Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
na.elf

Overview

General Information

Sample name:na.elf
Analysis ID:1528778
MD5:f56ba281f91d4d31de3af57e72dee818
SHA1:3fea0260ade94a6ee41244398c0ac095c44c9899
SHA256:b561e39594ff47df3eeac90d75996213255090763d1cde1a1eace6c945659981
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1528778
Start date and time:2024-10-08 10:46:14 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 22s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:na.elf
Detection:MAL
Classification:mal56.linELF@0/0@36/0
Command:/tmp/na.elf
PID:6206
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
zenci
Standard Error:
  • system is lnxubuntu20
  • na.elf (PID: 6206, Parent: 6123, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/na.elf
    • na.elf New Fork (PID: 6208, Parent: 6206)
      • na.elf New Fork (PID: 6214, Parent: 6208)
  • udisksd New Fork (PID: 6220, Parent: 799)
  • dumpe2fs (PID: 6220, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: na.elfAvira: detected
Source: na.elfVirustotal: Detection: 57%Perma Link
Source: na.elfReversingLabs: Detection: 52%
Source: /tmp/na.elf (PID: 6206)Socket: 127.0.0.1:2353Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownDNS traffic detected: query: akamaisus.dyn replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 139.84.165.176
Source: unknownUDP traffic detected without corresponding DNS query: 65.21.1.106
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: unknownUDP traffic detected without corresponding DNS query: 5.161.109.23
Source: unknownUDP traffic detected without corresponding DNS query: 70.34.254.19
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 137.220.52.23
Source: global trafficDNS traffic detected: DNS query: akamaisus.dyn
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@36/0
Source: /tmp/na.elf (PID: 6206)Queries kernel information via 'uname': Jump to behavior
Source: na.elf, 6206.1.00007fff7c556000.00007fff7c577000.rw-.sdmp, na.elf, 6214.1.00007fff7c556000.00007fff7c577000.rw-.sdmpBinary or memory string: O>S<x86_64/usr/bin/qemu-sh4/tmp/na.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/na.elf
Source: na.elf, 6206.1.00007fff7c556000.00007fff7c577000.rw-.sdmp, na.elf, 6214.1.00007fff7c556000.00007fff7c577000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: na.elf, 6206.1.000055e3036f5000.000055e303758000.rw-.sdmp, na.elf, 6214.1.000055e3036f5000.000055e303758000.rw-.sdmpBinary or memory string: U5!/etc/qemu-binfmt/sh4
Source: na.elf, 6206.1.000055e3036f5000.000055e303758000.rw-.sdmp, na.elf, 6214.1.000055e3036f5000.000055e303758000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1528778 Sample: na.elf Startdate: 08/10/2024 Architecture: LINUX Score: 56 16 109.202.202.202, 80 INIT7CH Switzerland 2->16 18 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->18 20 2 other IPs or domains 2->20 22 Antivirus / Scanner detection for submitted sample 2->22 24 Multi AV Scanner detection for submitted file 2->24 8 na.elf 2->8         started        10 udisksd dumpe2fs 2->10         started        signatures3 process4 process5 12 na.elf 8->12         started        process6 14 na.elf 12->14         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
na.elf57%VirustotalBrowse
na.elf53%ReversingLabsLinux.Exploit.Mirai
na.elf100%AviraEXP/ELF.Mirai.W
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
akamaisus.dyn
unknown
unknownfalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43na.elfGet hashmaliciousUnknownBrowse
      na.elfGet hashmaliciousUnknownBrowse
        na.elfGet hashmaliciousUnknownBrowse
          na.elfGet hashmaliciousMiraiBrowse
            na.elfGet hashmaliciousUnknownBrowse
              na.elfGet hashmaliciousMiraiBrowse
                na.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousUnknownBrowse
                    na.elfGet hashmaliciousMiraiBrowse
                      na.elfGet hashmaliciousMiraiBrowse
                        91.189.91.42na.elfGet hashmaliciousUnknownBrowse
                          na.elfGet hashmaliciousUnknownBrowse
                            na.elfGet hashmaliciousUnknownBrowse
                              na.elfGet hashmaliciousUnknownBrowse
                                na.elfGet hashmaliciousMiraiBrowse
                                  na.elfGet hashmaliciousMiraiBrowse
                                    na.elfGet hashmaliciousUnknownBrowse
                                      na.elfGet hashmaliciousMiraiBrowse
                                        na.elfGet hashmaliciousUnknownBrowse
