Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf

Overview

General Information

Sample name:SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
Analysis ID:1431613
MD5:f117efee9e82c956ec950aa7d4a3fa32
SHA1:30e845fc5486cf50cbfe784d840076a9815a70b5
SHA256:85440e7e88ed123e20f7347b6923d501aa2b81c6147185a927005b239ae7b526
Tags:elf
Infos:

Detection

Mirai
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1431613
Start date and time:2024-04-25 14:35:05 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 58s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@113/0
Command:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
PID:6217
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmpJoeSecurity_Mirai_5Yara detected MiraiJoe Security
      6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
      • 0x106a4:$x1: POST /cdn-cgi/
      • 0x10a28:$s1: LCOGQGPTGP
      6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmpMAL_ELF_LNX_Mirai_Oct10_2Detects ELF malware Mirai relatedFlorian Roth
      • 0x106a4:$c01: 50 4F 53 54 20 2F 63 64 6E 2D 63 67 69 2F 00 00 20 48 54 54 50 2F 31 2E 31 0D 0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 00 0D 0A 48 6F 73 74 3A
      6226.1.00007f9f90017000.00007f9f90029000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        Click to see the 15 entries
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elfAvira: detected
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elfVirustotal: Detection: 60%Perma Link
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elfReversingLabs: Detection: 67%
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6217)Socket: 127.0.0.1::29103Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::23Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::0Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::80Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::81Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::8443Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::9009Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::1337Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::13883Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::19481Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::4444Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)Socket: 0.0.0.0::9789Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::0Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::80Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::81Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::8443Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::9009Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::1337Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::13883Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::19481Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::4444Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)Socket: 0.0.0.0::9789Jump to behavior
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: global trafficDNS traffic detected: DNS query: www.sushiking.world
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elfString found in binary or memory: http://upx.sf.net
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

        System Summary

        barindex
        Source: 6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: 6226.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 6226.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: 6219.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 6219.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: 6220.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 6220.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: LOAD without section mappingsProgram segment: 0x8000
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6219)SIGKILL sent: pid: 936, result: successfulJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)SIGKILL sent: pid: 936, result: successfulJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)SIGKILL sent: pid: 6219, result: successfulJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)SIGKILL sent: pid: 759, result: successfulJump to behavior
        Source: 6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: 6226.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 6226.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: 6219.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 6219.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: 6220.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 6220.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@113/0

        Data Obfuscation

        barindex
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2033/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2033/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1582/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1582/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2275/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1612/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1612/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1579/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1579/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1699/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1699/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1335/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1335/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1698/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1698/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2028/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2028/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1334/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1334/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1576/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1576/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2302/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/3236/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2025/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2025/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2146/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/910/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/912/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/912/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/912/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/759/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/759/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/759/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/517/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2307/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/918/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/918/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/918/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1594/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1594/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2285/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2281/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1349/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1349/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1623/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1623/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/761/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/761/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/761/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1622/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1622/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/884/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/884/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/884/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