Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf

Overview

General Information

Sample name:SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
Analysis ID:1431615
MD5:04d13cfaf7676bf680eba4e671030af9
SHA1:5d78b935337aa43430e7376335a1bf75a8773ac0
SHA256:51d6f3ebab00dac8430a22fb253425205a9e3b353a4f7ed90f534af7d55edd73
Tags:elf
Infos:

Detection

Mirai
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
Static ELF header machine description suggests that the sample might only run correctly on MIPS or ARM architectures.
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1431615
Start date and time:2024-04-25 14:35:10 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
Detection:MAL
Classification:mal84.troj.evad.linELF@0/0@105/0
Command:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
PID:5494
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
5494.1.00007f0640017000.00007f064002e000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    5494.1.00007f0640017000.00007f064002e000.r-x.sdmpJoeSecurity_Mirai_5Yara detected MiraiJoe Security
      5494.1.00007f0640017000.00007f064002e000.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
      • 0x157e8:$x1: POST /cdn-cgi/
      • 0x15b6c:$s1: LCOGQGPTGP
      5494.1.00007f0640017000.00007f064002e000.r-x.sdmpMAL_ELF_LNX_Mirai_Oct10_2Detects ELF malware Mirai relatedFlorian Roth
      • 0x157e8:$c01: 50 4F 53 54 20 2F 63 64 6E 2D 63 67 69 2F 00 00 20 48 54 54 50 2F 31 2E 31 0D 0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 00 0D 0A 48 6F 73 74 3A
      5496.1.00007f0640017000.00007f064002e000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
        Click to see the 14 entries
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elfAvira: detected
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elfVirustotal: Detection: 55%Perma Link
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elfReversingLabs: Detection: 67%
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5494)Socket: 127.0.0.1::29103Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::23Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::0Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::80Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::81Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::8443Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::9009Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::1337Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::13883Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::19481Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::4444Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)Socket: 0.0.0.0::9789Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::0Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::80Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::81Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::8443Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::9009Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::1337Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::13883Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::19481Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::4444Jump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)Socket: 0.0.0.0::9789Jump to behavior
        Source: global trafficDNS traffic detected: DNS query: www.sushiking.world
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elfString found in binary or memory: http://upx.sf.net

        System Summary

        barindex
        Source: 5494.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 5494.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: 5496.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 5496.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: 5498.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 5498.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: 5504.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
        Source: 5504.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Detects ELF malware Mirai related Author: Florian Roth
        Source: LOAD without section mappingsProgram segment: 0x8000
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)SIGKILL sent: pid: 940, result: successfulJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)SIGKILL sent: pid: 940, result: successfulJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)SIGKILL sent: pid: 5496, result: successfulJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)SIGKILL sent: pid: 767, result: successfulJump to behavior
        Source: 5494.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 5494.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: 5496.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 5496.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: 5498.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 5498.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: 5504.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
        Source: 5504.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORYMatched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research
        Source: classification engineClassification label: mal84.troj.evad.linELF@0/0@105/0

        Data Obfuscation

        barindex
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/490/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/791/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/794/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/795/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/797/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/853/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/917/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/780/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/1/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/661/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/782/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/785/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/940/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/767/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/800/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/888/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/801/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/725/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/769/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/726/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/803/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/806/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/807/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5496)File opened: /proc/928/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3244/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1583/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/2672/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3120/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3120/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3361/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3239/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1577/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1577/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1610/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1610/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1299/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1299/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3235/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/512/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/514/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/519/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/2946/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/2946/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/917/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/917/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/917/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3134/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3134/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1593/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1593/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3011/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3011/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3094/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3094/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/2955/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/2955/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3406/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