                                          na.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBna.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBna.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            INIT7CHna.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):6.798100793666167
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:na.elf
                                            File size:55'472 bytes
                                            MD5:f56ba281f91d4d31de3af57e72dee818
                                            SHA1:3fea0260ade94a6ee41244398c0ac095c44c9899
                                            SHA256:b561e39594ff47df3eeac90d75996213255090763d1cde1a1eace6c945659981
                                            SHA512:523f314a2f3c74162fe7fdc82376fe0906a10f1bbb53638d00e82bf8cc4c0359574f1584913a71a6210f89b9846570920b47e67adff9d2478b5dade8b43a5516
                                            SSDEEP:768:CBg4h+aWmD/HiehHqU2jLBc6iM4SrC5PL8bdKLehPgaYopNv+okCxKlFkfbGXKI:CBfh+3x1LjG27KihPb3fPkCxvGa
                                            TLSH:4F439E3BC42A2E58E19482F5B8658F791B53F94482476FFE16A6C1328047EACF7493F4
                                            File Content Preview:.ELF..............*.......@.4... .......4. ...(...............@...@.|...|.....................A...A.`....5..........Q.td............................././"O.n........#.*@........#.*@L....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:<unknown>
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x4001a0
                                            Flags:0x9
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:55072
                                            Section Header Size:40
                                            Number of Section Headers:10
                                            Header String Table Index:9
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x300x00x6AX004
                                            .textPROGBITS0x4000e00xe00xbe600x00x6AX0032
                                            .finiPROGBITS0x40bf400xbf400x240x00x6AX004
                                            .rodataPROGBITS0x40bf640xbf640x14180x00x2A004
                                            .ctorsPROGBITS0x41d3800xd3800x80x00x3WA004
                                            .dtorsPROGBITS0x41d3880xd3880x80x00x3WA004
                                            .dataPROGBITS0x41d3940xd3940x34c0x00x3WA004
                                            .bssNOBITS0x41d6e00xd6e00x31b80x00x3WA004
                                            .shstrtabSTRTAB0x00xd6e00x3e0x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000xd37c0xd37c6.85380x5R E0x10000.init .text .fini .rodata
                                            LOAD0xd3800x41d3800x41d3800x3600x35182.66130x6RW 0x10000.ctors .dtors .data .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSource PortDest PortSource IPDest IP
                                            Oct 8, 2024 10:46:52.765188932 CEST43928443192.168.2.2391.189.91.42
                                            Oct 8, 2024 10:46:58.396497965 CEST42836443192.168.2.2391.189.91.43
                                            Oct 8, 2024 10:46:59.932334900 CEST4251680192.168.2.23109.202.202.202
                                            Oct 8, 2024 10:47:13.242619991 CEST43928443192.168.2.2391.189.91.42
                                            Oct 8, 2024 10:47:25.528721094 CEST42836443192.168.2.2391.189.91.43
                                            Oct 8, 2024 10:47:29.624435902 CEST4251680192.168.2.23109.202.202.202
                                            Oct 8, 2024 10:47:54.196737051 CEST43928443192.168.2.2391.189.91.42
                                            TimestampSource PortDest PortSource IPDest IP
                                            Oct 8, 2024 10:46:53.490731001 CEST4458753192.168.2.23185.181.61.24
                                            Oct 8, 2024 10:46:53.524496078 CEST5344587185.181.61.24192.168.2.23
                                            Oct 8, 2024 10:46:53.525414944 CEST4815553192.168.2.23139.84.165.176
                                            Oct 8, 2024 10:46:58.531227112 CEST4955253192.168.2.23139.84.165.176
                                            Oct 8, 2024 10:47:03.540537119 CEST5242753192.168.2.23139.84.165.176
                                            Oct 8, 2024 10:47:15.548048019 CEST3762153192.168.2.2370.34.254.19
                                            Oct 8, 2024 10:47:20.554162025 CEST5976653192.168.2.23178.254.22.166
