Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1527368
MD5:c669c8487b5586dc6580ea8e2bd29719
SHA1:264a4998ce2926b15e6974032be216b01168f60e
SHA256:73fc8f69d01fb8c5e37f19df9aa8e84d5724dde24cc124004167f450873d40f2
Tags:elfuser-abuse_ch
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1527368
Start date and time:2024-10-06 23:00:48 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 21s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal52.evad.linELF@0/0@2/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5637
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:2024/10/06 16:01:51 Forking
2024/10/06 16:01:51 Connecting to 152.136.107.163:3232
2024/10/06 16:01:54 Successfully connnected 152.136.107.163:3232
2024/10/06 16:01:55 [client] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: jump
2024/10/06 16:01:57 [152.136.107.163:3232] INFO jumphost.go:52 func1() : New SSH connection, version SSH-2.0-paramiko_3.0.0
2024/10/06 16:01:58 [152.136.107.163:3232] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: session
2024/10/06 16:01:59 [152.136.107.163:3232] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: session
2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:57 Session() : Session got request: "exec"
2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:109 Session() : Session disconnected
2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:157 Session() : Session disconnected
2024/10/06 16:02:00 [client] ERROR jumphost.go:97 func1() : Channel call back error: connection terminated
  • system is lnxubuntu20
  • na.elf (PID: 5637, Parent: 5555, MD5: c669c8487b5586dc6580ea8e2bd29719) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5642, Parent: 5637)
    • exe (PID: 5642, Parent: 5637, MD5: c669c8487b5586dc6580ea8e2bd29719) Arguments: /proc/self/exe
      • exe New Fork (PID: 5651, Parent: 5642)
      • whoami (PID: 5651, Parent: 5642, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: na.elfReversingLabs: Detection: 28%
Source: global trafficTCP traffic: 192.168.2.14:38832 -> 152.136.107.163:3232
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: unknownTCP traffic detected without corresponding DNS query: 152.136.107.163
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: na.elfString found in binary or memory: http://upx.sf.net
Source: LOAD without section mappingsProgram segment: 0x400000
Source: classification engineClassification label: mal52.evad.linELF@0/0@2/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.96 Copyright (C) 1996-2020 the UPX Team. All Rights Reserved. $
Source: submitted sampleStderr: 2024/10/06 16:01:51 Forking2024/10/06 16:01:51 Connecting to 152.136.107.163:32322024/10/06 16:01:54 Successfully connnected 152.136.107.163:32322024/10/06 16:01:55 [client] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: jump2024/10/06 16:01:57 [152.136.107.163:3232] INFO jumphost.go:52 func1() : New SSH connection, version SSH-2.0-paramiko_3.0.02024/10/06 16:01:58 [152.136.107.163:3232] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: session2024/10/06 16:01:59 [152.136.107.163:3232] INFO global.go:118 RegisterChannelCallbacks() : Handling channel: session2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:57 Session() : Session got request: "exec"2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:109 Session() : Session disconnected2024/10/06 16:02:00 [152.136.107.163:3232] INFO session.go:157 Session() : Session disconnected2024/10/06 16:02:00 [client] ERROR jumphost.go:97 func1() : Channel call back error: connection terminated: exit code = 0
Source: na.elfSubmission file: segment LOAD with 7.8829 entropy (max. 8.0)
Source: /proc/self/exe (PID: 5642)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1527368 Sample: na.elf Startdate: 06/10/2024 Architecture: LINUX Score: 52 14 152.136.107.163, 3232, 38832 CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompa China 2->14 16 daisy.ubuntu.com 2->16 18 Multi AV Scanner detection for submitted file 2->18 20 Sample is packed with UPX 2->20 8 na.elf 2->8         started        signatures3 process4 process5 10 na.elf exe 8->10         started        process6 12 exe whoami 10->12         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
na.elf29%ReversingLabsLinux.Hacktool.RevhellMarte
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
unknown
unknownfalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netna.elftrue
    • URL Reputation: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    152.136.107.163
    unknownChina
    45090CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompafalse
    No context
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompaofR1Hd4NPM.exeGet hashmaliciousRunningRATBrowse
    • 119.29.18.61
    na.elfGet hashmaliciousMiraiBrowse
    • 106.55.42.255
    na.elfGet hashmaliciousMiraiBrowse
    • 129.28.238.208
    na.elfGet hashmaliciousMiraiBrowse
    • 62.234.235.129
    na.elfGet hashmaliciousMiraiBrowse
    • 109.244.173.155
    gSmGRFmE0C.exeGet hashmaliciousMetasploit, MeterpreterBrowse
    • 62.234.81.85
    novo.arm7.elfGet hashmaliciousMirai, MoobotBrowse
    • 134.175.9.149
    SecuriteInfo.com.Linux.Siggen.9999.30976.5557.elfGet hashmaliciousMiraiBrowse
    • 42.194.216.24
    8Vh32fbVGc.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
    • 122.51.22.201
    https://asbdjdas-asd.top/Get hashmaliciousUnknownBrowse
    • 111.231.169.247
    No context
    No context
    No created / dropped files found
    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
    Entropy (8bit):7.882845039462739
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:na.elf
    File size:3'282'304 bytes
    MD5:c669c8487b5586dc6580ea8e2bd29719
    SHA1:264a4998ce2926b15e6974032be216b01168f60e
    SHA256:73fc8f69d01fb8c5e37f19df9aa8e84d5724dde24cc124004167f450873d40f2
    SHA512:fa49ccd21aec928edf20887ff4b88592cd8d281d7926e1c1d9fe539f725a3101a9add3d058fe0656475c0a00b8f0951c38f73f9bef1a2c859cd07884fced19f0
    SSDEEP:98304:JkktXm1YJc9muZcKTc9HNu510CCtCE4sdh7:JM1YJaZcBzCYCoh7
    TLSH:7FE533A78812497C141A727937D6F55A31DF7AF24A84CCB2115F4F878A7F2EEDA31820
    File Content Preview:.ELF..............>.......r.....@...................@.8...@.......................@.......@.......2.......2.............................. r...... r.............P.Q.............Q.td.....................................................?..UPX!.........0...0.