1589/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1589/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3129/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3129/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1588/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/1588/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3402/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3125/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3125/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3246/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3245/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/767/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/767/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/767/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/800/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/800/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/800/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/888/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/888/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/888/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/801/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/801/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/801/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/769/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/769/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/769/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/803/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/803/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/803/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/806/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/806/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/806/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/807/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/807/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/807/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/928/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/928/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/928/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/2956/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/2956/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3420/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/490/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/490/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/490/exeJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3142/fdJump to behavior
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5502)File opened: /proc/3142/exeJump to behavior
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elfSubmission file: segment LOAD with 7.9594 entropy (max. 8.0)
        Source: /tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf (PID: 5494)Queries kernel information via 'uname': Jump to behavior
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5494.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5496.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5498.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5504.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5494.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5496.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5498.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5504.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmpBinary or memory string: _U!/etc/qemu-binfmt/arm
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5494.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5496.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5498.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5504.1.0000555fcfd5d000.0000555fcff2b000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
        Source: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5494.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5496.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5498.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmp, SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf, 5504.1.00007ffe8b864000.00007ffe8b885000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 5494.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5496.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5498.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5504.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf PID: 5494, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf PID: 5496, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf PID: 5498, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 5494.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5496.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5498.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 5504.1.00007f0640017000.00007f064002e000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf PID: 5494, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf PID: 5496, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf PID: 5498, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
        Obfuscated Files or Information
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Non-Application Layer Protocol
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Application Layer Protocol
        Exfiltration Over BluetoothNetwork Denial of Service
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf56%VirustotalBrowse
        SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf68%ReversingLabsLinux.Trojan.Mirai
        SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf100%AviraANDROID/Mirai.xofdu
        No Antivirus matches
        SourceDetectionScannerLabelLink
        www.sushiking.world8%VirustotalBrowse
        No Antivirus matches
        NameIPActiveMaliciousAntivirus DetectionReputation
        www.sushiking.world
        unknown
        unknownfalseunknown
        NameSourceMaliciousAntivirus DetectionReputation
        http://upx.sf.netSecuriteInfo.com.Linux.Siggen.9999.23595.2512.elffalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          79.110.48.149
          unknownGermany
          57287OTAVANET-ASCZfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          79.110.48.149TGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            OTAVANET-ASCZTGIQpNxMb0.elfGet hashmaliciousMiraiBrowse
            • 79.110.48.149
            skid.arm7.elfGet hashmaliciousMiraiBrowse
            • 79.110.49.174
            HROFrIvvVk.elfGet hashmaliciousMiraiBrowse
            • 79.110.49.195
            https://79.110.48.52/nicko.vbsGet hashmaliciousUnknownBrowse
            • 79.110.48.52
            PO_1100620230526.pdf(39kb).exeGet hashmaliciousRemcos, RedLine, XpertRATBrowse
            • 79.110.48.151
            https://prc-homes.uk/wp-images/26738903/content/Security_on_your_card_account.htmlGet hashmaliciousHTMLPhisherBrowse
            • 79.110.48.18
            https://towntalkeg.com/wp-images/108373893032/Security_on_your_card_account.htmlGet hashmaliciousHTMLPhisherBrowse
            • 79.110.48.18
            0xc2s.x86.elfGet hashmaliciousUnknownBrowse
            • 79.110.48.91
            oWlBd5huKm.elfGet hashmaliciousUnknownBrowse
            • 79.110.48.116
            JSJRrcfx4B.elfGet hashmaliciousUnknownBrowse
            • 79.110.48.116
            No context
            No context
            No created / dropped files found
            File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, no section header
            Entropy (8bit):7.976446472256899
            TrID:
            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
            File name:SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            File size:50'460 bytes
            MD5:04d13cfaf7676bf680eba4e671030af9
            SHA1:5d78b935337aa43430e7376335a1bf75a8773ac0
            SHA256:51d6f3ebab00dac8430a22fb253425205a9e3b353a4f7ed90f534af7d55edd73
            SHA512:44f6ae9f831f1dfecedc2bde4de461833d59fd3932f308f231dceeb52c7598ed29b00c25eee430a05b90bdfb7af70b0dd980f8ea9d530b9387e171d97d9385f9
            SSDEEP:768:DZZ1zSsAK2yJ9o8ZEQDnRsent7j/rI4Jnkfw9q3UELn7u1ygpowQNd26f2FRsYDy:DFzSFKv9j7Rsent7zZM5Ln7TC6QRsWkP
            TLSH:FB330138B0AB6AE39BB0731DC9E603D35E1DD73CB0A63D374411495E6B9111ABBE0987
            File Content Preview:.ELF..............(.........4...........4. ...(.....................................................................Q.td............................>. NUPX!....................j..........?.E.h;....#..$...o......4Y.....;G%H........)..%lD....3Y!...t...{.G_.