                                            Oct 8, 2024 10:47:25.560128927 CEST3803853192.168.2.23178.254.22.166
                                            Oct 8, 2024 10:47:30.567487955 CEST3292653192.168.2.2380.152.203.134
                                            Oct 8, 2024 10:47:30.807508945 CEST533292680.152.203.134192.168.2.23
                                            Oct 8, 2024 10:47:32.813790083 CEST5282053192.168.2.23194.36.144.87
                                            Oct 8, 2024 10:47:32.824151039 CEST5352820194.36.144.87192.168.2.23
                                            Oct 8, 2024 10:47:32.826179028 CEST4229353192.168.2.2380.152.203.134
                                            Oct 8, 2024 10:47:32.859730005 CEST534229380.152.203.134192.168.2.23
                                            Oct 8, 2024 10:47:32.862624884 CEST4254753192.168.2.2380.152.203.134
                                            Oct 8, 2024 10:47:32.885931015 CEST534254780.152.203.134192.168.2.23
                                            Oct 8, 2024 10:47:32.888154984 CEST4232153192.168.2.2381.169.136.222
                                            Oct 8, 2024 10:47:32.916543961 CEST534232181.169.136.222192.168.2.23
                                            Oct 8, 2024 10:47:38.922382116 CEST6049353192.168.2.2381.169.136.222
                                            Oct 8, 2024 10:47:38.950802088 CEST536049381.169.136.222192.168.2.23
                                            Oct 8, 2024 10:47:38.951843977 CEST4056753192.168.2.23152.53.15.127
                                            Oct 8, 2024 10:47:38.962080956 CEST5340567152.53.15.127192.168.2.23
                                            Oct 8, 2024 10:47:38.963320017 CEST3306153192.168.2.23152.53.15.127
                                            Oct 8, 2024 10:47:38.974028111 CEST5333061152.53.15.127192.168.2.23
                                            Oct 8, 2024 10:47:38.975219965 CEST3711653192.168.2.2365.21.1.106
                                            Oct 8, 2024 10:47:39.002233982 CEST533711665.21.1.106192.168.2.23
                                            Oct 8, 2024 10:47:46.006072044 CEST5511253192.168.2.23137.220.52.23
                                            Oct 8, 2024 10:47:51.011399984 CEST3410053192.168.2.23202.61.197.122
                                            Oct 8, 2024 10:47:51.021888018 CEST5334100202.61.197.122192.168.2.23
                                            Oct 8, 2024 10:47:51.023066044 CEST3765253192.168.2.2381.169.136.222
                                            Oct 8, 2024 10:47:51.050879955 CEST533765281.169.136.222192.168.2.23
                                            Oct 8, 2024 10:47:51.051836967 CEST3682553192.168.2.2370.34.254.19
                                            Oct 8, 2024 10:48:06.057898998 CEST5564953192.168.2.23168.235.111.72
                                            Oct 8, 2024 10:48:06.147540092 CEST5355649168.235.111.72192.168.2.23
                                            Oct 8, 2024 10:48:06.149466038 CEST5836253192.168.2.23137.220.52.23
                                            Oct 8, 2024 10:48:11.155428886 CEST3792553192.168.2.23152.53.15.127
                                            Oct 8, 2024 10:48:11.408198118 CEST5337925152.53.15.127192.168.2.23
                                            Oct 8, 2024 10:48:11.409192085 CEST3653753192.168.2.2365.21.1.106
                                            Oct 8, 2024 10:48:11.435720921 CEST533653765.21.1.106192.168.2.23
                                            Oct 8, 2024 10:48:12.438033104 CEST3931353192.168.2.23139.84.165.176
                                            Oct 8, 2024 10:48:17.443633080 CEST5679353192.168.2.2365.21.1.106
                                            Oct 8, 2024 10:48:17.470345974 CEST535679365.21.1.106192.168.2.23
                                            Oct 8, 2024 10:48:17.471493006 CEST4950053192.168.2.235.161.109.23
                                            Oct 8, 2024 10:48:22.477396965 CEST5755853192.168.2.2381.169.136.222
                                            Oct 8, 2024 10:48:22.505105019 CEST535755881.169.136.222192.168.2.23
                                            Oct 8, 2024 10:48:23.509660006 CEST4256953192.168.2.23137.220.52.23
                                            Oct 8, 2024 10:48:28.515865088 CEST5519953192.168.2.235.161.109.23
                                            Oct 8, 2024 10:48:33.521059990 CEST4704853192.168.2.2370.34.254.19
