Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1527370
MD5:01fe3ad934fa66a72120acfb88bad44c
SHA1:93514ae76cc5ac7b2c5fb77ef74f8b9b48ee8724
SHA256:ab20b8c733d2f1a34b837a37800b2bbcd48c80243f3cf1795bda8245c18ad6fb
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Machine Learning detection for sample
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Reads the 'hosts' file potentially containing internal network hosts
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1527370
Start date and time:2024-10-06 23:02:51 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 9s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal48.evad.linELF@0/0@4/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5456
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:2024/10/06 16:03:44 Forking
2024/10/06 16:03:45 Connecting to ssh.updategoogle.cc:3232
2024/10/06 16:03:48 Successfully connnected ssh.updategoogle.cc:3232
2024/10/06 16:03:48 [client] INFO ??:1 Its_ubl() : Handling channel: jump
2024/10/06 16:03:51 [103.212.49.88:3232] INFO ??:1 () : New SSH connection, version SSH-2.0-paramiko_3.0.0
2024/10/06 16:03:52 [103.212.49.88:3232] INFO ??:1 Its_ubl() : Handling channel: session
2024/10/06 16:03:53 [103.212.49.88:3232] INFO ??:1 Its_ubl() : Handling channel: session
2024/10/06 16:03:53 [103.212.49.88:3232] INFO ??:1 DIEtEm() : Session got request: "exec"
2024/10/06 16:03:54 [103.212.49.88:3232] INFO ??:3 DIEtEm() : Session disconnected
2024/10/06 16:03:54 [103.212.49.88:3232] INFO ??:6 DIEtEm() : Session disconnected
2024/10/06 16:03:54 [client] ERROR ??:1 () : Channel call back error: connection terminated
  • system is lnxubuntu20
  • na.elf (PID: 5456, Parent: 5376, MD5: 01fe3ad934fa66a72120acfb88bad44c) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5461, Parent: 5456)
    • exe (PID: 5461, Parent: 5456, MD5: 01fe3ad934fa66a72120acfb88bad44c) Arguments: /proc/self/exe
      • exe New Fork (PID: 5470, Parent: 5461)
      • whoami (PID: 5470, Parent: 5461, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: na.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.13:33588 -> 103.212.49.88:3232
Source: /proc/self/exe (PID: 5461)Reads hosts file: /etc/hostsJump to behavior
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: ssh.updategoogle.cc
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: na.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443
Source: LOAD without section mappingsProgram segment: 0x8048000
Source: classification engineClassification label: mal48.evad.linELF@0/0@4/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.96 Copyright (C) 1996-2020 the UPX Team. All Rights Reserved. $
Source: submitted sampleStderr: 2024/10/06 16:03:44 Forking2024/10/06 16:03:45 Connecting to ssh.updategoogle.cc:32322024/10/06 16:03:48 Successfully connnected ssh.updategoogle.cc:32322024/10/06 16:03:48 [client] INFO ??:1 Its_ubl() : Handling channel: jump2024/10/06 16:03:51 [103.212.49.88:3232] INFO ??:1 () : New SSH connection, version SSH-2.0-paramiko_3.0.02024/10/06 16:03:52 [103.212.49.88:3232] INFO ??:1 Its_ubl() : Handling channel: session2024/10/06 16:03:53 [103.212.49.88:3232] INFO ??:1 Its_ubl() : Handling channel: session2024/10/06 16:03:53 [103.212.49.88:3232] INFO ??:1 DIEtEm() : Session got request: "exec"2024/10/06 16:03:54 [103.212.49.88:3232] INFO ??:3 DIEtEm() : Session disconnected2024/10/06 16:03:54 [103.212.49.88:3232] INFO ??:6 DIEtEm() : Session disconnected2024/10/06 16:03:54 [client] ERROR ??:1 () : Channel call back error: connection terminated: exit code = 0
Source: na.elfSubmission file: segment LOAD with 7.8868 entropy (max. 8.0)
Source: /proc/self/exe (PID: 5461)Queries kernel information via 'uname': Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1527370 Sample: na.elf Startdate: 06/10/2024 Architecture: LINUX Score: 48 14 ssh.updategoogle.cc 103.212.49.88, 3232, 33588 CLOUDIE-AS-APCloudieLimitedHK China 2->14 16 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->16 18 daisy.ubuntu.com 2->18 20 Machine Learning detection for sample 2->20 22 Sample is packed with UPX 2->22 8 na.elf 2->8         started        signatures3 process4 process5 10 na.elf exe 8->10         started        process6 12 exe whoami 10->12         started       
SourceDetectionScannerLabelLink
na.elf17%ReversingLabsLinux.PUA.Generic
na.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.25
truefalse
    unknown
    ssh.updategoogle.cc
    103.212.49.88
    truefalse
      unknown
      NameSourceMaliciousAntivirus DetectionReputation
      http://upx.sf.netna.elftrue
      • URL Reputation: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      185.125.190.26
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      103.212.49.88
      ssh.updategoogle.ccChina
      55933CLOUDIE-AS-APCloudieLimitedHKfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      185.125.190.26na.elfGet hashmaliciousMoobotBrowse
        na.elfGet hashmaliciousUnknownBrowse