1983/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1983/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2038/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2038/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1586/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1586/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1465/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1465/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1344/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1344/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1860/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1860/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1463/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1463/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2156/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/800/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/800/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/800/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/801/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/801/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/801/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1629/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1629/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1627/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1627/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1900/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1900/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/491/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/491/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/491/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2294/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2050/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/2050/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1877/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1877/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/772/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/772/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/772/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1633/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1633/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1599/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1599/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1632/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1632/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1477/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/1477/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/774/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/774/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6225)File opened: /proc/774/exeJump to behavior
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elfSubmission file: segment LOAD with 7.9449 entropy (max. 8.0)
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf (PID: 6217)Queries kernel information via 'uname': Jump to behavior
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6217.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6219.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6220.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6226.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6217.1.000056175aff8000.000056175b126000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6219.1.000056175aff8000.000056175b126000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6220.1.000056175aff8000.000056175b126000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6226.1.000056175aff8000.000056175b126000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6217.1.000056175aff8000.000056175b126000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6219.1.000056175aff8000.000056175b126000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6220.1.000056175aff8000.000056175b126000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6226.1.000056175aff8000.000056175b126000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
        Source: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6217.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6219.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6220.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf, 6226.1.00007ffead5cc000.00007ffead5ed000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6226.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6219.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6220.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6217, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6219, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6220, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6226, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 6217.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6226.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6219.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6220.1.00007f9f90017000.00007f9f90029000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6217, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6219, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6220, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf PID: 6226, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
        Obfuscated Files or Information
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        SourceDetectionScannerLabelLink
        SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf60%VirustotalBrowse
        SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf68%ReversingLabsLinux.Trojan.Mirai
        SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf100%AviraANDROID/Mirai.xorzm
        No Antivirus matches
        SourceDetectionScannerLabelLink
        www.sushiking.world8%VirustotalBrowse
        No Antivirus matches
        NameIPActiveMaliciousAntivirus DetectionReputation
        www.sushiking.world
        unknown
        unknownfalseunknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://upx.sf.netSecuriteInfo.com.Linux.Siggen.9999.12445.30549.elffalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          79.110.48.149
          unknownGermany
          57287OTAVANET-ASCZfalse
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          91.189.91.43
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          79.110.48.149TGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
            109.202.202.202g1wkNJ0Ncz.elfGet hashmaliciousMirai, OkiruBrowse
              vlxx.x86.elfGet hashmaliciousMirai, OkiruBrowse
                vlxx.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                  bJC4H147mB.elfGet hashmaliciousUnknownBrowse
                    XM3JcqhdgB.elfGet hashmaliciousUnknownBrowse
                      VUjiythPAQ.elfGet hashmaliciousUnknownBrowse
                        TGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
                          qnW5l5IegwGet hashmaliciousXmrigBrowse
                            SecuriteInfo.com.Linux.Siggen.9999.28857.26683.elfGet hashmaliciousMiraiBrowse
                              SecuriteInfo.com.Other.Malware-gen.3200.4135.elfGet hashmaliciousMiraiBrowse
                                91.189.91.43g1wkNJ0Ncz.elfGet hashmaliciousMirai, OkiruBrowse
                                  vlxx.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                    vlxx.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                      XM3JcqhdgB.elfGet hashmaliciousUnknownBrowse
                                        VUjiythPAQ.elfGet hashmaliciousUnknownBrowse
                                          TGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