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x720b88
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:64
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x3215000x3215007.88290x5R E0x1000
    LOAD0x00x7220000x7220000x00x5103500.00000x6RW 0x1000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
    TimestampSource PortDest PortSource IPDest IP
    Oct 6, 2024 23:01:53.116647005 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:53.121831894 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:53.122255087 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:53.124332905 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:53.139101028 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.016747952 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.017072916 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:54.113425016 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:54.118880033 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.148802996 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.148981094 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:54.156619072 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:54.202420950 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.674113035 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.674484015 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:54.678570986 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:54.682116985 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:54.683562040 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.686992884 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.774285078 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:54.774615049 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:55.237757921 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:55.238112926 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:55.242588043 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:55.248034954 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:55.550688028 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:55.558151007 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:55.563668013 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:55.866085052 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:55.872595072 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:55.878247023 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.180910110 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.223903894 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:56.329221964 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.329444885 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:56.336194038 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:56.341608047 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.419466972 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.419557095 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:56.428601027 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:56.432163954 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:56.433849096 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.437654972 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.898201942 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:56.898425102 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.033907890 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.034141064 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.034607887 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.034813881 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.040999889 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.046456099 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.047059059 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.051342010 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.605818987 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.648161888 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.736505032 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.736778021 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.744672060 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.749557018 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.750014067 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.753019094 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.754807949 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.755748034 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:57.757930040 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:57.760555029 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:58.305756092 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:58.306001902 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:58.440632105 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:58.440970898 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:58.445003033 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:58.448657990 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:58.450867891 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:58.454210043 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.005919933 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.006429911 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.138648987 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.139115095 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.144598007 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.149614096 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.149933100 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.154850960 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.709817886 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.751796961 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.840882063 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.841386080 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.848323107 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.853472948 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:01:59.857778072 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:01:59.862946987 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:00.409759045 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:00.409975052 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:00.540785074 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:00.541234970 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:00.547470093 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:00.552968025 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:00.555638075 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:00.561209917 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.110101938 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.110547066 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.244906902 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.245362043 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.251466990 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.256493092 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.260552883 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.265502930 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.320285082 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.325295925 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.325912952 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.330863953 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.643724918 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.647738934 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.652697086 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.817625999 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.859834909 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.948621035 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:01.948863983 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.956428051 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:01.961334944 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:07.029412031 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:07.030061007 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:07.037178993 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:07.042265892 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:12.347491026 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:12.348089933 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:12.354918003 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:12.360407114 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:17.663039923 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:17.668055058 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:17.673257113 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:22.980129957 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:22.986711025 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:22.992003918 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:28.294605970 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:28.298914909 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:28.303735018 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:33.607338905 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:33.613348961 