Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Trhc0oj3L5.elf

Overview

General Information

Sample name:Trhc0oj3L5.elf
renamed because original name is a hash value
Original sample name:ce22ca3990271926f6c74c1402d45a17.elf
Analysis ID:1427655
MD5:ce22ca3990271926f6c74c1402d45a17
SHA1:c673a79ded420df2738001bdd9957d562dfc6bf6
SHA256:b5c23c8c3ff16addf37d54d3fab67ab3e1f06bb3987ff5a49b27e7a631f1de58
Tags:32elfmiraisparc
Infos:

Detection

Mirai
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Performs DNS queries to domains with low reputation
Sample deletes itself
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1427655
Start date and time:2024-04-17 23:13:21 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 56s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Trhc0oj3L5.elf
renamed because original name is a hash value
Original Sample Name:ce22ca3990271926f6c74c1402d45a17.elf
Detection:MAL
Classification:mal80.troj.evad.linELF@0/1@30/0
  • VT rate limit hit for: Trhc0oj3L5.elf
Command:/tmp/Trhc0oj3L5.elf
PID:5691
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
about to cum inside a femboy btw
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 5698, Parent: 1498, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
  • gsd-rfkill (PID: 5698, Parent: 1498, MD5: 88a16a3c0aba1759358c06215ecfb5cc) Arguments: /usr/libexec/gsd-rfkill
  • systemd New Fork (PID: 5703, Parent: 1)
  • systemd-hostnamed (PID: 5703, Parent: 1, MD5: 2cc8a5576629a2d5bd98e49a4b8bef65) Arguments: /lib/systemd/systemd-hostnamed
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
Trhc0oj3L5.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    Trhc0oj3L5.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x12b18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12b2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12b40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12b54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12b68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12b7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12b90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12ba4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12bb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12bcc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12be0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12bf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12c94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x12ca8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    SourceRuleDescriptionAuthorStrings
    5691.1.00007f7498011000.00007f7498027000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5691.1.00007f7498011000.00007f7498027000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x12b18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12b2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12b40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12b54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12b68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12b7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12b90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12ba4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12bb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12bcc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12be0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12bf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12c94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x12ca8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      Process Memory Space: Trhc0oj3L5.elf PID: 5691Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x82f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x843:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x857:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x86b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x87f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x893:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8a7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8bb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8cf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8e3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x8f7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x90b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x91f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x933:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x947:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x95b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x96f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x983:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x997:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x9ab:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x9bf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: Trhc0oj3L5.elfAvira: detected
      Source: Trhc0oj3L5.elfReversingLabs: Detection: 39%
      Source: Trhc0oj3L5.elfString: 8(EOF/proc//proc/%s/cmdlinewgetcurlftpechokillbashrebootshutdownhaltpoweroff[locker] killed process: %s ;; pid: %d

      Networking

      barindex
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: DNS query: kovey.mezo-api.xyz
      Source: global trafficTCP traffic: 192.168.2.15:39696 -> 45.131.111.219:33966
      Source: global trafficTCP traffic: 192.168.2.15:37436 -> 89.190.156.145:7733
      Source: unknownTCP traffic detected without corresponding DNS query: 89.190.156.145
      Source: unknownTCP traffic detected without corresponding DNS query: 89.190.156.145
      Source: unknownTCP traffic detected without corresponding DNS query: 89.190.156.145
      Source: unknownTCP traffic detected without corresponding DNS query: 89.190.156.145
      Source: unknownTCP traffic detected without corresponding DNS query: 89.190.156.145
      Source: unknownTCP traffic detected without corresponding DNS query: 89.190.156.145
      Source: unknownTCP traffic detected without corresponding DNS query: 89.190.156.145
      Source: unknownDNS traffic detected: queries for: kovey.mezo-api.xyz