                                            qnW5l5IegwGet hashmaliciousXmrigBrowse
                                              SecuriteInfo.com.Linux.Siggen.9999.28857.26683.elfGet hashmaliciousMiraiBrowse
                                                SecuriteInfo.com.Other.Malware-gen.3200.4135.elfGet hashmaliciousMiraiBrowse
                                                  SecuriteInfo.com.Linux.Siggen.6954.6684.13146.elfGet hashmaliciousMiraiBrowse
                                                    91.189.91.42g1wkNJ0Ncz.elfGet hashmaliciousMirai, OkiruBrowse
                                                      vlxx.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                        vlxx.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                          bJC4H147mB.elfGet hashmaliciousUnknownBrowse
                                                            XM3JcqhdgB.elfGet hashmaliciousUnknownBrowse
                                                              VUjiythPAQ.elfGet hashmaliciousUnknownBrowse
                                                                TGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
                                                                  qnW5l5IegwGet hashmaliciousXmrigBrowse
                                                                    SecuriteInfo.com.Linux.Siggen.9999.28857.26683.elfGet hashmaliciousMiraiBrowse
                                                                      SecuriteInfo.com.Other.Malware-gen.3200.4135.elfGet hashmaliciousMiraiBrowse
                                                                        No context
                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                        OTAVANET-ASCZTGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
                                                                        • 79.110.48.149
                                                                        skid.arm7.elfGet hashmaliciousMiraiBrowse
                                                                        • 79.110.49.174
                                                                        HROFrIvvVk.elfGet hashmaliciousMiraiBrowse
                                                                        • 79.110.49.195
                                                                        https://79.110.48.52/nicko.vbsGet hashmaliciousUnknownBrowse
                                                                        • 79.110.48.52
                                                                        PO_1100620230526.pdf(39kb).exeGet hashmaliciousRemcos, RedLine, XpertRATBrowse
                                                                        • 79.110.48.151
                                                                        https://prc-homes.uk/wp-images/26738903/content/Security_on_your_card_account.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                        • 79.110.48.18
                                                                        https://towntalkeg.com/wp-images/108373893032/Security_on_your_card_account.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                        • 79.110.48.18
                                                                        0xc2s.x86.elfGet hashmaliciousUnknownBrowse
                                                                        • 79.110.48.91
                                                                        oWlBd5huKm.elfGet hashmaliciousUnknownBrowse
                                                                        • 79.110.48.116
                                                                        JSJRrcfx4B.elfGet hashmaliciousUnknownBrowse
                                                                        • 79.110.48.116
                                                                        CANONICAL-ASGBg1wkNJ0Ncz.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        ldCdti5sRA.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 185.125.190.26
                                                                        vlxx.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        vlxx.x86_64.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 185.125.190.26
                                                                        vlxx.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        bJC4H147mB.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        XM3JcqhdgB.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        gCqnbN34QY.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        VUjiythPAQ.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        PylIt4izlJ.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        CANONICAL-ASGBg1wkNJ0Ncz.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        ldCdti5sRA.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 185.125.190.26
                                                                        vlxx.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        vlxx.x86_64.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 185.125.190.26
                                                                        vlxx.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        bJC4H147mB.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        XM3JcqhdgB.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        gCqnbN34QY.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        VUjiythPAQ.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        PylIt4izlJ.elfGet hashmaliciousUnknownBrowse
                                                                        • 185.125.190.26
                                                                        INIT7CHg1wkNJ0Ncz.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 109.202.202.202
                                                                        vlxx.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 109.202.202.202
                                                                        vlxx.mpsl.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 109.202.202.202
                                                                        bJC4H147mB.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        XM3JcqhdgB.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        VUjiythPAQ.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        TGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        qnW5l5IegwGet hashmaliciousXmrigBrowse
                                                                        • 109.202.202.202
                                                                        SecuriteInfo.com.Linux.Siggen.9999.28857.26683.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        SecuriteInfo.com.Other.Malware-gen.3200.4135.elfGet hashmaliciousMiraiBrowse
                                                                        • 109.202.202.202
                                                                        No context
                                                                        No context
                                                                        No created / dropped files found
                                                                        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
                                                                        Entropy (8bit):7.941257292192873
                                                                        TrID:
                                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                        File name:SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        File size:26'620 bytes