            ELF header

            Class:ELF32
            Data:2's complement, little endian
            Version:1 (current)
            Machine:ARM
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - Linux
            ABI Version:0
            Entry Point Address:0xf8a0
            Flags:0x4000002
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:0
            Section Header Size:40
            Number of Section Headers:0
            Header String Table Index:0
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00x80000x80000x8a8d0x8a8d7.95940x5R E0x8000
            LOAD0x1c1c0x29c1c0x29c1c0x00x00.00000x6RW 0x8000
            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
            TimestampSource PortDest PortSource IPDest IP
            Apr 25, 2024 14:35:53.221513987 CEST3694080192.168.2.1479.110.48.149
            Apr 25, 2024 14:35:53.516166925 CEST803694079.110.48.149192.168.2.14
            Apr 25, 2024 14:35:55.073951006 CEST3694280192.168.2.1479.110.48.149
            Apr 25, 2024 14:35:55.373740911 CEST803694279.110.48.149192.168.2.14
            Apr 25, 2024 14:36:02.926868916 CEST3694480192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:03.225589991 CEST803694479.110.48.149192.168.2.14
            Apr 25, 2024 14:36:10.776891947 CEST3694680192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:11.075622082 CEST803694679.110.48.149192.168.2.14
            Apr 25, 2024 14:36:16.627656937 CEST3694880192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:16.923572063 CEST803694879.110.48.149192.168.2.14
            Apr 25, 2024 14:36:24.475373983 CEST3695080192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:24.769792080 CEST803695079.110.48.149192.168.2.14
            Apr 25, 2024 14:36:35.322810888 CEST3695280192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:35.642338991 CEST803695279.110.48.149192.168.2.14
            Apr 25, 2024 14:36:40.198215008 CEST3695480192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:40.489336014 CEST803695479.110.48.149192.168.2.14
            Apr 25, 2024 14:36:44.043971062 CEST3695680192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:44.363492966 CEST803695679.110.48.149192.168.2.14
            Apr 25, 2024 14:36:52.916291952 CEST3695880192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:53.212347031 CEST803695879.110.48.149192.168.2.14
            Apr 25, 2024 14:36:55.764997005 CEST3696080192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:56.085493088 CEST803696079.110.48.149192.168.2.14
            Apr 25, 2024 14:36:58.637823105 CEST3696280192.168.2.1479.110.48.149
            Apr 25, 2024 14:36:58.932538986 CEST803696279.110.48.149192.168.2.14
            Apr 25, 2024 14:37:06.485517025 CEST3696480192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:06.781955957 CEST803696479.110.48.149192.168.2.14
            Apr 25, 2024 14:37:12.337038994 CEST3696680192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:12.631704092 CEST803696679.110.48.149192.168.2.14
            Apr 25, 2024 14:37:17.183814049 CEST3696880192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:17.479438066 CEST803696879.110.48.149192.168.2.14
            Apr 25, 2024 14:37:21.035142899 CEST3697080192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:21.330399990 CEST803697079.110.48.149192.168.2.14
            Apr 25, 2024 14:37:31.883419037 CEST3697280192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:32.175193071 CEST803697279.110.48.149192.168.2.14
            Apr 25, 2024 14:37:39.727855921 CEST3697480192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:40.023392916 CEST803697479.110.48.149192.168.2.14
            Apr 25, 2024 14:37:44.580938101 CEST3697680192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:44.876032114 CEST803697679.110.48.149192.168.2.14
            Apr 25, 2024 14:37:51.428133011 CEST3697880192.168.2.1479.110.48.149
            Apr 25, 2024 14:37:51.722697973 CEST803697879.110.48.149192.168.2.14