      System Summary

      barindex
      Source: Trhc0oj3L5.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: 5691.1.00007f7498011000.00007f7498027000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: Process Memory Space: Trhc0oj3L5.elf PID: 5691, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)SIGKILL sent: pid: 1679, result: successfulJump to behavior
      Source: Trhc0oj3L5.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: 5691.1.00007f7498011000.00007f7498027000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: Process Memory Space: Trhc0oj3L5.elf PID: 5691, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
      Source: classification engineClassification label: mal80.troj.evad.linELF@0/1@30/0
      Source: /usr/libexec/gsd-rfkill (PID: 5698)Directory: <invalid fd (9)>/..Jump to behavior
      Source: /usr/libexec/gsd-rfkill (PID: 5698)Directory: <invalid fd (8)>/..Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 5703)Directory: <invalid fd (10)>/..Jump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/110/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/231/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/111/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/112/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/233/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/113/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/114/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/235/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/115/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1333/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/116/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/117/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/118/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/119/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/911/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/914/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/10/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/917/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/11/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/12/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/13/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/14/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/15/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/16/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/17/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/18/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/19/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1591/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/120/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/121/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/122/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/243/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/2/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/123/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/3/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/124/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1588/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/125/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/4/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/246/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/126/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/5/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/127/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/6/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1585/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/128/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/7/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/129/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/8/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/800/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/9/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/802/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/803/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/804/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/20/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/21/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/22/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/23/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/24/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/25/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/26/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/27/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/28/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/29/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1484/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/490/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/250/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/130/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/251/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/131/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/132/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/133/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1479/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/378/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/258/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/259/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/931/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1595/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/812/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/933/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/30/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/35/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/260/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/261/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/262/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/142/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/263/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/264/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/265/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/145/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/266/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/267/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/268/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/269/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/1486/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/270/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/271/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/272/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/273/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/274/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/275/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/276/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/277/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/278/cmdlineJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5696)File opened: /proc/279/cmdlineJump to behavior

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: /tmp/Trhc0oj3L5.elf (PID: 5694)File: /tmp/Trhc0oj3L5.elfJump to behavior
      Source: /tmp/Trhc0oj3L5.elf (PID: 5691)Queries kernel information via 'uname': Jump to behavior
      Source: /lib/systemd/systemd-hostnamed (PID: 5703)Queries kernel information via 'uname': Jump to behavior
      Source: Trhc0oj3L5.elf, 5691.1.000055a9bd0c6000.000055a9bd14c000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
      Source: Trhc0oj3L5.elf, 5691.1.00007ffe8cf7c000.00007ffe8cf9d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/Trhc0oj3L5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Trhc0oj3L5.elf
      Source: Trhc0oj3L5.elf, 5691.1.000055a9bd0c6000.000055a9bd14c000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
      Source: Trhc0oj3L5.elf, 5691.1.00007ffe8cf7c000.00007ffe8cf9d000.rw-.sdmpBinary or memory string: /qemu-open.XXXXX
      Source: Trhc0oj3L5.elf, 5691.1.00007ffe8cf7c000.00007ffe8cf9d000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.QrfOZw\TV
      Source: Trhc0oj3L5.elf, 5691.1.00007ffe8cf7c000.00007ffe8cf9d000.rw-.sdmpBinary or memory string: /tmp/qemu-open.QrfOZw
      Source: Trhc0oj3L5.elf, 5691.1.00007ffe8cf7c000.00007ffe8cf9d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: Trhc0oj3L5.elf, type: SAMPLE
      Source: Yara matchFile source: 5691.1.00007f7498011000.00007f7498027000.r-x.sdmp, type: MEMORY

