Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1527367
MD5:b12d19bcf7b417ec41ffe87df5f80970
SHA1:dd9e77314729b9f43ed09d037cb6004b7565b348
SHA256:85d443a739267b5d780ed0920d72631380b7ca5797f6b2247bedcc9da17b48f3
Tags:elfSupershelluser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Machine Learning detection for sample
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1527367
Start date and time:2024-10-06 22:57:58 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal48.evad.linELF@0/0@2/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5480
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:2024/10/06 15:59:08 Forking
2024/10/06 15:59:08 Connecting to 20.2.223.147:3232
2024/10/06 15:59:12 Successfully connnected 20.2.223.147:3232
2024/10/06 15:59:12 [client] INFO ??:1 BoFsrOtr() : Handling channel: jump
2024/10/06 15:59:15 [20.2.223.147:3232] INFO ??:1 () : New SSH connection, version SSH-2.0-paramiko_3.0.0
2024/10/06 15:59:15 [20.2.223.147:3232] INFO ??:1 BoFsrOtr() : Handling channel: session
2024/10/06 15:59:16 [20.2.223.147:3232] INFO ??:1 BoFsrOtr() : Handling channel: session
2024/10/06 15:59:17 [20.2.223.147:3232] INFO ??:1 IFu6thF7() : Session got request: "exec"
2024/10/06 15:59:17 [20.2.223.147:3232] INFO ??:3 IFu6thF7() : Session disconnected
2024/10/06 15:59:18 [20.2.223.147:3232] INFO ??:6 IFu6thF7() : Session disconnected
2024/10/06 15:59:18 [client] ERROR ??:1 () : Channel call back error: connection terminated
  • system is lnxubuntu20
  • na.elf (PID: 5480, Parent: 5403, MD5: b12d19bcf7b417ec41ffe87df5f80970) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5485, Parent: 5480)
    • exe (PID: 5485, Parent: 5480, MD5: b12d19bcf7b417ec41ffe87df5f80970) Arguments: /proc/self/exe
      • exe New Fork (PID: 5498, Parent: 5485)
      • whoami (PID: 5498, Parent: 5485, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: na.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.13:45800 -> 20.2.223.147:3232
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: unknownTCP traffic detected without corresponding DNS query: 20.2.223.147
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: na.elfString found in binary or memory: http://upx.sf.net
Source: LOAD without section mappingsProgram segment: 0x400000
Source: classification engineClassification label: mal48.evad.linELF@0/0@2/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.96 Copyright (C) 1996-2020 the UPX Team. All Rights Reserved. $
Source: submitted sampleStderr: 2024/10/06 15:59:08 Forking2024/10/06 15:59:08 Connecting to 20.2.223.147:32322024/10/06 15:59:12 Successfully connnected 20.2.223.147:32322024/10/06 15:59:12 [client] INFO ??:1 BoFsrOtr() : Handling channel: jump2024/10/06 15:59:15 [20.2.223.147:3232] INFO ??:1 () : New SSH connection, version SSH-2.0-paramiko_3.0.02024/10/06 15:59:15 [20.2.223.147:3232] INFO ??:1 BoFsrOtr() : Handling channel: session2024/10/06 15:59:16 [20.2.223.147:3232] INFO ??:1 BoFsrOtr() : Handling channel: session2024/10/06 15:59:17 [20.2.223.147:3232] INFO ??:1 IFu6thF7() : Session got request: "exec"2024/10/06 15:59:17 [20.2.223.147:3232] INFO ??:3 IFu6thF7() : Session disconnected2024/10/06 15:59:18 [20.2.223.147:3232] INFO ??:6 IFu6thF7() : Session disconnected2024/10/06 15:59:18 [client] ERROR ??:1 () : Channel call back error: connection terminated: exit code = 0
Source: na.elfSubmission file: segment LOAD with 7.885 entropy (max. 8.0)
Source: /proc/self/exe (PID: 5485)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1527367 Sample: na.elf Startdate: 06/10/2024 Architecture: LINUX Score: 48 14 20.2.223.147, 3232, 45800 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 2->14 16 daisy.ubuntu.com 2->16 18 Machine Learning detection for sample 2->18 20 Sample is packed with UPX 2->20 8 na.elf 2->8         started        signatures3 process4 process5 10 na.elf exe 8->10         started        process6 12 exe whoami 10->12         started       
SourceDetectionScannerLabelLink
na.elf11%ReversingLabsLinux.Trojan.Generic
na.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netna.elftrue
    • URL Reputation: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    20.2.223.147
    unknownUnited States
    8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.comna.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousMoobotBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    MICROSOFT-CORP-MSN-AS-BLOCKUSna.elfGet hashmaliciousMiraiBrowse
    • 20.187.234.248
    na.elfGet hashmaliciousUnknownBrowse
    • 20.202.223.162
    na.elfGet hashmaliciousMirai, OkiruBrowse
    • 52.154.85.247
    na.elfGet hashmaliciousMirai, OkiruBrowse
    • 52.165.65.43
    na.elfGet hashmaliciousMirai, OkiruBrowse
    • 52.189.20.92
    na.elfGet hashmaliciousMirai, OkiruBrowse
    • 20.67.73.45
    na.elfGet hashmaliciousMirai, OkiruBrowse
    • 52.122.36.6
    na.elfGet hashmaliciousMirai, OkiruBrowse
    • 51.142.97.176
    na.elfGet hashmaliciousMirai, OkiruBrowse
    • 20.17.17.212
    na.elfGet hashmaliciousMiraiBrowse
    • 20.172.189.89
    No context
    No context
    No created / dropped files found
    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
    Entropy (8bit):7.885021639185236
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:na.elf
    File size:4'741'000 bytes
    MD5:b12d19bcf7b417ec41ffe87df5f80970
    SHA1:dd9e77314729b9f43ed09d037cb6004b7565b348
    SHA256:85d443a739267b5d780ed0920d72631380b7ca5797f6b2247bedcc9da17b48f3
    SHA512:f223934c5ce55b2cb2a0883fe24096684820870c918cbcb9c0e8bfdd7dffccd044fba5a0fbd15e89d3d17d3892019ce46da54783cf2401c35e5bfdfc112e2755
    SSDEEP:98304:khPXNcI4mESYZHgi6CTcNO7pmbpkzEOpwX6k3Hx12IcztIgNr:SXOtjSmHxcscFkzb8FRKztLr
    TLSH:FE2633423932AB7BD9FD1B1DE97530498BA1F01860FCB356FF9AE45123342E6DB94121
    File Content Preview:.ELF..............>......M......@...................@.8...@.......................@.......@......WH......WH..............................`.......`..............0.z.............Q.td.....................................................>U.UPX!...............

