Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1527369
MD5:3559c2707f62c1f865580cee7b3171cd
SHA1:66eca3476f4dfc614509816801949071f77b71ca
SHA256:03f22c5d73c3cf11b65b6cfa90fbfc2571e76f9b3e8e0443685d739cf1002d8f
Tags:elfSupershelluser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Suricata IDS alerts for network traffic
Machine Learning detection for sample
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1527369
Start date and time:2024-10-06 23:02:17 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 17s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal56.evad.linELF@0/0@2/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5541
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:2024/10/06 16:03:12 Forking
2024/10/06 16:03:12 Connecting to 111.229.211.161:3232
2024/10/06 16:03:16 Successfully connnected 111.229.211.161:3232
2024/10/06 16:03:16 [client] INFO ??:1 BoFsrOtr() : Handling channel: jump
2024/10/06 16:03:19 [ws://111.229.211.161:3232/ws] INFO ??:1 () : New SSH connection, version SSH-2.0-paramiko_3.0.0
2024/10/06 16:03:20 [ws://111.229.211.161:3232/ws] INFO ??:1 BoFsrOtr() : Handling channel: session
2024/10/06 16:03:21 [ws://111.229.211.161:3232/ws] INFO ??:1 BoFsrOtr() : Handling channel: session
2024/10/06 16:03:21 [ws://111.229.211.161:3232/ws] INFO ??:1 IFu6thF7() : Session got request: "exec"
2024/10/06 16:03:22 [ws://111.229.211.161:3232/ws] INFO ??:3 IFu6thF7() : Session disconnected
2024/10/06 16:03:22 [ws://111.229.211.161:3232/ws] INFO ??:6 IFu6thF7() : Session disconnected
2024/10/06 16:03:22 [client] ERROR ??:1 () : Channel call back error: connection terminated
  • system is lnxubuntu20
  • na.elf (PID: 5541, Parent: 5469, MD5: 3559c2707f62c1f865580cee7b3171cd) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5546, Parent: 5541)
    • exe (PID: 5546, Parent: 5541, MD5: 3559c2707f62c1f865580cee7b3171cd) Arguments: /proc/self/exe
      • exe New Fork (PID: 5554, Parent: 5546)
      • whoami (PID: 5554, Parent: 5546, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-10-06T23:03:14.946044+020028500231A Network Trojan was detected111.229.211.1613232192.168.2.1551342TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: na.elfJoe Sandbox ML: detected