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:33.618623018 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:38.921207905 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:38.929033995 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:38.934453964 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:44.237771034 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:44.245521069 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:44.454071999 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:44.479521990 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:44.479589939 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:44.479624987 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:44.479744911 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:49.781959057 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:49.782180071 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:49.787018061 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:49.792071104 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:55.096049070 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:02:55.096473932 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:55.104604959 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:02:55.110258102 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:00.413166046 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:00.413322926 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:00.418343067 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:00.423338890 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:05.727226973 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:05.733061075 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:05.738636971 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:11.041060925 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:11.046678066 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:11.052633047 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:16.355571985 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:16.361712933 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:16.366611958 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:21.676371098 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:21.686219931 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:21.692436934 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:26.993835926 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:27.001729012 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:27.007124901 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:32.309886932 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:32.316708088 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:32.321577072 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:37.629667044 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:37.635545969 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:37.640486956 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:42.943622112 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:42.951263905 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:42.956182003 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:48.259659052 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:48.266697884 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:48.271768093 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:53.581967115 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:53.589771986 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:53.594737053 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:58.897886038 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:03:58.904741049 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:03:58.909919977 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:04.212934017 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:04.219681025 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:04.224912882 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:09.534940004 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:09.544469118 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:09.549504995 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:14.852775097 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:14.859675884 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:14.864965916 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:20.169061899 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:20.176700115 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:20.184317112 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:25.486939907 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:25.495956898 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:25.501135111 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:30.804155111 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:30.812778950 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:30.818391085 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:36.121670008 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:36.144273043 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:36.149709940 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:36.585402966 CEST4516253192.168.2.148.8.8.8
    Oct 6, 2024 23:04:36.590694904 CEST53451628.8.8.8192.168.2.14
    Oct 6, 2024 23:04:36.590919018 CEST4516253192.168.2.148.8.8.8
    Oct 6, 2024 23:04:36.590919018 CEST4516253192.168.2.148.8.8.8
    Oct 6, 2024 23:04:36.590919018 CEST4516253192.168.2.148.8.8.8
    Oct 6, 2024 23:04:36.595959902 CEST53451628.8.8.8192.168.2.14
    Oct 6, 2024 23:04:36.595990896 CEST53451628.8.8.8192.168.2.14
    Oct 6, 2024 23:04:37.034034014 CEST53451628.8.8.8192.168.2.14
    Oct 6, 2024 23:04:37.034337044 CEST4516253192.168.2.148.8.8.8
    Oct 6, 2024 23:04:39.034188032 CEST53451628.8.8.8192.168.2.14
    Oct 6, 2024 23:04:39.034454107 CEST4516253192.168.2.148.8.8.8
    Oct 6, 2024 23:04:39.040481091 CEST53451628.8.8.8192.168.2.14
    Oct 6, 2024 23:04:41.452438116 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:41.457245111 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:41.462297916 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:46.766356945 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:46.772836924 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:46.778027058 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:52.166044950 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:52.175704002 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:52.180767059 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:57.883575916 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:57.883654118 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:04:57.883761883 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:57.892124891 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:04:57.898271084 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:03.241844893 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:03.242257118 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:05:03.249671936 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:05:03.255229950 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:08.557706118 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:08.558305025 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:05:08.566404104 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:05:08.572004080 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:13.874814987 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:13.884633064 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:05:13.889993906 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:19.193042040 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:19.202816010 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:05:19.208077908 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:24.511090994 CEST323238832152.136.107.163192.168.2.14
    Oct 6, 2024 23:05:24.520797014 CEST388323232192.168.2.14152.136.107.163
    Oct 6, 2024 23:05:24.526833057 CEST323238832152.136.107.163192.168.2.14
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Oct 6, 2024 23:04:36.590919018 CEST192.168.2.148.8.8.80x2a5cStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Oct 6, 2024 23:04:36.590919018 CEST192.168.2.148.8.8.80xbd84Standard query (0)daisy.ubuntu.com28IN (0x0001)false

    System Behavior

    Start time (UTC):21:01:51
    Start date (UTC):06/10/2024
    Path:/tmp/na.elf
    Arguments:/tmp/na.elf
    File size:3282304 bytes
    MD5 hash:c669c8487b5586dc6580ea8e2bd29719

    Start time (UTC):21:01:51
    Start date (UTC):06/10/2024
    Path:/tmp/na.elf
    Arguments:-
    File size:3282304 bytes
    MD5 hash:c669c8487b5586dc6580ea8e2bd29719

    Start time (UTC):21:01:51
    Start date (UTC):06/10/2024
    Path:/proc/self/exe
    Arguments:/proc/self/exe
    File size:3282304 bytes
    MD5 hash:c669c8487b5586dc6580ea8e2bd29719

    Start time (UTC):21:02:00
    Start date (UTC):06/10/2024
    Path:/proc/self/exe
    Arguments:-
    File size:3282304 bytes
    MD5 hash:c669c8487b5586dc6580ea8e2bd29719

    Start time (UTC):21:02:00
    Start date (UTC):06/10/2024
    Path:/usr/bin/whoami
    Arguments:whoami
    File size:39256 bytes
    MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710