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: Trhc0oj3L5.elf, type: SAMPLE
      Source: Yara matchFile source: 5691.1.00007f7498011000.00007f7498027000.r-x.sdmp, type: MEMORY
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Scripting
      Path Interception1
      Hidden Files and Directories
      1
      OS Credential Dumping
      11
      Security Software Discovery
      Remote ServicesData from Local System1
      Non-Standard Port
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
      File Deletion
      LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      SourceDetectionScannerLabelLink
      Trhc0oj3L5.elf39%ReversingLabsLinux.Trojan.Mirai
      Trhc0oj3L5.elf100%AviraEXP/ELF.Mirai.Z.A
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      kovey.mezo-api.xyz
      45.131.111.219
      truetrue
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        45.131.111.219
        kovey.mezo-api.xyzGermany
        398373SERVERDESTROYERSUStrue
        89.190.156.145
        unknownUnited Kingdom
        7489HOSTUS-GLOBAL-ASHostUSHKfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        45.131.111.219sMmzRMu1P6.elfGet hashmaliciousMiraiBrowse
          NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
            AkV7DALWTe.elfGet hashmaliciousMiraiBrowse
              6pZSqZEAa2.elfGet hashmaliciousMiraiBrowse
                FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                  LPXP6wFUyX.elfGet hashmaliciousMiraiBrowse
                    dvxuxG34sk.elfGet hashmaliciousMiraiBrowse
                      aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                        KxTpfpJzPK.elfGet hashmaliciousMiraiBrowse
                          MhV593RNl7.elfGet hashmaliciousMiraiBrowse
                            89.190.156.145sMmzRMu1P6.elfGet hashmaliciousMiraiBrowse
                              aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                LiZXGg7fyH.elfGet hashmaliciousUnknownBrowse
                                  hW73Zv5QP8.elfGet hashmaliciousUnknownBrowse
                                    kb66uL4J4v.elfGet hashmaliciousUnknownBrowse
                                      8g1ZsLnPkT.elfGet hashmaliciousUnknownBrowse
                                        3kpdYyPMQ1.elfGet hashmaliciousMiraiBrowse
                                          4kubb9wtoo.elfGet hashmaliciousUnknownBrowse
                                            YpYCMrKWmt.elfGet hashmaliciousUnknownBrowse
                                              rC1NOq2tlX.elfGet hashmaliciousUnknownBrowse
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                kovey.mezo-api.xyzNvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                dvxuxG34sk.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                MhV593RNl7.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                HOSTUS-GLOBAL-ASHostUSHKsMmzRMu1P6.elfGet hashmaliciousMiraiBrowse
                                                • 89.190.156.145
                                                aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                                • 89.190.156.145
                                                XoJZcyGnfc.elfGet hashmaliciousGafgytBrowse
                                                • 89.190.156.227
                                                5Nfro46k6z.elfGet hashmaliciousGafgytBrowse
                                                • 89.190.156.227
                                                rWIq0N7gR0.elfGet hashmaliciousGafgytBrowse
                                                • 89.190.156.227
                                                xu4uPf2rLF.elfGet hashmaliciousGafgytBrowse
                                                • 89.190.156.227
                                                DYQCCl3BLP.elfGet hashmaliciousGafgytBrowse
                                                • 89.190.156.227
                                                x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 89.190.156.211
                                                LiZXGg7fyH.elfGet hashmaliciousUnknownBrowse
                                                • 89.190.156.145
                                                hW73Zv5QP8.elfGet hashmaliciousUnknownBrowse
                                                • 89.190.156.145
                                                SERVERDESTROYERSUSsMmzRMu1P6.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                NvmCe2XrqN.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                AkV7DALWTe.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                6pZSqZEAa2.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                FwLad7Fxwv.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                LPXP6wFUyX.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                dvxuxG34sk.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                aNeRrtorRm.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                KxTpfpJzPK.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                MhV593RNl7.elfGet hashmaliciousMiraiBrowse
                                                • 45.131.111.219
                                                No context
                                                No context
                                                Process:/tmp/Trhc0oj3L5.elf
                                                File Type:data
                                                Category:dropped
                                                Size (bytes):30
                                                Entropy (8bit):4.415061012203069
                                                Encrypted:false
                                                SSDEEP:3:TgrGgmVR8HJN:TgSgmyJN
                                                MD5:FE859F25052B2CC30DBE35F9F32B4D4E
                                                SHA1:F444CDA0F623BE8B04A6BE8983DD493E16EE21E9
                                                SHA-256:4DB35309294239387BA134BEE218BEF047D9B488D24AFD2D8EE4C686A5515CBB
                                                SHA-512:5568E96D1DB6F2C511AA8986937F9570D99C02CD9C5A0B21BD3C53B5DC26B2C314DA611D4AB7602933F2B5385EC372BD3CB48ACE5E6ADFC6156E427020E43635
                                                Malicious:false
                                                Reputation:low
                                                Preview:/tmp/Trhc0oj3L5.elf.nwlrbbmqbh
                                                File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                                                Entropy (8bit):6.011219863203505
                                                TrID:
                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                File name:Trhc0oj3L5.elf
                                                File size:91'716 bytes
                                                MD5:ce22ca3990271926f6c74c1402d45a17
                                                SHA1:c673a79ded420df2738001bdd9957d562dfc6bf6
                                                SHA256:b5c23c8c3ff16addf37d54d3fab67ab3e1f06bb3987ff5a49b27e7a631f1de58
                                                SHA512:efeda7f4d7864674e70c9802bc9b2db0bad0bb13f882972223296e95a59941886e61c03fd0040637fd0a0655bf6411cd0b4f8c776f3a4c409d490321f7845802
                                                SSDEEP:1536:vUaSo7kKDcfW5JtmKMLpQ7mpn/oj1UtczNk5Pc4REmZ6tO5ciMF:8zOo4dMNPn/izNU0IBGF
                                                TLSH:67934B32BA751E2BC4D1A47A21F74B25F1F247CA21A8CA1B3D710D5EAF646403643EF8
                                                File Content Preview:.ELF...........................4..d......4. ...(......................Z...Z...............`...`...`....H..&(........dt.Q................................@..(....@.JM................#.....`H..`.....!..... $..@.....".........`......$ $.. $..@...........`....