            Apr 25, 2024 14:38:01.275347948 CEST3698080192.168.2.1479.110.48.149
            Apr 25, 2024 14:38:01.574548006 CEST803698079.110.48.149192.168.2.14
            TimestampSource PortDest PortSource IPDest IP
            Apr 25, 2024 14:35:52.667831898 CEST5246953192.168.2.148.8.8.8
            Apr 25, 2024 14:35:52.778768063 CEST53524698.8.8.8192.168.2.14
            Apr 25, 2024 14:35:52.779138088 CEST4504953192.168.2.148.8.8.8
            Apr 25, 2024 14:35:52.889297962 CEST53450498.8.8.8192.168.2.14
            Apr 25, 2024 14:35:52.889434099 CEST4760553192.168.2.148.8.8.8
            Apr 25, 2024 14:35:52.999655962 CEST53476058.8.8.8192.168.2.14
            Apr 25, 2024 14:35:52.999883890 CEST3939253192.168.2.148.8.8.8
            Apr 25, 2024 14:35:53.111185074 CEST53393928.8.8.8192.168.2.14
            Apr 25, 2024 14:35:53.111275911 CEST4152453192.168.2.148.8.8.8
            Apr 25, 2024 14:35:53.221158028 CEST53415248.8.8.8192.168.2.14
            Apr 25, 2024 14:35:54.516706944 CEST5339353192.168.2.148.8.8.8
            Apr 25, 2024 14:35:54.628700018 CEST53533938.8.8.8192.168.2.14
            Apr 25, 2024 14:35:54.628849030 CEST4384053192.168.2.148.8.8.8
            Apr 25, 2024 14:35:54.738866091 CEST53438408.8.8.8192.168.2.14
            Apr 25, 2024 14:35:54.738976002 CEST3465553192.168.2.148.8.8.8
            Apr 25, 2024 14:35:54.849262953 CEST53346558.8.8.8192.168.2.14
            Apr 25, 2024 14:35:54.849375963 CEST3764653192.168.2.148.8.8.8
            Apr 25, 2024 14:35:54.963306904 CEST53376468.8.8.8192.168.2.14
            Apr 25, 2024 14:35:54.963421106 CEST5122353192.168.2.148.8.8.8
            Apr 25, 2024 14:35:55.073767900 CEST53512238.8.8.8192.168.2.14
            Apr 25, 2024 14:36:02.373811960 CEST4417953192.168.2.148.8.8.8
            Apr 25, 2024 14:36:02.484035969 CEST53441798.8.8.8192.168.2.14
            Apr 25, 2024 14:36:02.484457016 CEST4975753192.168.2.148.8.8.8
            Apr 25, 2024 14:36:02.595824003 CEST53497578.8.8.8192.168.2.14
            Apr 25, 2024 14:36:02.596172094 CEST6004253192.168.2.148.8.8.8
            Apr 25, 2024 14:36:02.705996990 CEST53600428.8.8.8192.168.2.14
            Apr 25, 2024 14:36:02.706309080 CEST5073853192.168.2.148.8.8.8
            Apr 25, 2024 14:36:02.816265106 CEST53507388.8.8.8192.168.2.14
            Apr 25, 2024 14:36:02.816673040 CEST3940053192.168.2.148.8.8.8
            Apr 25, 2024 14:36:02.926618099 CEST53394008.8.8.8192.168.2.14
            Apr 25, 2024 14:36:10.225701094 CEST5926753192.168.2.148.8.8.8
            Apr 25, 2024 14:36:10.335484982 CEST53592678.8.8.8192.168.2.14
            Apr 25, 2024 14:36:10.335918903 CEST3923253192.168.2.148.8.8.8
            Apr 25, 2024 14:36:10.445992947 CEST53392328.8.8.8192.168.2.14
            Apr 25, 2024 14:36:10.446274042 CEST3622653192.168.2.148.8.8.8
            Apr 25, 2024 14:36:10.556318045 CEST53362268.8.8.8192.168.2.14
            Apr 25, 2024 14:36:10.556606054 CEST4242053192.168.2.148.8.8.8
            Apr 25, 2024 14:36:10.666426897 CEST53424208.8.8.8192.168.2.14
            Apr 25, 2024 14:36:10.666670084 CEST4596553192.168.2.148.8.8.8
            Apr 25, 2024 14:36:10.776696920 CEST53459658.8.8.8192.168.2.14
            Apr 25, 2024 14:36:16.075803041 CEST5013653192.168.2.148.8.8.8
            Apr 25, 2024 14:36:16.186052084 CEST53501368.8.8.8192.168.2.14
            Apr 25, 2024 14:36:16.186295986 CEST5310153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:16.296236992 CEST53531018.8.8.8192.168.2.14
            Apr 25, 2024 14:36:16.296513081 CEST5936453192.168.2.148.8.8.8
            Apr 25, 2024 14:36:16.406744957 CEST53593648.8.8.8192.168.2.14
            Apr 25, 2024 14:36:16.407121897 CEST3481653192.168.2.148.8.8.8
            Apr 25, 2024 14:36:16.517071962 CEST53348168.8.8.8192.168.2.14
            Apr 25, 2024 14:36:16.517321110 CEST4771253192.168.2.148.8.8.8
            Apr 25, 2024 14:36:16.627244949 CEST53477128.8.8.8192.168.2.14