                                                                        MD5:f117efee9e82c956ec950aa7d4a3fa32
                                                                        SHA1:30e845fc5486cf50cbfe784d840076a9815a70b5
                                                                        SHA256:85440e7e88ed123e20f7347b6923d501aa2b81c6147185a927005b239ae7b526
                                                                        SHA512:d51989fb131e8b4287d268e58e5d279e15a4633f9322c88049279d5449a94767817a30e869f2dde1b29a59b8d706f0b9cf25cec41106a5a5544ae56a54c776ee
                                                                        SSDEEP:384:C7rcQHNG5qnQn7IjgoFVleXpWoR3CKyV145hw8ZpizQPPhymdGUop5hn:orcQlk7UgoNKWoAa5JiQPPs3Uozl
                                                                        TLSH:2DC2D0617AAD2EF2CBF00839FE7A44C333C159B8D0D9F6636859813C69D62066DDE542
                                                                        File Content Preview:.ELF...a..........(.....`...4...........4. ...(......................g...g..........................................Q.td............................s.y.UPX!....................R..........?.E.h;.}...^..........f.*......Q.$.AHQA@^...%........9_...y..'..g.~E

                                                                        ELF header

                                                                        Class:ELF32
                                                                        Data:2's complement, little endian
                                                                        Version:1 (current)
                                                                        Machine:ARM
                                                                        Version Number:0x1
                                                                        Type:EXEC (Executable file)
                                                                        OS/ABI:ARM - ABI
                                                                        ABI Version:0
                                                                        Entry Point Address:0xd560
                                                                        Flags:0x2
                                                                        ELF Header Size:52
                                                                        Program Header Offset:52
                                                                        Program Header Size:32
                                                                        Number of Program Headers:3
                                                                        Section Header Offset:0
                                                                        Section Header Size:40
                                                                        Number of Section Headers:0
                                                                        Header String Table Index:0
                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                        LOAD0x00x80000x80000x670f0x670f7.94490x5R E0x8000
                                                                        LOAD0x1adc0x21adc0x21adc0x00x00.00000x6RW 0x8000
                                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Apr 25, 2024 14:35:50.581615925 CEST4887680192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:35:50.876079082 CEST804887679.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:35:52.064095020 CEST43928443192.168.2.2391.189.91.42
                                                                        Apr 25, 2024 14:35:57.428019047 CEST4887880192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:35:57.439369917 CEST42836443192.168.2.2391.189.91.43
                                                                        Apr 25, 2024 14:35:57.750550032 CEST804887879.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:35:58.719235897 CEST4251680192.168.2.23109.202.202.202
                                                                        Apr 25, 2024 14:36:02.302853107 CEST4888080192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:02.623368979 CEST804888079.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:08.175637007 CEST4888280192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:08.470767975 CEST804888279.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:12.797342062 CEST43928443192.168.2.2391.189.91.42
                                                                        Apr 25, 2024 14:36:14.022171021 CEST4888480192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:14.321185112 CEST804888479.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:23.035945892 CEST42836443192.168.2.2391.189.91.43
                                                                        Apr 25, 2024 14:36:23.872318029 CEST4888680192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:24.167100906 CEST804888679.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:29.178925037 CEST4251680192.168.2.23109.202.202.202
                                                                        Apr 25, 2024 14:36:29.719827890 CEST4888880192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:30.014640093 CEST804888879.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:39.579319954 CEST4889080192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:39.875395060 CEST804889079.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:49.427670002 CEST4889280192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:49.751920938 CEST804889279.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:53.303884029 CEST4889480192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:36:53.596808910 CEST804889479.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:36:53.751518011 CEST43928443192.168.2.2391.189.91.42
                                                                        Apr 25, 2024 14:37:03.148961067 CEST4889680192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:03.444053888 CEST804889679.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:04.997112989 CEST4889880192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:05.295742035 CEST804889879.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:12.850564003 CEST4890080192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:13.169856071 CEST804890079.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:14.228636980 CEST42836443192.168.2.2391.189.91.43
                                                                        Apr 25, 2024 14:37:18.724064112 CEST4890280192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:19.047348022 CEST804890279.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:23.600157022 CEST4890480192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:23.895833015 CEST804890479.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:32.447602034 CEST4890680192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:32.746452093 CEST804890679.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:34.299386024 CEST4890880192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:34.593770027 CEST804890879.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:40.147305012 CEST4891080192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:40.439692020 CEST804891079.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:42.992296934 CEST4891280192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:43.313064098 CEST804891279.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:46.866069078 CEST4891480192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:47.163981915 CEST804891479.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:57.714306116 CEST4891680192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:58.008858919 CEST804891679.110.48.149192.168.2.23