          na.elfGet hashmaliciousMiraiBrowse
            na.elfGet hashmaliciousMiraiBrowse
              na.elfGet hashmaliciousMiraiBrowse
                na.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousMirai, MoobotBrowse
                    na.elfGet hashmaliciousUnknownBrowse
                      na.elfGet hashmaliciousUnknownBrowse
                        na.elfGet hashmaliciousMirai, MoobotBrowse
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          daisy.ubuntu.comna.elfGet hashmaliciousUnknownBrowse
                          • 162.213.35.25
                          na.elfGet hashmaliciousUnknownBrowse
                          • 162.213.35.24
                          na.elfGet hashmaliciousMiraiBrowse
                          • 162.213.35.25
                          na.elfGet hashmaliciousMiraiBrowse
                          • 162.213.35.24
                          na.elfGet hashmaliciousUnknownBrowse
                          • 162.213.35.24
                          na.elfGet hashmaliciousUnknownBrowse
                          • 162.213.35.25
                          na.elfGet hashmaliciousUnknownBrowse
                          • 162.213.35.25
                          na.elfGet hashmaliciousMiraiBrowse
                          • 162.213.35.24
                          na.elfGet hashmaliciousUnknownBrowse
                          • 162.213.35.24
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          CLOUDIE-AS-APCloudieLimitedHKnovo.mips.elfGet hashmaliciousMirai, MoobotBrowse
                          • 191.96.215.15
                          H1pXo79CPdGet hashmaliciousGhostRatBrowse
                          • 103.118.253.78
                          SOA.exeGet hashmaliciousFormBookBrowse
                          • 103.59.102.59
                          http://telegsramc.club/Get hashmaliciousTelegram PhisherBrowse
                          • 103.76.84.225
                          https://www.shopapptime.xyz/Get hashmaliciousUnknownBrowse
                          • 45.153.129.178
                          https://tosigos.com/Get hashmaliciousUnknownBrowse
                          • 202.181.24.16
                          https://aomzsmaszs.com/index/ap/registerGet hashmaliciousUnknownBrowse
                          • 93.177.76.90
                          http://timihref.com/Get hashmaliciousUnknownBrowse
                          • 202.181.26.245
                          http://www.telegraxms.club/Get hashmaliciousTelegram PhisherBrowse
                          • 103.76.84.225
                          http://telegirams.club/Get hashmaliciousTelegram PhisherBrowse
                          • 103.140.127.114
                          CANONICAL-ASGBna.elfGet hashmaliciousMiraiBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousUnknownBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousUnknownBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousUnknownBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousUnknownBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousMiraiBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousMoobotBrowse
                          • 185.125.190.26
                          na.elfGet hashmaliciousMirai, MoobotBrowse
                          • 91.189.91.42
                          na.elfGet hashmaliciousUnknownBrowse
                          • 185.125.190.26
                          na.elfGet hashmaliciousUnknownBrowse
                          • 91.189.91.42
                          No context
                          No context
                          No created / dropped files found
                          File type:ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, no section header
                          Entropy (8bit):7.886813803801719
                          TrID:
                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                          File name:na.elf
                          File size:4'129'976 bytes
                          MD5:01fe3ad934fa66a72120acfb88bad44c
                          SHA1:93514ae76cc5ac7b2c5fb77ef74f8b9b48ee8724
                          SHA256:ab20b8c733d2f1a34b837a37800b2bbcd48c80243f3cf1795bda8245c18ad6fb
                          SHA512:83fb45736d3500708e724c1012780d3c1e26d31389b3b3b1fd64bc16d7739197a01bdc4eefa3054dc70907276e71aa9833d66c9f4df6bde7b811e94b0db14d07
                          SSDEEP:98304:MXnCLL2Sw1rW66dX2k5m9tf7uy/C5YNyQpWny3M:AnCLLHw5WprEuyKONKYM
                          TLSH:FE163342D5CBA62B49E88265AF7522A3E18C900FDD509351FF11E36B2E38F926739371
                          File Content Preview:.ELF....................H{C.4...........4. ...(.....................=.?.=.?...................C...C......8y.........Q.td............................='pZUPX!............................w....ELF........".{....4../. ...(..>..]w..........Q.U......6.b.o...n..?