            Apr 25, 2024 14:36:23.923671961 CEST3348453192.168.2.148.8.8.8
            Apr 25, 2024 14:36:24.033617020 CEST53334848.8.8.8192.168.2.14
            Apr 25, 2024 14:36:24.033878088 CEST5887353192.168.2.148.8.8.8
            Apr 25, 2024 14:36:24.143893003 CEST53588738.8.8.8192.168.2.14
            Apr 25, 2024 14:36:24.144242048 CEST3599853192.168.2.148.8.8.8
            Apr 25, 2024 14:36:24.254231930 CEST53359988.8.8.8192.168.2.14
            Apr 25, 2024 14:36:24.254693031 CEST4907153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:24.364819050 CEST53490718.8.8.8192.168.2.14
            Apr 25, 2024 14:36:24.365025997 CEST5898853192.168.2.148.8.8.8
            Apr 25, 2024 14:36:24.475192070 CEST53589888.8.8.8192.168.2.14
            Apr 25, 2024 14:36:34.769927979 CEST4212353192.168.2.148.8.8.8
            Apr 25, 2024 14:36:34.880193949 CEST53421238.8.8.8192.168.2.14
            Apr 25, 2024 14:36:34.880707026 CEST3869153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:34.990986109 CEST53386918.8.8.8192.168.2.14
            Apr 25, 2024 14:36:34.991344929 CEST4568253192.168.2.148.8.8.8
            Apr 25, 2024 14:36:35.101419926 CEST53456828.8.8.8192.168.2.14
            Apr 25, 2024 14:36:35.101799965 CEST5729453192.168.2.148.8.8.8
            Apr 25, 2024 14:36:35.211910009 CEST53572948.8.8.8192.168.2.14
            Apr 25, 2024 14:36:35.212380886 CEST4971253192.168.2.148.8.8.8
            Apr 25, 2024 14:36:35.322513103 CEST53497128.8.8.8192.168.2.14
            Apr 25, 2024 14:36:39.642592907 CEST4614653192.168.2.148.8.8.8
            Apr 25, 2024 14:36:39.753504992 CEST53461468.8.8.8192.168.2.14
            Apr 25, 2024 14:36:39.753741026 CEST4172553192.168.2.148.8.8.8
            Apr 25, 2024 14:36:39.864743948 CEST53417258.8.8.8192.168.2.14
            Apr 25, 2024 14:36:39.865118027 CEST4853953192.168.2.148.8.8.8
            Apr 25, 2024 14:36:39.976707935 CEST53485398.8.8.8192.168.2.14
            Apr 25, 2024 14:36:39.976999044 CEST3888153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:40.087167025 CEST53388818.8.8.8192.168.2.14
            Apr 25, 2024 14:36:40.087718964 CEST5715353192.168.2.148.8.8.8
            Apr 25, 2024 14:36:40.197959900 CEST53571538.8.8.8192.168.2.14
            Apr 25, 2024 14:36:43.489700079 CEST4710553192.168.2.148.8.8.8
            Apr 25, 2024 14:36:43.599848986 CEST53471058.8.8.8192.168.2.14
            Apr 25, 2024 14:36:43.600148916 CEST5698253192.168.2.148.8.8.8
            Apr 25, 2024 14:36:43.710405111 CEST53569828.8.8.8192.168.2.14
            Apr 25, 2024 14:36:43.710794926 CEST4561553192.168.2.148.8.8.8
            Apr 25, 2024 14:36:43.821178913 CEST53456158.8.8.8192.168.2.14
            Apr 25, 2024 14:36:43.821305037 CEST5616353192.168.2.148.8.8.8
            Apr 25, 2024 14:36:43.931778908 CEST53561638.8.8.8192.168.2.14
            Apr 25, 2024 14:36:43.932028055 CEST3344053192.168.2.148.8.8.8
            Apr 25, 2024 14:36:44.043735027 CEST53334408.8.8.8192.168.2.14
            Apr 25, 2024 14:36:52.363703012 CEST4972753192.168.2.148.8.8.8
            Apr 25, 2024 14:36:52.474004030 CEST53497278.8.8.8192.168.2.14
            Apr 25, 2024 14:36:52.474282026 CEST4789253192.168.2.148.8.8.8
            Apr 25, 2024 14:36:52.584362984 CEST53478928.8.8.8192.168.2.14
            Apr 25, 2024 14:36:52.585081100 CEST5108153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:52.695110083 CEST53510818.8.8.8192.168.2.14
            Apr 25, 2024 14:36:52.695348024 CEST4960353192.168.2.148.8.8.8
            Apr 25, 2024 14:36:52.805581093 CEST53496038.8.8.8192.168.2.14
            Apr 25, 2024 14:36:52.805814028 CEST4330353192.168.2.148.8.8.8
            Apr 25, 2024 14:36:52.916052103 CEST53433038.8.8.8192.168.2.14
            Apr 25, 2024 14:36:55.212709904 CEST3960153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:55.322877884 CEST53396018.8.8.8192.168.2.14
            Apr 25, 2024 14:36:55.323045969 CEST5039853192.168.2.148.8.8.8