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, big endian
                                                Version:1 (current)
                                                Machine:Sparc
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x101a4
                                                Flags:0x0
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:3
                                                Section Header Offset:91276
                                                Section Header Size:40
                                                Number of Section Headers:11
                                                Header String Table Index:10
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .initPROGBITS0x100940x940x1c0x00x6AX004
                                                .textPROGBITS0x100b00xb00x1296c0x00x6AX004
                                                .finiPROGBITS0x22a1c0x12a1c0x140x00x6AX004
                                                .rodataPROGBITS0x22a300x12a300x2fe80x00x2A008
                                                .ctorsPROGBITS0x360000x160000x80x00x3WA004
                                                .dtorsPROGBITS0x360080x160080x80x00x3WA004
                                                .gotPROGBITS0x360140x160140x80x40x3WA004
                                                .dataPROGBITS0x360200x160200x4280x00x3WA008
                                                .bssNOBITS0x364480x164480x21e00x00x3WA008
                                                .shstrtabSTRTAB0x00x164480x430x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x100000x100000x15a180x15a186.09850x5R E0x10000.init .text .fini .rodata
                                                LOAD0x160000x360000x360000x4480x26283.51070x6RW 0x10000.ctors .dtors .got .data .bss
                                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                TimestampSource PortDest PortSource IPDest IP
                                                Apr 17, 2024 23:14:24.716537952 CEST3969633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:24.923149109 CEST339663969645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:24.923212051 CEST3969633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:24.961261034 CEST374367733192.168.2.1589.190.156.145
                                                Apr 17, 2024 23:14:25.736131907 CEST3969633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:25.944791079 CEST339663969645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:25.944868088 CEST3969633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:25.945676088 CEST3969633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:25.991322994 CEST374367733192.168.2.1589.190.156.145
                                                Apr 17, 2024 23:14:26.153714895 CEST339663969645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:26.153816938 CEST3969633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:26.362166882 CEST339663969645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:28.007314920 CEST374367733192.168.2.1589.190.156.145
                                                Apr 17, 2024 23:14:28.926042080 CEST339663969645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:28.926803112 CEST3969633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:29.133529902 CEST339663969645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:29.140865088 CEST3970033966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:29.349102020 CEST339663970045.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:29.559341908 CEST3970233966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:29.767836094 CEST339663970245.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:29.978480101 CEST3970433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:30.185899019 CEST339663970445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:30.403569937 CEST3970633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:30.613935947 CEST339663970645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:30.824897051 CEST3970833966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:31.028786898 CEST339663970845.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:31.242536068 CEST3971033966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:31.449836016 CEST339663971045.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:31.660970926 CEST3971233966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:31.868175983 CEST339663971245.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:32.079174042 CEST3971433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:32.199146986 CEST374367733192.168.2.1589.190.156.145
                                                Apr 17, 2024 23:14:32.287151098 CEST339663971445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:32.497613907 CEST3971633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:32.707233906 CEST339663971645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:32.918101072 CEST3971833966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:33.120754957 CEST339663971845.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:33.333498001 CEST3972033966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:33.540920019 CEST339663972045.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:33.751514912 CEST3972233966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:33.959681988 CEST339663972245.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:34.169903040 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:34.378123999 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:34.378308058 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:34.378372908 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:34.590629101 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:34.590904951 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:34.800080061 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:40.390821934 CEST374367733192.168.2.1589.190.156.145
                                                Apr 17, 2024 23:14:49.802211046 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:14:49.802336931 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:14:56.518299103 CEST374367733192.168.2.1589.190.156.145