                          ELF header

                          Class:ELF32
                          Data:2's complement, little endian
                          Version:1 (current)
                          Machine:Intel 80386
                          Version Number:0x1
                          Type:EXEC (Executable file)
                          OS/ABI:UNIX - Linux
                          ABI Version:0
                          Entry Point Address:0x8437b48
                          Flags:0x0
                          ELF Header Size:52
                          Program Header Offset:52
                          Program Header Size:32
                          Number of Program Headers:3
                          Section Header Offset:0
                          Section Header Size:40
                          Number of Section Headers:0
                          Header String Table Index:0
                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                          LOAD0x00x80480000x80480000x3f043d0x3f043d7.88680x5R E0x1000
                          LOAD0x00x84390000x84390000x00x79380c0.00000x6RW 0x1000
                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                          TimestampSource PortDest PortSource IPDest IP
                          Oct 6, 2024 23:03:46.429670095 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:46.434715033 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:46.434788942 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:46.435986996 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:46.440975904 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:47.358993053 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:47.359255075 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:47.424245119 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:47.429146051 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:47.492461920 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:47.492578030 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:47.500058889 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:47.504914999 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:47.985251904 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:47.985409975 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:47.998205900 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:48.003215075 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:48.093902111 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:48.093992949 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:48.100809097 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:48.106199026 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:48.557461023 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:48.562812090 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:48.567924976 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:48.890840054 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:48.895656109 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:48.900599003 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:49.302970886 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:49.307996035 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:49.313195944 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:49.738599062 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:49.779375076 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:49.893840075 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:49.894088030 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:49.901940107 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:49.907299042 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.009303093 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.009639025 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.024781942 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.029392004 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.030570984 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.034740925 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.540805101 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.541171074 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.672996044 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.673041105 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.673340082 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.673340082 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.678996086 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.684879065 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:50.685452938 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:50.691356897 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.240021944 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.283400059 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:51.372605085 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.372770071 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:51.377008915 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:51.381899118 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.383430004 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:51.386895895 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:51.388468027 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.390551090 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:51.391869068 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.395498991 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.974709988 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:51.975316048 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.108608007 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:52.108803034 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.114342928 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.119668007 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.119667053 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:52.124691010 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:52.715262890 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:52.715801001 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.852058887 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:52.852396965 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.857827902 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.863018990 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:52.864031076 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:52.869154930 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:53.459697962 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:53.503470898 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:53.593844891 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:53.593975067 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:53.599072933 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:53.604077101 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:53.607103109 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:53.612427950 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:54.158891916 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:54.159146070 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:54.296618938 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:54.296781063 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:54.300879955 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:54.306123972 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:54.306457996 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:54.311497927 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:54.903094053 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:54.903377056 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.036562920 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.036693096 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.042481899 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.047382116 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.050035954 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.055052996 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.105496883 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.110340118 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.110532045 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.115287066 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.251630068 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.257703066 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.263048887 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.483220100 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.527400017 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.555443048 CEST48202443192.168.2.13185.125.190.26
                          Oct 6, 2024 23:03:55.616826057 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:03:55.616925955 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.620600939 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:03:55.625701904 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:00.601834059 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:00.602169991 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:00.605976105 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:00.611574888 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:05.934772968 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:05.935009956 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:05.942536116 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:05.947709084 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:11.271029949 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:11.283432007 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:11.288784981 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:16.615061998 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:16.625566006 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:16.631191969 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:21.958178043 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:21.965437889 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:21.970923901 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:27.295242071 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:27.306006908 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:27.311604023 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:27.811464071 CEST48202443192.168.2.13185.125.190.26
                          Oct 6, 2024 23:04:32.634879112 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:32.643822908 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:32.649736881 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:37.972492933 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:37.979167938 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:37.984256983 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:43.919416904 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:43.919492006 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:43.919533014 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:43.919933081 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:43.919933081 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:43.929517984 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:43.935592890 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:49.259478092 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:49.259813070 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:49.267648935 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:49.273598909 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:54.597372055 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:54.597668886 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:54.606450081 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:54.611850977 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:59.935184002 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:04:59.943828106 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:04:59.949348927 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:05.272597075 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:05.281914949 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:05.287120104 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:10.900794983 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:10.900856972 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:10.901279926 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:10.911333084 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:10.916436911 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:16.243913889 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:16.244216919 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:16.252728939 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:16.258188963 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:21.581991911 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:21.582185984 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:21.588269949 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:21.594392061 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:26.918229103 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:26.928100109 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:26.933773041 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:32.257437944 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:32.265542030 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:32.271328926 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:37.593882084 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:37.601579905 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:37.607413054 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:42.929814100 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:42.937563896 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:42.942734003 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:48.266814947 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:48.274631023 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:48.279560089 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:53.603579998 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:53.613051891 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:53.618923903 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:58.941637039 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:05:58.949700117 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:05:58.955096960 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:04.278295040 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:04.286830902 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:04.292419910 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:09.616010904 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:09.624735117 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:09.630306005 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:14.953182936 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:14.960174084 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:14.965323925 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:20.288945913 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:20.298544884 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:20.303582907 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:25.628168106 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:25.635865927 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:25.640732050 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:30.963845015 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:30.974234104 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:30.979018927 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:36.302757025 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:36.307410955 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:36.314227104 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:41.637258053 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:41.642019987 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:41.648730040 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:46.971667051 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:46.980753899 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:46.986035109 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:52.308581114 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:52.315650940 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:52.320724964 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:57.643681049 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:06:57.651755095 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:06:57.656935930 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:02.980587006 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:02.985582113 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:07:02.990428925 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:08.323321104 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:08.329442978 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:07:08.334847927 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:13.658209085 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:13.667586088 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:07:13.672683954 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:18.996568918 CEST323233588103.212.49.88192.168.2.13
                          Oct 6, 2024 23:07:19.006160975 CEST335883232192.168.2.13103.212.49.88
                          Oct 6, 2024 23:07:19.011362076 CEST323233588103.212.49.88192.168.2.13
                          TimestampSource PortDest PortSource IPDest IP
                          Oct 6, 2024 23:03:46.184278965 CEST3440953192.168.2.131.1.1.1
                          Oct 6, 2024 23:03:46.185723066 CEST3310553192.168.2.131.1.1.1
                          Oct 6, 2024 23:03:46.425405025 CEST53331051.1.1.1192.168.2.13
                          Oct 6, 2024 23:03:46.425456047 CEST53344091.1.1.1192.168.2.13
                          Oct 6, 2024 23:06:30.284709930 CEST4726853192.168.2.131.1.1.1
                          Oct 6, 2024 23:06:30.284765005 CEST3976153192.168.2.131.1.1.1
                          Oct 6, 2024 23:06:30.291914940 CEST53397611.1.1.1192.168.2.13
                          Oct 6, 2024 23:06:30.292738914 CEST53472681.1.1.1192.168.2.13
                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                          Oct 6, 2024 23:03:46.184278965 CEST192.168.2.131.1.1.10x7b70Standard query (0)ssh.updategoogle.cc28IN (0x0001)false
                          Oct 6, 2024 23:03:46.185723066 CEST192.168.2.131.1.1.10x1b3bStandard query (0)ssh.updategoogle.ccA (IP address)IN (0x0001)false
                          Oct 6, 2024 23:06:30.284709930 CEST192.168.2.131.1.1.10x3cd3Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                          Oct 6, 2024 23:06:30.284765005 CEST192.168.2.131.1.1.10xa6d2Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                          Oct 6, 2024 23:03:46.425405025 CEST1.1.1.1192.168.2.130x1b3bNo error (0)ssh.updategoogle.cc103.212.49.88A (IP address)IN (0x0001)false
                          Oct 6, 2024 23:06:30.292738914 CEST1.1.1.1192.168.2.130x3cd3No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                          Oct 6, 2024 23:06:30.292738914 CEST1.1.1.1192.168.2.130x3cd3No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                          System Behavior