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x884d90
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:64
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x4857080x4857087.88500x5R E0x1000
    LOAD0x00x8860000x8860000x00x7ae6300.00000x6RW 0x1000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
    TimestampSource PortDest PortSource IPDest IP
    Oct 6, 2024 22:59:09.416786909 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:09.421996117 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:09.422130108 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:09.423369884 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:09.428261042 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:10.302313089 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:10.302809954 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:10.396811008 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:10.401813984 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:10.438621998 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:10.438879967 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:10.444870949 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:10.449780941 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:11.287940025 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:11.288187027 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:11.289334059 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:11.289376974 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:11.290857077 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:11.293406963 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:11.295741081 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:11.298414946 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:11.844225883 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:11.844716072 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:11.848773956 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:11.853794098 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.151607037 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.151755095 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.155432940 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.160312891 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.458834887 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.463525057 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.468457937 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.766756058 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.808406115 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.897182941 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.897284985 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.899260998 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.904141903 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.983935118 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.984112978 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.987842083 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.989866018 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:12.992924929 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:12.994784117 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:13.452972889 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:13.453125000 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:13.581192970 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:13.581228018 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:13.581518888 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:13.581518888 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:13.583822012 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:13.586307049 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:13.588706017 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:13.591308117 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.137025118 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.180285931 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.265316010 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.265681028 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.267644882 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.269921064 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.271838903 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.272650957 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.273538113 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.274766922 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.276829958 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.278405905 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.884135962 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.884475946 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.953164101 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.953273058 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.955853939 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.957735062 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:14.960851908 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:14.962610006 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:15.508914948 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:15.509085894 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:15.637223005 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:15.637363911 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:15.639225006 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:15.641333103 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:15.644085884 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:15.646217108 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:16.201102018 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:16.244302034 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:16.329648972 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:16.329843044 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:16.332221985 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:16.336699963 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:16.337232113 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:16.341808081 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:16.897247076 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:16.897752047 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.221924067 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.222181082 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.224570990 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.228143930 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.229458094 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.233079910 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.901732922 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.901967049 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.902028084 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.902117968 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.904108047 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.907131910 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.909499884 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.912517071 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.949660063 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.951016903 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:17.955255985 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:17.956326008 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:18.203779936 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:18.206811905 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:18.211760044 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:18.414638996 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:18.456296921 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:18.545731068 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:18.546080112 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:18.548634052 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:18.553822041 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:23.625958920 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:23.626372099 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:23.632380962 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:23.637721062 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:28.936718941 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:28.937397003 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:28.945784092 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:28.950977087 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:34.251745939 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:34.260353088 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:34.266086102 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:39.564157009 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:39.570189953 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:39.575321913 