Networking

barindex
Source: Network trafficSuricata IDS: 2850023 - Severity 1 - ETPRO JA3 Hash - Possible Ligolo Server/Golang Binary Response : 111.229.211.161:3232 -> 192.168.2.15:51342
Source: global trafficTCP traffic: 192.168.2.15:51342 -> 111.229.211.161:3232
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: unknownTCP traffic detected without corresponding DNS query: 111.229.211.161
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: na.elfString found in binary or memory: http://upx.sf.net
Source: LOAD without section mappingsProgram segment: 0x400000
Source: classification engineClassification label: mal56.evad.linELF@0/0@2/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.96 Copyright (C) 1996-2020 the UPX Team. All Rights Reserved. $
Source: submitted sampleStderr: 2024/10/06 16:03:12 Forking2024/10/06 16:03:12 Connecting to 111.229.211.161:32322024/10/06 16:03:16 Successfully connnected 111.229.211.161:32322024/10/06 16:03:16 [client] INFO ??:1 BoFsrOtr() : Handling channel: jump2024/10/06 16:03:19 [ws://111.229.211.161:3232/ws] INFO ??:1 () : New SSH connection, version SSH-2.0-paramiko_3.0.02024/10/06 16:03:20 [ws://111.229.211.161:3232/ws] INFO ??:1 BoFsrOtr() : Handling channel: session2024/10/06 16:03:21 [ws://111.229.211.161:3232/ws] INFO ??:1 BoFsrOtr() : Handling channel: session2024/10/06 16:03:21 [ws://111.229.211.161:3232/ws] INFO ??:1 IFu6thF7() : Session got request: "exec"2024/10/06 16:03:22 [ws://111.229.211.161:3232/ws] INFO ??:3 IFu6thF7() : Session disconnected2024/10/06 16:03:22 [ws://111.229.211.161:3232/ws] INFO ??:6 IFu6thF7() : Session disconnected2024/10/06 16:03:22 [client] ERROR ??:1 () : Channel call back error: connection terminated: exit code = 0
Source: na.elfSubmission file: segment LOAD with 7.8854 entropy (max. 8.0)
Source: /proc/self/exe (PID: 5546)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1527369 Sample: na.elf Startdate: 06/10/2024 Architecture: LINUX Score: 56 14 111.229.211.161, 3232, 51342 CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompa China 2->14 16 daisy.ubuntu.com 2->16 18 Suricata IDS alerts for network traffic 2->18 20 Machine Learning detection for sample 2->20 22 Sample is packed with UPX 2->22 8 na.elf 2->8         started        signatures3 process4 process5 10 na.elf exe 8->10         started        process6 12 exe whoami 10->12         started       
SourceDetectionScannerLabelLink
na.elf17%ReversingLabsLinux.Trojan.Generic
na.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netna.elftrue
    • URL Reputation: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    111.229.211.161
    unknownChina
    45090CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompatrue
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    daisy.ubuntu.comna.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.25
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousUnknownBrowse
    • 162.213.35.24
    na.elfGet hashmaliciousMiraiBrowse
    • 162.213.35.25
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompana.elfGet hashmaliciousUnknownBrowse
    • 152.136.107.163
    ofR1Hd4NPM.exeGet hashmaliciousRunningRATBrowse
    • 119.29.18.61
    na.elfGet hashmaliciousMiraiBrowse
    • 106.55.42.255
    na.elfGet hashmaliciousMiraiBrowse
    • 129.28.238.208
    na.elfGet hashmaliciousMiraiBrowse
    • 62.234.235.129
    na.elfGet hashmaliciousMiraiBrowse
    • 109.244.173.155
    gSmGRFmE0C.exeGet hashmaliciousMetasploit, MeterpreterBrowse
    • 62.234.81.85
    novo.arm7.elfGet hashmaliciousMirai, MoobotBrowse
    • 134.175.9.149
    SecuriteInfo.com.Linux.Siggen.9999.30976.5557.elfGet hashmaliciousMiraiBrowse
    • 42.194.216.24
    8Vh32fbVGc.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
    • 122.51.22.201
    No context
    No context
    No created / dropped files found
    File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
    Entropy (8bit):7.885343477707851
    TrID:
    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
    File name:na.elf
    File size:4'741'256 bytes
    MD5:3559c2707f62c1f865580cee7b3171cd
    SHA1:66eca3476f4dfc614509816801949071f77b71ca
    SHA256:03f22c5d73c3cf11b65b6cfa90fbfc2571e76f9b3e8e0443685d739cf1002d8f
    SHA512:8a711b41ce9fc5a16b28e7966d955b7814a9b59997b5f55834a1f15c118756599549c2b58db83e92a4d5751769c8e9de205d133cc3844b1285b0e5cdb966b822
    SSDEEP:98304:/Fhc9QsDxuNnV+rIcsEP4wTEOFh8h/ClUp5pSP89r5pnDCzE+pLv8:TsYVoIcsELSP5w8lDCoJ
    TLSH:912633141261F377B8C86BD8F53B1184EEC6746820F8573B6E25E127A3B4EDB4B421B6
    File Content Preview:.ELF..............>......N......@...................@.8...@.......................@.......@......XH......XH..............................`.......`..............0.z.............Q.td.....................................................>U.UPX!...............