                          Start time (UTC):21:03:44
                          Start date (UTC):06/10/2024
                          Path:/tmp/na.elf
                          Arguments:/tmp/na.elf
                          File size:4129976 bytes
                          MD5 hash:01fe3ad934fa66a72120acfb88bad44c

                          Start time (UTC):21:03:44
                          Start date (UTC):06/10/2024
                          Path:/tmp/na.elf
                          Arguments:-
                          File size:4129976 bytes
                          MD5 hash:01fe3ad934fa66a72120acfb88bad44c

                          Start time (UTC):21:03:44
                          Start date (UTC):06/10/2024
                          Path:/proc/self/exe
                          Arguments:/proc/self/exe
                          File size:4129976 bytes
                          MD5 hash:01fe3ad934fa66a72120acfb88bad44c

                          Start time (UTC):21:03:53
                          Start date (UTC):06/10/2024
                          Path:/proc/self/exe
                          Arguments:-
                          File size:4129976 bytes
                          MD5 hash:01fe3ad934fa66a72120acfb88bad44c

                          Start time (UTC):21:03:53
                          Start date (UTC):06/10/2024
                          Path:/usr/bin/whoami
                          Arguments:whoami
                          File size:39256 bytes
                          MD5 hash:dbc1888ae50bb5d4d9a7a210d51be710