            Apr 25, 2024 14:36:55.433415890 CEST53503988.8.8.8192.168.2.14
            Apr 25, 2024 14:36:55.433780909 CEST4036153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:55.543982983 CEST53403618.8.8.8192.168.2.14
            Apr 25, 2024 14:36:55.544241905 CEST5308353192.168.2.148.8.8.8
            Apr 25, 2024 14:36:55.654165983 CEST53530838.8.8.8192.168.2.14
            Apr 25, 2024 14:36:55.654519081 CEST3454053192.168.2.148.8.8.8
            Apr 25, 2024 14:36:55.764712095 CEST53345408.8.8.8192.168.2.14
            Apr 25, 2024 14:36:58.085813999 CEST4035653192.168.2.148.8.8.8
            Apr 25, 2024 14:36:58.196177959 CEST53403568.8.8.8192.168.2.14
            Apr 25, 2024 14:36:58.196366072 CEST4577453192.168.2.148.8.8.8
            Apr 25, 2024 14:36:58.306366920 CEST53457748.8.8.8192.168.2.14
            Apr 25, 2024 14:36:58.306726933 CEST4619853192.168.2.148.8.8.8
            Apr 25, 2024 14:36:58.416826963 CEST53461988.8.8.8192.168.2.14
            Apr 25, 2024 14:36:58.417012930 CEST5736153192.168.2.148.8.8.8
            Apr 25, 2024 14:36:58.527149916 CEST53573618.8.8.8192.168.2.14
            Apr 25, 2024 14:36:58.527309895 CEST4962853192.168.2.148.8.8.8
            Apr 25, 2024 14:36:58.637516975 CEST53496288.8.8.8192.168.2.14
            Apr 25, 2024 14:37:05.932672977 CEST4556053192.168.2.148.8.8.8
            Apr 25, 2024 14:37:06.043242931 CEST53455608.8.8.8192.168.2.14
            Apr 25, 2024 14:37:06.043417931 CEST5550253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:06.153645039 CEST53555028.8.8.8192.168.2.14
            Apr 25, 2024 14:37:06.153891087 CEST6095653192.168.2.148.8.8.8
            Apr 25, 2024 14:37:06.264126062 CEST53609568.8.8.8192.168.2.14
            Apr 25, 2024 14:37:06.264405012 CEST3746053192.168.2.148.8.8.8
            Apr 25, 2024 14:37:06.374516964 CEST53374608.8.8.8192.168.2.14
            Apr 25, 2024 14:37:06.374989033 CEST5353253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:06.485299110 CEST53535328.8.8.8192.168.2.14
            Apr 25, 2024 14:37:11.782170057 CEST4582253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:11.892780066 CEST53458228.8.8.8192.168.2.14
            Apr 25, 2024 14:37:11.892983913 CEST5153353192.168.2.148.8.8.8
            Apr 25, 2024 14:37:12.003513098 CEST53515338.8.8.8192.168.2.14
            Apr 25, 2024 14:37:12.003731966 CEST3776353192.168.2.148.8.8.8
            Apr 25, 2024 14:37:12.114222050 CEST53377638.8.8.8192.168.2.14
            Apr 25, 2024 14:37:12.114449978 CEST4494853192.168.2.148.8.8.8
            Apr 25, 2024 14:37:12.224642992 CEST53449488.8.8.8192.168.2.14
            Apr 25, 2024 14:37:12.224869967 CEST4552153192.168.2.148.8.8.8
            Apr 25, 2024 14:37:12.336755037 CEST53455218.8.8.8192.168.2.14
            Apr 25, 2024 14:37:16.631946087 CEST5690353192.168.2.148.8.8.8
            Apr 25, 2024 14:37:16.742044926 CEST53569038.8.8.8192.168.2.14
            Apr 25, 2024 14:37:16.742271900 CEST4860053192.168.2.148.8.8.8
            Apr 25, 2024 14:37:16.852586031 CEST53486008.8.8.8192.168.2.14
            Apr 25, 2024 14:37:16.852829933 CEST5486353192.168.2.148.8.8.8
            Apr 25, 2024 14:37:16.962939978 CEST53548638.8.8.8192.168.2.14
            Apr 25, 2024 14:37:16.963259935 CEST4098153192.168.2.148.8.8.8
            Apr 25, 2024 14:37:17.073307991 CEST53409818.8.8.8192.168.2.14
            Apr 25, 2024 14:37:17.073538065 CEST4393253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:17.183480024 CEST53439328.8.8.8192.168.2.14
            Apr 25, 2024 14:37:20.479739904 CEST4636753192.168.2.148.8.8.8
            Apr 25, 2024 14:37:20.589993954 CEST53463678.8.8.8192.168.2.14
            Apr 25, 2024 14:37:20.590285063 CEST5696453192.168.2.148.8.8.8
            Apr 25, 2024 14:37:20.700437069 CEST53569648.8.8.8192.168.2.14
            Apr 25, 2024 14:37:20.700660944 CEST6068253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:20.810822964 CEST53606828.8.8.8192.168.2.14