                                                                        Apr 25, 2024 14:37:59.561834097 CEST4891880192.168.2.2379.110.48.149
                                                                        Apr 25, 2024 14:37:59.856386900 CEST804891879.110.48.149192.168.2.23
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Apr 25, 2024 14:35:50.029800892 CEST4789553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:50.139934063 CEST53478958.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:50.140319109 CEST3900553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:50.250314951 CEST53390058.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:50.250475883 CEST4692153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:50.360691071 CEST53469218.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:50.360860109 CEST4006953192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:50.470968008 CEST53400698.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:50.471100092 CEST5966553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:50.581119061 CEST53596658.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:56.876336098 CEST4351353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:56.986542940 CEST53435138.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:56.986859083 CEST4885953192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:57.096868992 CEST53488598.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:57.097084999 CEST4483153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:57.207196951 CEST53448318.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:57.207439899 CEST5574353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:57.317477942 CEST53557438.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:35:57.317744017 CEST4784453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:35:57.427810907 CEST53478448.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:01.750426054 CEST5236453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:01.860541105 CEST53523648.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:01.860865116 CEST3861553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:01.971131086 CEST53386158.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:01.971462965 CEST4426153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:02.081646919 CEST53442618.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:02.082000971 CEST3374653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:02.192224979 CEST53337468.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:02.192471981 CEST5291353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:02.302525997 CEST53529138.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:07.623281956 CEST5302453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:07.733460903 CEST53530248.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:07.733906031 CEST3944153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:07.844140053 CEST53394418.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:07.844388962 CEST5729453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:07.954448938 CEST53572948.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:07.954689026 CEST3453253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:08.064841032 CEST53345328.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:08.065288067 CEST5457253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:08.175261974 CEST53545728.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:13.470621109 CEST4564153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:13.580807924 CEST53456418.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:13.580955029 CEST3922853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:13.690932989 CEST53392288.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:13.691189051 CEST4676553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:13.801220894 CEST53467658.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:13.801589012 CEST5252653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:13.911470890 CEST53525268.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:13.911767006 CEST6032453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:14.021842957 CEST53603248.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:23.320401907 CEST3687153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:23.430723906 CEST53368718.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:23.431000948 CEST4789453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:23.541033030 CEST53478948.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:23.541444063 CEST5334253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:23.651331902 CEST53533428.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:23.651582003 CEST4322753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:23.761626005 CEST53432278.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:23.761878014 CEST5784753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:23.871936083 CEST53578478.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:29.166985989 CEST4224453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:29.277332067 CEST53422448.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:29.277672052 CEST5177653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:29.387856007 CEST53517768.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:29.388217926 CEST5300553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:29.498334885 CEST53530058.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:29.498569012 CEST4643653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:29.608783007 CEST53464368.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:29.609164953 CEST5555453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:29.719322920 CEST53555548.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:39.013951063 CEST5272353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:39.124265909 CEST53527238.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:39.124530077 CEST6064253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:39.241702080 CEST53606428.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:39.242007971 CEST5967253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:39.352181911 CEST53596728.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:39.352577925 CEST3964953192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:39.465344906 CEST53396498.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:39.465555906 CEST3498253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:39.579123974 CEST53349828.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:48.874870062 CEST5906853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:48.985481977 CEST53590688.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:48.985651970 CEST5418453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:49.095779896 CEST53541848.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:49.095948935 CEST4558053192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:49.206079960 CEST53455808.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:49.206393003 CEST4295853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:49.316584110 CEST53429588.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:49.317078114 CEST3467753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:49.427330971 CEST53346778.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:52.751997948 CEST5771853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:52.862090111 CEST53577188.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:52.862340927 CEST3297953192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:52.972428083 CEST53329798.