                                                Apr 17, 2024 23:15:05.057818890 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:05.057964087 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:15:20.269805908 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:20.269932985 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:15:29.540947914 CEST374367733192.168.2.1589.190.156.145
                                                Apr 17, 2024 23:15:34.508590937 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:34.508829117 CEST3972433966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:15:34.716717005 CEST339663972445.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:34.719255924 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:15:34.925867081 CEST339663972645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:34.926058054 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:15:34.926139116 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:15:35.133059025 CEST339663972645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:35.133358002 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:15:35.340090036 CEST339663972645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:50.367559910 CEST339663972645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:15:50.367717028 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:16:05.576569080 CEST339663972645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:16:05.576693058 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:16:14.961613894 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:16:15.170581102 CEST339663972645.131.111.219192.168.2.15
                                                Apr 17, 2024 23:16:24.971400976 CEST3972633966192.168.2.1545.131.111.219
                                                Apr 17, 2024 23:16:25.178410053 CEST339663972645.131.111.219192.168.2.15
                                                TimestampSource PortDest PortSource IPDest IP
                                                Apr 17, 2024 23:14:24.505902052 CEST3958153192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:24.610506058 CEST53395818.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:24.611186028 CEST4833053192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:24.716355085 CEST53483308.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:28.927072048 CEST4482653192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:29.032016993 CEST53448268.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:29.032244921 CEST5458853192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:29.140522957 CEST53545888.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:29.349426985 CEST4209653192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:29.454112053 CEST53420968.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:29.454268932 CEST5146153192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:29.559133053 CEST53514618.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:29.768023968 CEST3804853192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:29.873039961 CEST53380488.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:29.873341084 CEST3997653192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:29.978070021 CEST53399768.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:30.186280966 CEST4526753192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:30.298454046 CEST53452678.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:30.298682928 CEST4330253192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:30.403305054 CEST53433028.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:30.614249945 CEST5994953192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:30.719546080 CEST53599498.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:30.719765902 CEST5667953192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:30.824749947 CEST53566798.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:31.029244900 CEST4513453192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:31.136838913 CEST53451348.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:31.137077093 CEST3807053192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:31.242362976 CEST53380708.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:31.450129032 CEST5896653192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:31.555418968 CEST53589668.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:31.555613995 CEST4953053192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:31.660624027 CEST53495308.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:31.868429899 CEST5529453192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:31.973391056 CEST53552948.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:31.973712921 CEST5210753192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:32.078886986 CEST53521078.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:32.287400961 CEST5137753192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:32.392252922 CEST53513778.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:32.392426968 CEST4091353192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:32.497381926 CEST53409138.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:32.707885027 CEST5397953192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:32.812611103 CEST53539798.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:32.812999010 CEST5883153192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:32.917902946 CEST53588318.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:33.121052980 CEST4116053192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:33.226622105 CEST53411608.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:33.226972103 CEST5430753192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:33.332990885 CEST53543078.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:33.541217089 CEST4388553192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:33.645978928 CEST53438858.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:33.646282911 CEST5134053192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:33.751271963 CEST53513408.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:33.960062027 CEST4710353192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:34.064798117 CEST53471038.8.8.8192.168.2.15
                                                Apr 17, 2024 23:14:34.065104008 CEST5150453192.168.2.158.8.8.8
                                                Apr 17, 2024 23:14:34.169586897 CEST53515048.8.8.8192.168.2.15