            Apr 25, 2024 14:37:20.810986042 CEST3619753192.168.2.148.8.8.8
            Apr 25, 2024 14:37:20.922671080 CEST53361978.8.8.8192.168.2.14
            Apr 25, 2024 14:37:20.922801971 CEST3525153192.168.2.148.8.8.8
            Apr 25, 2024 14:37:21.034940004 CEST53352518.8.8.8192.168.2.14
            Apr 25, 2024 14:37:31.330609083 CEST3978853192.168.2.148.8.8.8
            Apr 25, 2024 14:37:31.440759897 CEST53397888.8.8.8192.168.2.14
            Apr 25, 2024 14:37:31.441097021 CEST5694853192.168.2.148.8.8.8
            Apr 25, 2024 14:37:31.551213026 CEST53569488.8.8.8192.168.2.14
            Apr 25, 2024 14:37:31.551711082 CEST4238853192.168.2.148.8.8.8
            Apr 25, 2024 14:37:31.661969900 CEST53423888.8.8.8192.168.2.14
            Apr 25, 2024 14:37:31.662432909 CEST4957453192.168.2.148.8.8.8
            Apr 25, 2024 14:37:31.772448063 CEST53495748.8.8.8192.168.2.14
            Apr 25, 2024 14:37:31.772984982 CEST5298453192.168.2.148.8.8.8
            Apr 25, 2024 14:37:31.883054018 CEST53529848.8.8.8192.168.2.14
            Apr 25, 2024 14:37:39.175451040 CEST4136453192.168.2.148.8.8.8
            Apr 25, 2024 14:37:39.285665035 CEST53413648.8.8.8192.168.2.14
            Apr 25, 2024 14:37:39.285955906 CEST4207153192.168.2.148.8.8.8
            Apr 25, 2024 14:37:39.396229029 CEST53420718.8.8.8192.168.2.14
            Apr 25, 2024 14:37:39.396469116 CEST5900553192.168.2.148.8.8.8
            Apr 25, 2024 14:37:39.506727934 CEST53590058.8.8.8192.168.2.14
            Apr 25, 2024 14:37:39.506943941 CEST5296953192.168.2.148.8.8.8
            Apr 25, 2024 14:37:39.617127895 CEST53529698.8.8.8192.168.2.14
            Apr 25, 2024 14:37:39.617381096 CEST3609553192.168.2.148.8.8.8
            Apr 25, 2024 14:37:39.727497101 CEST53360958.8.8.8192.168.2.14
            Apr 25, 2024 14:37:44.023943901 CEST5480153192.168.2.148.8.8.8
            Apr 25, 2024 14:37:44.134335041 CEST53548018.8.8.8192.168.2.14
            Apr 25, 2024 14:37:44.134815931 CEST4364453192.168.2.148.8.8.8
            Apr 25, 2024 14:37:44.245012045 CEST53436448.8.8.8192.168.2.14
            Apr 25, 2024 14:37:44.245371103 CEST5839253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:44.355616093 CEST53583928.8.8.8192.168.2.14
            Apr 25, 2024 14:37:44.355856895 CEST4099053192.168.2.148.8.8.8
            Apr 25, 2024 14:37:44.470136881 CEST53409908.8.8.8192.168.2.14
            Apr 25, 2024 14:37:44.470386028 CEST4770453192.168.2.148.8.8.8
            Apr 25, 2024 14:37:44.580620050 CEST53477048.8.8.8192.168.2.14
            Apr 25, 2024 14:37:50.876216888 CEST5835053192.168.2.148.8.8.8
            Apr 25, 2024 14:37:50.986176014 CEST53583508.8.8.8192.168.2.14
            Apr 25, 2024 14:37:50.986282110 CEST4634753192.168.2.148.8.8.8
            Apr 25, 2024 14:37:51.096446991 CEST53463478.8.8.8192.168.2.14
            Apr 25, 2024 14:37:51.096741915 CEST3294253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:51.206861019 CEST53329428.8.8.8192.168.2.14
            Apr 25, 2024 14:37:51.207231045 CEST5119353192.168.2.148.8.8.8
            Apr 25, 2024 14:37:51.317447901 CEST53511938.8.8.8192.168.2.14
            Apr 25, 2024 14:37:51.317687988 CEST4361253192.168.2.148.8.8.8
            Apr 25, 2024 14:37:51.427803040 CEST53436128.8.8.8192.168.2.14
            Apr 25, 2024 14:38:00.722796917 CEST5418753192.168.2.148.8.8.8
            Apr 25, 2024 14:38:00.833091974 CEST53541878.8.8.8192.168.2.14
            Apr 25, 2024 14:38:00.833425999 CEST5591053192.168.2.148.8.8.8
            Apr 25, 2024 14:38:00.943792105 CEST53559108.8.8.8192.168.2.14
            Apr 25, 2024 14:38:00.944044113 CEST4640953192.168.2.148.8.8.8
            Apr 25, 2024 14:38:01.054092884 CEST53464098.8.8.8192.168.2.14
            Apr 25, 2024 14:38:01.054349899 CEST3473753192.168.2.148.8.8.8
            Apr 25, 2024 14:38:01.164469004 CEST53347378.8.8.8192.168.2.14
            Apr 25, 2024 14:38:01.164791107 CEST3334353192.168.2.148.8.8.8