    ELF header

    Class:ELF64
    Data:2's complement, little endian
    Version:1 (current)
    Machine:Advanced Micro Devices X86-64
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x884e90
    Flags:0x0
    ELF Header Size:64
    Program Header Offset:64
    Program Header Size:56
    Number of Program Headers:3
    Section Header Offset:0
    Section Header Size:64
    Number of Section Headers:0
    Header String Table Index:0
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x4858080x4858087.88540x5R E0x1000
    LOAD0x00x8860000x8860000x00x7ae6300.00000x6RW 0x1000
    GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
    2024-10-06T23:03:14.946044+02002850023ETPRO JA3 Hash - Possible Ligolo Server/Golang Binary Response1111.229.211.1613232192.168.2.1551342TCP
    TimestampSource PortDest PortSource IPDest IP
    Oct 6, 2024 23:03:14.017580986 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:14.022664070 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:14.022731066 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:14.024485111 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:14.031603098 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:14.934986115 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:14.935022116 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:14.935163021 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:14.935163021 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:14.941225052 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:14.943892956 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:14.946043968 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:14.951196909 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:15.526432037 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:15.526653051 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:15.530422926 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:15.535267115 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:15.851161003 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:15.851485014 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:15.890229940 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:15.895232916 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:15.984711885 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:15.984812975 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:15.989064932 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:15.993890047 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:16.476469994 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:16.480299950 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:16.483779907 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:16.485157013 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:16.488590002 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:16.575886011 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:16.617522955 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:17.065151930 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:17.065327883 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:17.070683002 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:17.075607061 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:17.391819954 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:17.392031908 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:17.398756027 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:17.404062033 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:17.720268965 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:17.720495939 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:17.726619005 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:17.732469082 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.048975945 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.089600086 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.186011076 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.186211109 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.192601919 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.197696924 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.278894901 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.279047966 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.286304951 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.288558960 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.292419910 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.294667959 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.778330088 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.778747082 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.916620016 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.916661978 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.916805029 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.916805983 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.922884941 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.926698923 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:18.927966118 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:18.931986094 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:19.509222031 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:19.549474955 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:19.640631914 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:19.641050100 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:19.646641016 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:19.651495934 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:19.652631998 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:19.657136917 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:19.657613993 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:19.660780907 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:19.662230015 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:19.666225910 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:20.234225035 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:20.234602928 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:20.364708900 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:20.364820004 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:20.369544029 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:20.372602940 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:20.374483109 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:20.377832890 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:20.955234051 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:20.955410957 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.092890024 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:21.093015909 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.098664999 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.104368925 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.105150938 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:21.110490084 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:21.705137968 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:21.745359898 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.844647884 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:21.844912052 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.850560904 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.856173038 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:21.859491110 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:21.863740921 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:22.436094999 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:22.436384916 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:22.568613052 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:22.568728924 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:22.572206020 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:22.576827049 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:22.577167034 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:22.581943035 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.166081905 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.166306019 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.297007084 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.297240973 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.302339077 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.307111979 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.308080912 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.312817097 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.356021881 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.360445976 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.361198902 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.365358114 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.514240026 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.517748117 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.523443937 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.739464998 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.781270027 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.872592926 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:23.872700930 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.876564980 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:23.881500959 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:28.888606071 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:28.888884068 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:28.893135071 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:29.096982002 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:34.412457943 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:34.412754059 