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:45.064210892 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:45.071350098 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:45.076781034 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:50.376276016 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:50.384479046 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:50.389765978 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:55.690941095 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:55.698916912 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:55.908488035 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 22:59:55.915213108 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 22:59:55.915258884 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:01.212775946 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:01.219650984 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:01.225277901 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:06.523356915 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:06.528711081 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:06.533723116 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:11.832422018 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:11.840919018 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:11.846103907 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:17.144857883 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:17.151323080 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:17.156821012 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:22.455173016 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:22.464531898 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:22.469945908 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:27.768441916 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:27.777371883 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:27.782514095 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:33.080586910 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:33.091495991 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:33.096657038 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:38.396487951 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:38.406744003 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:38.412147045 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:43.711972952 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:43.721012115 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:43.728677988 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:49.027107000 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:49.034168005 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:49.039040089 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:54.337201118 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:54.342299938 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:54.347256899 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:59.645941019 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:00:59.654659033 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:00:59.660249949 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:04.960048914 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:04.965954065 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:04.972237110 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:10.271362066 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:10.277615070 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:10.283233881 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:15.581262112 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:15.589589119 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:15.595211983 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:20.893234015 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:20.901612043 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:20.906914949 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:26.210320950 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:26.219090939 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:26.224687099 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:31.526046038 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:31.533001900 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:31.538038969 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:36.836251020 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:36.842885017 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:36.847800970 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:42.146617889 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:42.152544975 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:42.157871962 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:47.456414938 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:47.465854883 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:47.471219063 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:52.769639015 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:52.779597044 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:52.784904003 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:58.083334923 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:01:58.087553024 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:01:58.092660904 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:03.392287970 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:03.397464991 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:03.402595043 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:08.701697111 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:08.712255955 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:08.717329979 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:14.015985966 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:14.025456905 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:14.031122923 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:19.645750046 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:19.645782948 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:19.646420956 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:19.656586885 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:19.661842108 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:24.963238955 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:24.963522911 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:24.971134901 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:24.976197958 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:30.274583101 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:30.274863958 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:30.282623053 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:30.287720919 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:35.586541891 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:35.596244097 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:35.601576090 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:40.899688959 CEST32324580020.2.223.147192.168.2.13
    Oct 6, 2024 23:02:40.910129070 CEST458003232192.168.2.1320.2.223.147
    Oct 6, 2024 23:02:40.915683031 CEST32324580020.2.223.147192.168.2.13
    TimestampSource PortDest PortSource IPDest IP
    Oct 6, 2024 23:01:52.294662952 CEST5160453192.168.2.131.1.1.1
    Oct 6, 2024 23:01:52.294663906 CEST4583853192.168.2.131.1.1.1
    Oct 6, 2024 23:01:52.303236961 CEST53458381.1.1.1192.168.2.13
    Oct 6, 2024 23:01:52.316576004 CEST53516041.1.1.1192.168.2.13
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Oct 6, 2024 23:01:52.294662952 CEST192.168.2.131.1.1.10x870Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Oct 6, 2024 23:01:52.294663906 CEST192.168.2.131.1.1.10x1f05Standard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Oct 6, 2024 23:01:52.316576004 CEST1.1.1.1192.168.2.130x870No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
    Oct 6, 2024 23:01:52.316576004 CEST1.1.1.1192.168.2.130x870No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):20:59:08
    Start date (UTC):06/10/2024
    Path:/tmp/na.elf
    Arguments:/tmp/na.elf
    File size:4741000 bytes
    MD5 hash:b12d19bcf7b417ec41ffe87df5f80970

    Start time (UTC):20:59:08
    Start date (UTC):06/10/2024
    Path:/tmp/na.elf
    Arguments:-
    File size:4741000 bytes
    MD5 hash:b12d19bcf7b417ec41ffe87df5f80970

    Start time (UTC):20:59:08
    Start date (UTC):06/10/2024
    Path:/proc/self/exe
    Arguments:/proc/self/exe
    File size:4741000 bytes
    MD5 hash:b12d19bcf7b417ec41ffe87df5f80970

    Start time (UTC):20:59:17
    Start date (UTC):06/10/2024
    Path:/proc/self/exe
    Arguments:-
    File size:4741000 bytes
    MD5 hash:b12d19bcf7b417ec41ffe87df5f80970

    Start time (UTC):20:59:17
    Start date (UTC):06/10/2024
    Path:/usr/bin/whoami
    Arguments:whoami
    File size:39256 bytes
    MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710