                                                Apr 17, 2024 23:15:34.508908987 CEST4070053192.168.2.158.8.8.8
                                                Apr 17, 2024 23:15:34.613991976 CEST53407008.8.8.8192.168.2.15
                                                Apr 17, 2024 23:15:34.614191055 CEST4338753192.168.2.158.8.8.8
                                                Apr 17, 2024 23:15:34.719078064 CEST53433878.8.8.8192.168.2.15
                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                Apr 17, 2024 23:14:24.505902052 CEST192.168.2.158.8.8.80x5aa2Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:24.611186028 CEST192.168.2.158.8.8.80xeff1Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:28.927072048 CEST192.168.2.158.8.8.80x11aeStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.032244921 CEST192.168.2.158.8.8.80x6af6Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.349426985 CEST192.168.2.158.8.8.80x1964Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.454268932 CEST192.168.2.158.8.8.80x47dfStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.768023968 CEST192.168.2.158.8.8.80x39fbStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.873341084 CEST192.168.2.158.8.8.80x90f7Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.186280966 CEST192.168.2.158.8.8.80xe7d9Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.298682928 CEST192.168.2.158.8.8.80x6141Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.614249945 CEST192.168.2.158.8.8.80xbf03Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.719765902 CEST192.168.2.158.8.8.80x44eaStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.029244900 CEST192.168.2.158.8.8.80x5eb2Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.137077093 CEST192.168.2.158.8.8.80xb25fStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.450129032 CEST192.168.2.158.8.8.80x9a2dStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.555613995 CEST192.168.2.158.8.8.80xc653Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.868429899 CEST192.168.2.158.8.8.80x2ea9Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.973712921 CEST192.168.2.158.8.8.80xbb47Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.287400961 CEST192.168.2.158.8.8.80xe39aStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.392426968 CEST192.168.2.158.8.8.80xcd71Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.707885027 CEST192.168.2.158.8.8.80xd1beStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.812999010 CEST192.168.2.158.8.8.80xbed3Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.121052980 CEST192.168.2.158.8.8.80xd2e2Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.226972103 CEST192.168.2.158.8.8.80x3cfaStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.541217089 CEST192.168.2.158.8.8.80x5b45Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.646282911 CEST192.168.2.158.8.8.80x98feStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.960062027 CEST192.168.2.158.8.8.80x64bbStandard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:34.065104008 CEST192.168.2.158.8.8.80x2f49Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:15:34.508908987 CEST192.168.2.158.8.8.80xfe4Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:15:34.614191055 CEST192.168.2.158.8.8.80xc5c0Standard query (0)kovey.mezo-api.xyzA (IP address)IN (0x0001)false
                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                Apr 17, 2024 23:14:24.610506058 CEST8.8.8.8192.168.2.150x5aa2No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:24.716355085 CEST8.8.8.8192.168.2.150xeff1No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.032016993 CEST8.8.8.8192.168.2.150x11aeNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.140522957 CEST8.8.8.8192.168.2.150x6af6No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.454112053 CEST8.8.8.8192.168.2.150x1964No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.559133053 CEST8.8.8.8192.168.2.150x47dfNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.873039961 CEST8.8.8.8192.168.2.150x39fbNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:29.978070021 CEST8.8.8.8192.168.2.150x90f7No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.298454046 CEST8.8.8.8192.168.2.150xe7d9No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.403305054 CEST8.8.8.8192.168.2.150x6141No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.719546080 CEST8.8.8.8192.168.2.150xbf03No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:30.824749947 CEST8.8.8.8192.168.2.150x44eaNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.136838913 CEST8.8.8.8192.168.2.150x5eb2No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.242362976 CEST8.8.8.8192.168.2.150xb25fNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.555418968 CEST8.8.8.8192.168.2.150x9a2dNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.660624027 CEST8.8.8.8192.168.2.150xc653No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:31.973391056 CEST8.8.8.8192.168.2.150x2ea9No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.078886986 CEST8.8.8.8192.168.2.150xbb47No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.392252922 CEST8.8.8.8192.168.2.150xe39aNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.497381926 CEST8.8.8.8192.168.2.150xcd71No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.812611103 CEST8.8.8.8192.168.2.150xd1beNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:32.917902946 CEST8.8.8.8192.168.2.150xbed3No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.226622105 CEST8.8.8.8192.168.2.150xd2e2No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.332990885 CEST8.8.8.8192.168.2.150x3cfaNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.645978928 CEST8.8.8.8192.168.2.150x5b45No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:33.751271963 CEST8.8.8.8192.168.2.150x98feNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:34.064798117 CEST8.8.8.8192.168.2.150x64bbNo error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:14:34.169586897 CEST8.8.8.8192.168.2.150x2f49No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:15:34.613991976 CEST8.8.8.8192.168.2.150xfe4No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false
                                                Apr 17, 2024 23:15:34.719078064 CEST8.8.8.8192.168.2.150xc5c0No error (0)kovey.mezo-api.xyz45.131.111.219A (IP address)IN (0x0001)false