                                            Oct 8, 2024 10:48:38.522218943 CEST4789953192.168.2.23185.181.61.24
                                            Oct 8, 2024 10:48:38.555641890 CEST5347899185.181.61.24192.168.2.23
                                            Oct 8, 2024 10:48:47.559101105 CEST5777653192.168.2.23217.160.70.42
                                            Oct 8, 2024 10:48:47.592031956 CEST5357776217.160.70.42192.168.2.23
                                            Oct 8, 2024 10:48:47.593813896 CEST4450353192.168.2.2380.152.203.134
                                            Oct 8, 2024 10:48:47.652964115 CEST534450380.152.203.134192.168.2.23
                                            Oct 8, 2024 10:48:47.654992104 CEST5189953192.168.2.23217.160.70.42
                                            Oct 8, 2024 10:48:47.682116985 CEST5351899217.160.70.42192.168.2.23
                                            Oct 8, 2024 10:48:47.683422089 CEST4224153192.168.2.23137.220.52.23
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Oct 8, 2024 10:46:53.490731001 CEST192.168.2.23185.181.61.240x871dStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:46:53.525414944 CEST192.168.2.23139.84.165.1760x2a9cStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:46:58.531227112 CEST192.168.2.23139.84.165.1760xed10Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:03.540537119 CEST192.168.2.23139.84.165.1760x927aStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:15.548048019 CEST192.168.2.2370.34.254.190x4a0bStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:20.554162025 CEST192.168.2.23178.254.22.1660xc28cStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:25.560128927 CEST192.168.2.23178.254.22.1660xf004Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:30.567487955 CEST192.168.2.2380.152.203.1340xf70aStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.813790083 CEST192.168.2.23194.36.144.870xa1Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.826179028 CEST192.168.2.2380.152.203.1340x3733Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.862624884 CEST192.168.2.2380.152.203.1340x8482Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.888154984 CEST192.168.2.2381.169.136.2220xd6bdStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:38.922382116 CEST192.168.2.2381.169.136.2220xf33eStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:38.951843977 CEST192.168.2.23152.53.15.1270xd53dStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:38.963320017 CEST192.168.2.23152.53.15.1270x526dStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:38.975219965 CEST192.168.2.2365.21.1.1060xf25eStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:46.006072044 CEST192.168.2.23137.220.52.230x7a8Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:51.011399984 CEST192.168.2.23202.61.197.1220x123aStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:51.023066044 CEST192.168.2.2381.169.136.2220xc9edStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:51.051836967 CEST192.168.2.2370.34.254.190xc794Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:06.057898998 CEST192.168.2.23168.235.111.720x5e40Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:06.149466038 CEST192.168.2.23137.220.52.230xb69aStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:11.155428886 CEST192.168.2.23152.53.15.1270x4549Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:11.409192085 CEST192.168.2.2365.21.1.1060xf7bbStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:12.438033104 CEST192.168.2.23139.84.165.1760x7f3aStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:17.443633080 CEST192.168.2.2365.21.1.1060x616cStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:17.471493006 CEST192.168.2.235.161.109.230xf8e3Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:22.477396965 CEST192.168.2.2381.169.136.2220x6857Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:23.509660006 CEST192.168.2.23137.220.52.230x44aStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:28.515865088 CEST192.168.2.235.161.109.230x3a5dStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:33.521059990 CEST192.168.2.2370.34.254.190x2e74Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:38.522218943 CEST192.168.2.23185.181.61.240x18dcStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:47.559101105 CEST192.168.2.23217.160.70.420x684cStandard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:47.593813896 CEST192.168.2.2380.152.203.1340xa660Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:47.654992104 