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:52.972651005 CEST5997453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:53.082742929 CEST53599748.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:53.083133936 CEST5968453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:53.193279028 CEST53596848.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:36:53.193588972 CEST3890853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:36:53.303713083 CEST53389088.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:02.595879078 CEST5973353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:02.705939054 CEST53597338.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:02.706279993 CEST3763153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:02.816416025 CEST53376318.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:02.816859007 CEST3434553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:02.927129984 CEST53343458.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:02.927498102 CEST3307153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:03.037945032 CEST53330718.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:03.038263083 CEST5588253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:03.148700953 CEST53558828.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:04.444401026 CEST5548153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:04.554420948 CEST53554818.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:04.554721117 CEST5190653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:04.664988041 CEST53519068.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:04.665282965 CEST4066053192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:04.775449991 CEST53406608.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:04.775926113 CEST3462553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:04.886169910 CEST53346258.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:04.886570930 CEST4144753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:04.996771097 CEST53414478.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:12.295269966 CEST4253153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:12.405419111 CEST53425318.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:12.405787945 CEST4080453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:12.518126011 CEST53408048.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:12.518579960 CEST4775553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:12.628695011 CEST53477558.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:12.629153967 CEST3553753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:12.739725113 CEST53355378.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:12.740180016 CEST4801553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:12.850209951 CEST53480158.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:18.169766903 CEST3564853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:18.280375957 CEST53356488.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:18.280822992 CEST4091053192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:18.391762018 CEST53409108.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:18.392184973 CEST3520153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:18.502337933 CEST53352018.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:18.502739906 CEST5802353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:18.612987041 CEST53580238.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:18.613509893 CEST5305353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:18.723736048 CEST53530538.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:23.047219038 CEST3516353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:23.157778978 CEST53351638.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:23.157983065 CEST4193353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:23.268198967 CEST53419338.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:23.268551111 CEST4612353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:23.378741980 CEST53461238.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:23.379196882 CEST4330253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:23.489449978 CEST53433028.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:23.489798069 CEST4368553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:23.599912882 CEST53436858.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:31.895241976 CEST4647653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:32.005235910 CEST53464768.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:32.005624056 CEST3326753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:32.115766048 CEST53332678.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:32.116038084 CEST3598653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:32.226067066 CEST53359868.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:32.226418972 CEST4165853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:32.336692095 CEST53416588.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:32.337027073 CEST4309453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:32.447339058 CEST53430948.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:33.746685982 CEST3561453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:33.857031107 CEST53356148.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:33.857203960 CEST3520553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:33.967458010 CEST53352058.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:33.967727900 CEST5672853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:34.077831984 CEST53567288.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:34.078115940 CEST3723853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:34.188481092 CEST53372388.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:34.188812017 CEST5760253192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:34.298969030 CEST53576028.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:39.593517065 CEST5377553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:39.703664064 CEST53537758.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:39.704370022 CEST4933553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:39.814502001 CEST53493358.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:39.814930916 CEST3307653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:39.925401926 CEST53330768.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:39.925585985 CEST5237653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:40.035562038 CEST53523768.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:40.036022902 CEST5426553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:40.146887064 CEST53542658.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:42.439851046 CEST5926653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:42.550148010 CEST53592668.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:42.550574064 CEST4560553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:42.660603046 CEST53456058.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:42.660865068 CEST3368453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:42.771040916 CEST53336848.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:42.771255016 CEST3947453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:42.881530046 CEST53394748.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:42.881810904 CEST3302753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:42.992031097 CEST53330278.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:46.313194990 CEST4631053192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:46.423449993 CEST53463108.