                                                System Behavior

                                                Start time (UTC):21:14:23
                                                Start date (UTC):17/04/2024
                                                Path:/tmp/Trhc0oj3L5.elf
                                                Arguments:/tmp/Trhc0oj3L5.elf
                                                File size:4379400 bytes
                                                MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                Start time (UTC):21:14:23
                                                Start date (UTC):17/04/2024
                                                Path:/tmp/Trhc0oj3L5.elf
                                                Arguments:-
                                                File size:4379400 bytes
                                                MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                Start time (UTC):21:14:23
                                                Start date (UTC):17/04/2024
                                                Path:/tmp/Trhc0oj3L5.elf
                                                Arguments:-
                                                File size:4379400 bytes
                                                MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                Start time (UTC):21:14:24
                                                Start date (UTC):17/04/2024
                                                Path:/usr/libexec/gnome-session-binary
                                                Arguments:-
                                                File size:334664 bytes
                                                MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                Start time (UTC):21:14:24
                                                Start date (UTC):17/04/2024
                                                Path:/bin/sh
                                                Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-rfkill
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):21:14:24
                                                Start date (UTC):17/04/2024
                                                Path:/usr/libexec/gsd-rfkill
                                                Arguments:/usr/libexec/gsd-rfkill
                                                File size:51808 bytes
                                                MD5 hash:88a16a3c0aba1759358c06215ecfb5cc

                                                Start time (UTC):21:14:24
                                                Start date (UTC):17/04/2024
                                                Path:/usr/lib/systemd/systemd
                                                Arguments:-
                                                File size:1620224 bytes
                                                MD5 hash:9b2bec7092a40488108543f9334aab75

                                                Start time (UTC):21:14:24
                                                Start date (UTC):17/04/2024
                                                Path:/lib/systemd/systemd-hostnamed
                                                Arguments:/lib/systemd/systemd-hostnamed
                                                File size:35040 bytes
                                                MD5 hash:2cc8a5576629a2d5bd98e49a4b8bef65