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:34.418515921 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:34.423348904 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:39.747531891 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:39.752873898 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:39.757839918 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:45.063834906 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:45.069853067 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:45.074807882 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:50.477937937 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:50.484674931 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:50.489903927 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:55.796309948 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:03:55.802911043 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:03:55.808034897 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:01.110635996 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:01.117765903 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:01.123718023 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:06.426553011 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:06.434813023 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:06.440134048 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:11.743648052 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:11.754667997 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:11.759948015 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:17.066793919 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:17.077624083 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:17.083619118 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:22.386507988 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:22.396476030 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:22.401900053 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:27.705445051 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:27.715938091 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:27.721154928 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:33.024256945 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:33.034653902 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:33.040105104 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:38.342924118 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:38.352132082 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:38.357129097 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:43.919512033 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:43.920011044 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:43.920460939 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:43.928925991 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:43.934910059 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:49.246413946 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:49.246823072 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:49.254909992 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:49.260241985 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:54.563313961 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:54.563935995 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:54.572464943 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:54.577965975 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:59.880773067 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:04:59.890347004 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:04:59.895451069 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:05.212436914 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:05.223325968 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:05.228578091 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:10.900731087 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:10.900827885 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:10.901164055 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:10.910938978 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:10.916134119 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:16.214575052 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:16.215140104 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:16.224592924 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:16.230078936 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:21.518341064 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:21.518698931 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:21.528636932 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:21.534419060 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:26.822935104 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:26.832575083 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:26.837884903 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:32.127192020 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:32.136313915 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:32.141381025 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:37.444214106 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:37.455065966 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:37.460325956 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:42.754103899 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:42.763515949 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:42.768670082 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:48.057280064 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:48.064984083 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:48.070024967 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:53.373445988 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:53.384449005 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:53.389674902 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:58.692301989 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:05:58.698443890 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:05:58.703636885 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:04.006356001 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:04.013051987 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:04.018584967 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:09.505577087 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:09.512655020 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:09.518681049 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:14.820971012 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:14.829461098 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:14.834394932 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:20.139106989 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:20.145339966 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:20.150301933 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:25.455809116 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:25.462403059 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:25.467354059 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:30.763824940 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:30.769174099 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:30.774038076 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:36.079734087 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:36.088846922 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:36.094372988 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:41.399847984 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:41.406773090 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:41.411783934 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:46.714505911 CEST323251342111.229.211.161192.168.2.15
    Oct 6, 2024 23:06:46.721520901 CEST513423232192.168.2.15111.229.211.161
    Oct 6, 2024 23:06:46.728451967 CEST323251342111.229.211.161192.168.2.15
    TimestampSource PortDest PortSource IPDest IP
    Oct 6, 2024 23:06:00.342959881 CEST3822753192.168.2.151.1.1.1
    Oct 6, 2024 23:06:00.342959881 CEST4906953192.168.2.151.1.1.1
    Oct 6, 2024 23:06:00.350936890 CEST53382271.1.1.1192.168.2.15
    Oct 6, 2024 23:06:00.350996017 CEST53490691.1.1.1192.168.2.15
    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
    Oct 6, 2024 23:06:00.342959881 CEST192.168.2.151.1.1.10xff2aStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
    Oct 6, 2024 23:06:00.342959881 CEST192.168.2.151.1.1.10x5e7eStandard query (0)daisy.ubuntu.com28IN (0x0001)false
    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
    Oct 6, 2024 23:06:00.350936890 CEST1.1.1.1192.168.2.150xff2aNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
    Oct 6, 2024 23:06:00.350936890 CEST1.1.1.1192.168.2.150xff2aNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

    System Behavior

    Start time (UTC):21:03:12
    Start date (UTC):06/10/2024
    Path:/tmp/na.elf
    Arguments:/tmp/na.elf
    File size:4741256 bytes
    MD5 hash:3559c2707f62c1f865580cee7b3171cd

    Start time (UTC):21:03:12
    Start date (UTC):06/10/2024
    Path:/tmp/na.elf
    Arguments:-
    File size:4741256 bytes
    MD5 hash:3559c2707f62c1f865580cee7b3171cd

    Start time (UTC):21:03:12
    Start date (UTC):06/10/2024
    Path:/proc/self/exe
    Arguments:/proc/self/exe
    File size:4741256 bytes
    MD5 hash:3559c2707f62c1f865580cee7b3171cd

    Start time (UTC):21:03:22
    Start date (UTC):06/10/2024
    Path:/proc/self/exe
    Arguments:-
    File size:4741256 bytes
    MD5 hash:3559c2707f62c1f865580cee7b3171cd

    Start time (UTC):21:03:22
    Start date (UTC):06/10/2024
    Path:/usr/bin/whoami
    Arguments:whoami
    File size:39256 bytes
    MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710