CEST192.168.2.23217.160.70.420x3b74Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:47.683422089 CEST192.168.2.23137.220.52.230x70e8Standard query (0)akamaisus.dynA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Oct 8, 2024 10:46:53.524496078 CEST185.181.61.24192.168.2.230x871dName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:30.807508945 CEST80.152.203.134192.168.2.230xf70aName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.824151039 CEST194.36.144.87192.168.2.230xa1Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.859730005 CEST80.152.203.134192.168.2.230x3733Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.885931015 CEST80.152.203.134192.168.2.230x8482Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:32.916543961 CEST81.169.136.222192.168.2.230xd6bdName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:38.950802088 CEST81.169.136.222192.168.2.230xf33eName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:38.962080956 CEST152.53.15.127192.168.2.230xd53dName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:38.974028111 CEST152.53.15.127192.168.2.230x526dName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:39.002233982 CEST65.21.1.106192.168.2.230xf25eName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:51.021888018 CEST202.61.197.122192.168.2.230x123aName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:47:51.050879955 CEST81.169.136.222192.168.2.230xc9edName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:06.147540092 CEST168.235.111.72192.168.2.230x5e40Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:11.408198118 CEST152.53.15.127192.168.2.230x4549Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:11.435720921 CEST65.21.1.106192.168.2.230xf7bbName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:17.470345974 CEST65.21.1.106192.168.2.230x616cName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:22.505105019 CEST81.169.136.222192.168.2.230x6857Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:38.555641890 CEST185.181.61.24192.168.2.230x18dcName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:47.592031956 CEST217.160.70.42192.168.2.230x684cName error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:47.652964115 CEST80.152.203.134192.168.2.230xa660Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false
                                            Oct 8, 2024 10:48:47.682116985 CEST217.160.70.42192.168.2.230x3b74Name error (3)akamaisus.dynnonenoneA (IP address)IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):08:46:50
                                            Start date (UTC):08/10/2024
                                            Path:/tmp/na.elf
                                            Arguments:/tmp/na.elf
                                            File size:4139976 bytes
                                            MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                            Start time (UTC):08:46:51
                                            Start date (UTC):08/10/2024
                                            Path:/tmp/na.elf
                                            Arguments:-
                                            File size:4139976 bytes
                                            MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                            Start time (UTC):08:46:51
                                            Start date (UTC):08/10/2024
                                            Path:/tmp/na.elf
                                            Arguments:-
                                            File size:4139976 bytes
                                            MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                            Start time (UTC):08:46:51
                                            Start date (UTC):08/10/2024
                                            Path:/usr/lib/udisks2/udisksd
                                            Arguments:-
                                            File size:483056 bytes
                                            MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                            Start time (UTC):08:46:51
                                            Start date (UTC):08/10/2024
                                            Path:/usr/sbin/dumpe2fs
                                            Arguments:dumpe2fs -h /dev/dm-0
                                            File size:31112 bytes
                                            MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4