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:46.423774958 CEST4650753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:46.533792019 CEST53465078.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:46.534116983 CEST4841753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:46.644293070 CEST53484178.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:46.644678116 CEST5225553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:46.754909039 CEST53522558.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:46.755311966 CEST3707653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:46.865783930 CEST53370768.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:57.162923098 CEST4729753192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:57.273216009 CEST53472978.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:57.273364067 CEST5322853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:57.383452892 CEST53532288.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:57.383625031 CEST4452853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:57.493685961 CEST53445288.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:57.493838072 CEST5355853192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:57.603848934 CEST53535588.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:57.603979111 CEST3525953192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:57.714163065 CEST53352598.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:59.009258032 CEST5326153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:59.119596958 CEST53532618.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:59.119849920 CEST5932553192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:59.230546951 CEST53593258.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:59.230782032 CEST4684653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:59.341023922 CEST53468468.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:59.341281891 CEST4149653192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:59.451292038 CEST53414968.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:37:59.451558113 CEST3582453192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:37:59.561609030 CEST53358248.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:38:00.856729031 CEST3472353192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:38:00.966756105 CEST53347238.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:38:00.967185020 CEST6090153192.168.2.238.8.8.8
                                                                        Apr 25, 2024 14:38:01.077539921 CEST53609018.8.8.8192.168.2.23
                                                                        Apr 25, 2024 14:38:01.077897072 CEST5888853192.168.2.238.8.8.8
                                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                        Apr 25, 2024 14:35:50.029800892 CEST192.168.2.238.8.8.80x25e3Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:50.140319109 CEST192.168.2.238.8.8.80x25e3Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:50.250475883 CEST192.168.2.238.8.8.80x25e3Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:50.360860109 CEST192.168.2.238.8.8.80x25e3Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:50.471100092 CEST192.168.2.238.8.8.80x25e3Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:56.876336098 CEST192.168.2.238.8.8.80x6b3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:56.986859083 CEST192.168.2.238.8.8.80x6b3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:57.097084999 CEST192.168.2.238.8.8.80x6b3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:57.207439899 CEST192.168.2.238.8.8.80x6b3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:35:57.317744017 CEST192.168.2.238.8.8.80x6b3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:01.750426054 CEST192.168.2.238.8.8.80xbf27Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:01.860865116 CEST192.168.2.238.8.8.80xbf27Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:01.971462965 CEST192.168.2.238.8.8.80xbf27Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:02.082000971 CEST192.168.2.238.8.8.80xbf27Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:02.192471981 CEST192.168.2.238.8.8.80xbf27Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:07.623281956 CEST192.168.2.238.8.8.80xdf5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:07.733906031 CEST192.168.2.238.8.8.80xdf5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:07.844388962 CEST192.168.2.238.8.8.80xdf5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:07.954689026 CEST192.168.2.238.8.8.80xdf5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:08.065288067 CEST192.168.2.238.8.8.80xdf5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:13.470621109 CEST192.168.2.238.8.8.80x500fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:13.580955029 CEST192.168.2.238.8.8.80x500fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:13.691189051 CEST192.168.2.238.8.8.80x500fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:13.801589012 CEST192.168.2.238.8.8.80x500fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:13.911767006 CEST192.168.2.238.8.8.80x500fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:23.320401907 CEST192.168.2.238.8.8.80x4ec1Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:23.431000948 CEST192.168.2.238.8.8.80x4ec1Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:23.541444063 CEST192.168.2.238.8.8.80x4ec1Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:23.651582003 CEST192.168.2.238.8.8.80x4ec1Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:23.761878014 CEST192.168.2.238.8.8.80x4ec1Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:29.166985989 CEST192.168.2.238.8.8.80x63e7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:29.277672052 CEST192.168.2.238.8.8.80x63e7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:29.388217926 CEST192.168.2.238.8.8.80x63e7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:29.498569012 CEST192.168.2.238.8.8.80x63e7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:29.609164953 CEST192.168.2.238.8.8.80x63e7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:39.013951063 CEST192.168.2.238.8.8.80x60edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:39.124530077 CEST192.168.2.238.8.8.80x60edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:39.242007971 CEST192.168.2.238.8.8.80x60edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:39.352577925 CEST192.168.2.238.8.8.80x60edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:39.465555906 CEST192.168.2.238.8.8.80x60edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:48.874870062 CEST192.168.2.238.8.8.80xa091Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:48.985651970 CEST192.168.2.238.8.8.80xa091Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:49.095948935 CEST192.168.2.238.8.8.80xa091Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:49.206393003 CEST192.168.2.238.8.8.80xa091Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:49.317078114 CEST192.168.2.238.8.8.80xa091Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:52.751997948 CEST192.168.2.238.8.8.80xb0f5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:52.862340927 CEST192.168.2.238.8.8.80xb0f5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:52.972651005 CEST192.168.2.238.8.8.80xb0f5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:53.083133936 CEST192.168.2.238.8.8.80xb0f5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:36:53.193588972 CEST192.168.2.238.8.8.80xb0f5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:02.595879078 CEST192.168.2.238.8.8.80x3bdfStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:02.706279993 