGLGet hashmaliciousUnknownBrowse
    • 92.223.124.62
    http://wwwlegals.comGet hashmaliciousUnknownBrowse
    • 92.223.124.62
    CNSERVERSUSSecuriteInfo.com.Linux.Siggen.9999.28313.2324.elfGet hashmaliciousMiraiBrowse
    • 172.247.204.254
    estado de cuenta adjunto.exeGet hashmaliciousFormBookBrowse
    • 198.16.50.171
    http://relay.csgoze520.com/Get hashmaliciousUnknownBrowse
    • 23.224.143.196
    Izvod racuna u prilogu.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    z1209627360293827.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    709876765465.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    SecuriteInfo.com.Win32.MalwareX-gen.15470.29062.exeGet hashmaliciousBlackMoonBrowse
    • 23.224.49.82
    PO#4510065525.exeGet hashmaliciousFormBookBrowse
    • 43.242.202.169
    700987654656676.exeGet hashmaliciousDBatLoader, FormBookBrowse
    • 198.16.50.171
    firmware.i586.elfGet hashmaliciousUnknownBrowse
    • 162.209.190.131
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
    Entropy (8bit):6.006253804597994
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:botnt.arm5.elf
    File size:83'004 bytes
    MD5:d7daf7738a75e997ebb9c2aca4a4bdfe
    SHA1:1d84958698faa73834f3d83c287b312097c0cffc
    SHA256:5c3cee247a19e0eca63e825fa03d77e8c7b326a1f112e037dd893c640cb637a6
    SHA512:9100bc27e582d15235f7df64fc04e3f95799a84e8d93148ba971cc943afa800a77b079cc1f0c3a969f914eb430fbae80aeffd92fb1f9cc5ca421af5323ec2042
    SSDEEP:1536:AGnPXt+ErYvxviM5LJZ8VpSYtO84/hD+yYYTiW2kknWOCeZCYI/9PKdNr:pYMYpbv6pSiO8+hiW2zfJChUdR
    TLSH:BE833B8ABC509B16D4D016BEFE1E518E33131BB4E2EB3206DD19AF2577CA91B0E3B541
    File Content Preview:.ELF..............(.....l...4....B......4. ...(........p.2..........................................d3..d3...............@...@...@..................Q.td.............................@-..@............/..@-.,@...0....S..... 0....S.........../..0...0...@..../

    ELF header

    Class:ELF32
    Data:2's complement, little endian
    Version:1 (current)
    Machine:ARM
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x816c
    Flags:0x4000002
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:4
    Section Header Offset:82444
    Section Header Size:40
    Number of Section Headers:14
    Header String Table Index:13
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x80b40xb40x140x00x6AX001
    .textPROGBITS0x80c80xc80x122a40x00x6AX004
    .finiPROGBITS0x1a36c0x1236c0x140x00x6AX001
    .rodataPROGBITS0x1a3800x123800xf1c0x00x2A004
    .ARM.exidxARM_EXIDX0x1b29c0x1329c0xc80x00x82AL204
    .eh_framePROGBITS0x240000x140000x40x00x3WA004
    .init_arrayINIT_ARRAY0x240040x140040x40x00x3WA004
    .fini_arrayFINI_ARRAY0x240080x140080x40x00x3WA004
    .gotPROGBITS0x240100x140100x280x40x3WA004
    .dataPROGBITS0x240380x140380x14c0x00x3WA008
    .bssNOBITS0x241880x141840xb6c0x00x3WA008
    .ARM.attributesARM_ATTRIBUTES0x00x141840x140x00x0001
    .shstrtabSTRTAB0x00x141980x720x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    EXIDX0x1329c0x1b29c0x1b29c0xc80xc84.31910x4R 0x4.ARM.exidx
    LOAD0x00x80000x80000x133640x133646.16260x5R E0x8000.init .text .fini .rodata .ARM.exidx
    LOAD0x140000x240000x240000x1840xcf42.79620x6RW 0x8000.eh_frame .init_array .fini_array .got .data .bss
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
    TimestampSource PortDest PortSource IPDest IP
    Aug 31, 2024 14:49:12.507735014 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:12.512582064 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:12.512648106 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:12.512801886 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:12.517515898 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:13.840750933 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:13.840908051 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:13.841305971 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:13.846076012 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:14.418333054 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:14.418437004 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:14.418612957 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:14.423929930 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:14.996136904 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:14.996352911 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:14.996871948 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:15.001611948 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:15.001669884 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:15.006622076 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:16.999155998 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:17.005338907 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:17.577625036 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:17.618822098 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:29.590357065 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:29.595246077 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:30.167707920 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:30.167850018 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:42.186463118 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:42.397989988 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:42.519968033 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:42.519983053 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:43.092447996 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:43.092595100 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:55.104690075 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:49:55.109649897 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:55.683325052 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:49:55.683487892 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:07.695588112 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:07.700579882 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:08.274420977 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:08.274535894 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:20.285005093 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:20.289911985 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:20.865541935 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:20.865839005 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:32.878619909 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:32.883586884 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:33.463725090 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:33.463903904 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:45.476310968 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:45.481324911 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:46.053920984 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:46.054219961 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:58.066165924 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:50:58.071791887 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:58.644098997 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:50:58.644206047 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:51:03.081348896 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:51:03.081507921 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:51:03.092386961 CEST4062880192.168.2.1523.224.130.196
    Aug 31, 2024 14:51:03.291383982 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:51:03.291536093 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:51:04.115600109 CEST4062880192.168.2.1523.224.130.196
    Aug 31, 2024 14:51:06.131515980 CEST4062880192.168.2.1523.224.130.196
    Aug 31, 2024 14:51:10.355395079 CEST4062880192.168.2.1523.224.130.196
    Aug 31, 2024 14:51:11.091909885 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:51:11.125816107 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:51:11.127157927 CEST4063080192.168.2.1523.224.130.196
    Aug 31, 2024 14:51:11.165483952 CEST804063023.224.130.196192.168.2.15
    Aug 31, 2024 14:51:11.165560961 CEST4063080192.168.2.1523.224.130.196
    Aug 31, 2024 14:51:11.167509079 CEST3405880192.168.2.1523.225.63.251
    Aug 31, 2024 14:51:11.704579115 CEST44444376692.38.135.247192.168.2.15
    Aug 31, 2024 14:51:11.704778910 CEST437664444192.168.2.1592.38.135.247
    Aug 31, 2024 14:51:12.179323912 CEST3405880192.168.2.1523.225.63.251
    Aug 31, 2024 14:51:12.183376074 CEST804063023.224.130.196192.168.2.15
    Aug 31, 2024 14:51:12.183500051 CEST4063080192.168.2.1523.224.130.196
    Aug 31, 2024 14:51:12.211873055 CEST803405823.225.63.251192.168.2.15
    Aug 31, 2024 14:51:12.211986065 CEST3405880192.168.2.1523.225.63.251
    Aug 31, 2024 14:51:12.212790012 CEST5111680192.168.2.15154.214.7.222
    Aug 31, 2024 14:51:12.246536016 CEST8051116154.214.7.222192.168.2.15
    Aug 31, 2024 14:51:12.246761084 CEST5111680192.168.2.15154.214.7.222
    Aug 31, 2024 14:51:12.247759104 CEST4959080192.168.2.150.159.99.4
    Aug 31, 2024 14:51:13.267266035 CEST4959080192.168.2.150.159.99.4
    Aug 31, 2024 14:51:15.283205032 CEST4959080192.168.2.150.159.99.4
    Aug 31, 2024 14:51:15.325649023 CEST80495900.159.99.4192.168.2.15
    Aug 31, 2024 14:51:15.325743914 CEST4959080192.168.2.150.159.99.4
    Aug 31, 2024 14:51:15.326378107 CEST3868080192.168.2.15154.214.7.220
    Aug 31, 2024 14:51:16.339303017 CEST3868080192.168.2.15154.214.7.220
    Aug 31, 2024 14:51:16.347371101 CEST80495900.159.99.4192.168.2.15
    Aug 31, 2024 14:51:16.347464085 CEST4959080192.168.2.150.159.99.4
    Aug 31, 2024 14:51:16.374924898 CEST8038680154.214.7.220192.168.2.15
    Aug 31, 2024 14:51:16.375114918 CEST3868080192.168.2.15154.214.7.220
    Aug 31, 2024 14:51:16.375601053 CEST4129480192.168.2.15172.247.148.76
    TimestampSource PortDest PortSource IPDest IP
    Aug 31, 2024 14:49:12.473686934 CEST6037753192.168.2.158.8.8.8
    Aug 31, 2024 14:49:12.493129015 CEST53603778.8.8.8192.168.2.15
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Aug 31, 2024 14:49:12.473686934 CEST192.168.2.158.8.8.80x7217Standard query (0)k.parasjha.oneA (IP address)IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one92.223.30.118A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one193.32.179.248A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one92.38.135.247A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one195.2.81.97A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one139.162.84.81A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one185.255.178.242A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one185.255.178.106A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one193.32.177.163A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one92.38.160.12A (IP address)IN (0x0001)false
    Aug 31, 2024 14:49:12.493129015 CEST8.8.8.8192.168.2.150x7217No error (0)k.parasjha.one92.38.160.9A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):12:49:11
    Start date (UTC):31/08/2024
    Path:/tmp/botnt.arm5.elf
    Arguments:/tmp/botnt.arm5.elf
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):12:49:11
    Start date (UTC):31/08/2024
    Path:/tmp/botnt.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):12:51:02
    Start date (UTC):31/08/2024
    Path:/tmp/botnt.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

    Start time (UTC):12:51:02
    Start date (UTC):31/08/2024
    Path:/tmp/botnt.arm5.elf
    Arguments:-
    File size:4956856 bytes
    MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1