CEST192.168.2.238.8.8.80x3bdfStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:02.816859007 CEST192.168.2.238.8.8.80x3bdfStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:02.927498102 CEST192.168.2.238.8.8.80x3bdfStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:03.038263083 CEST192.168.2.238.8.8.80x3bdfStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:04.444401026 CEST192.168.2.238.8.8.80x2b31Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:04.554721117 CEST192.168.2.238.8.8.80x2b31Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:04.665282965 CEST192.168.2.238.8.8.80x2b31Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:04.775926113 CEST192.168.2.238.8.8.80x2b31Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:04.886570930 CEST192.168.2.238.8.8.80x2b31Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:12.295269966 CEST192.168.2.238.8.8.80xfcb8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:12.405787945 CEST192.168.2.238.8.8.80xfcb8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:12.518579960 CEST192.168.2.238.8.8.80xfcb8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:12.629153967 CEST192.168.2.238.8.8.80xfcb8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:12.740180016 CEST192.168.2.238.8.8.80xfcb8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:18.169766903 CEST192.168.2.238.8.8.80xeae7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:18.280822992 CEST192.168.2.238.8.8.80xeae7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:18.392184973 CEST192.168.2.238.8.8.80xeae7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:18.502739906 CEST192.168.2.238.8.8.80xeae7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:18.613509893 CEST192.168.2.238.8.8.80xeae7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:23.047219038 CEST192.168.2.238.8.8.80xde52Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:23.157983065 CEST192.168.2.238.8.8.80xde52Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:23.268551111 CEST192.168.2.238.8.8.80xde52Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:23.379196882 CEST192.168.2.238.8.8.80xde52Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:23.489798069 CEST192.168.2.238.8.8.80xde52Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:31.895241976 CEST192.168.2.238.8.8.80x7665Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:32.005624056 CEST192.168.2.238.8.8.80x7665Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:32.116038084 CEST192.168.2.238.8.8.80x7665Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:32.226418972 CEST192.168.2.238.8.8.80x7665Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:32.337027073 CEST192.168.2.238.8.8.80x7665Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:33.746685982 CEST192.168.2.238.8.8.80x887Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:33.857203960 CEST192.168.2.238.8.8.80x887Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:33.967727900 CEST192.168.2.238.8.8.80x887Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:34.078115940 CEST192.168.2.238.8.8.80x887Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:34.188812017 CEST192.168.2.238.8.8.80x887Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:39.593517065 CEST192.168.2.238.8.8.80xdaf8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:39.704370022 CEST192.168.2.238.8.8.80xdaf8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:39.814930916 CEST192.168.2.238.8.8.80xdaf8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:39.925585985 CEST192.168.2.238.8.8.80xdaf8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:40.036022902 CEST192.168.2.238.8.8.80xdaf8Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:42.439851046 CEST192.168.2.238.8.8.80xb2edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:42.550574064 CEST192.168.2.238.8.8.80xb2edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:42.660865068 CEST192.168.2.238.8.8.80xb2edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:42.771255016 CEST192.168.2.238.8.8.80xb2edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:42.881810904 CEST192.168.2.238.8.8.80xb2edStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:46.313194990 CEST192.168.2.238.8.8.80xfb7fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:46.423774958 CEST192.168.2.238.8.8.80xfb7fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:46.534116983 CEST192.168.2.238.8.8.80xfb7fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:46.644678116 CEST192.168.2.238.8.8.80xfb7fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:46.755311966 CEST192.168.2.238.8.8.80xfb7fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:57.162923098 CEST192.168.2.238.8.8.80x1271Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:57.273364067 CEST192.168.2.238.8.8.80x1271Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:57.383625031 CEST192.168.2.238.8.8.80x1271Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:57.493838072 CEST192.168.2.238.8.8.80x1271Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:57.603979111 CEST192.168.2.238.8.8.80x1271Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:59.009258032 CEST192.168.2.238.8.8.80xab75Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:59.119849920 CEST192.168.2.238.8.8.80xab75Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:59.230782032 CEST192.168.2.238.8.8.80xab75Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:59.341281891 CEST192.168.2.238.8.8.80xab75Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:37:59.451558113 CEST192.168.2.238.8.8.80xab75Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:38:00.856729031 CEST192.168.2.238.8.8.80xfa3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:38:00.967185020 CEST192.168.2.238.8.8.80xfa3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
                                                                        Apr 25, 2024 14:38:01.077897072 CEST192.168.2.238.8.8.80xfa3bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false

                                                                        System Behavior

                                                                        Start time (UTC):12:35:49
                                                                        Start date (UTC):25/04/2024
                                                                        Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        Arguments:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):12:35:49
                                                                        Start date (UTC):25/04/2024
                                                                        Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):12:35:49
                                                                        Start date (UTC):25/04/2024
                                                                        Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):12:35:49
                                                                        Start date (UTC):25/04/2024
                                                                        Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):12:35:49
                                                                        Start date (UTC):25/04/2024
                                                                        Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):12:35:49
                                                                        Start date (UTC):25/04/2024
                                                                        Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.12445.30549.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1