            Apr 25, 2024 14:38:01.275115967 CEST53333438.8.8.8192.168.2.14
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
            Apr 25, 2024 14:35:52.667831898 CEST192.168.2.148.8.8.80x1fb5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:52.779138088 CEST192.168.2.148.8.8.80x1fb5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:52.889434099 CEST192.168.2.148.8.8.80x1fb5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:52.999883890 CEST192.168.2.148.8.8.80x1fb5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:53.111275911 CEST192.168.2.148.8.8.80x1fb5Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:54.516706944 CEST192.168.2.148.8.8.80x97dStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:54.628849030 CEST192.168.2.148.8.8.80x97dStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:54.738976002 CEST192.168.2.148.8.8.80x97dStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:54.849375963 CEST192.168.2.148.8.8.80x97dStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:35:54.963421106 CEST192.168.2.148.8.8.80x97dStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:02.373811960 CEST192.168.2.148.8.8.80xea56Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:02.484457016 CEST192.168.2.148.8.8.80xea56Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:02.596172094 CEST192.168.2.148.8.8.80xea56Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:02.706309080 CEST192.168.2.148.8.8.80xea56Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:02.816673040 CEST192.168.2.148.8.8.80xea56Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:10.225701094 CEST192.168.2.148.8.8.80xbeaStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:10.335918903 CEST192.168.2.148.8.8.80xbeaStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:10.446274042 CEST192.168.2.148.8.8.80xbeaStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:10.556606054 CEST192.168.2.148.8.8.80xbeaStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:10.666670084 CEST192.168.2.148.8.8.80xbeaStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:16.075803041 CEST192.168.2.148.8.8.80x621Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:16.186295986 CEST192.168.2.148.8.8.80x621Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:16.296513081 CEST192.168.2.148.8.8.80x621Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:16.407121897 CEST192.168.2.148.8.8.80x621Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:16.517321110 CEST192.168.2.148.8.8.80x621Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:23.923671961 CEST192.168.2.148.8.8.80x4b90Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:24.033878088 CEST192.168.2.148.8.8.80x4b90Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:24.144242048 CEST192.168.2.148.8.8.80x4b90Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:24.254693031 CEST192.168.2.148.8.8.80x4b90Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:24.365025997 CEST192.168.2.148.8.8.80x4b90Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:34.769927979 CEST192.168.2.148.8.8.80x9782Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:34.880707026 CEST192.168.2.148.8.8.80x9782Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:34.991344929 CEST192.168.2.148.8.8.80x9782Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:35.101799965 CEST192.168.2.148.8.8.80x9782Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:35.212380886 CEST192.168.2.148.8.8.80x9782Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:39.642592907 CEST192.168.2.148.8.8.80x7f8eStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:39.753741026 CEST192.168.2.148.8.8.80x7f8eStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:39.865118027 CEST192.168.2.148.8.8.80x7f8eStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:39.976999044 CEST192.168.2.148.8.8.80x7f8eStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:40.087718964 CEST192.168.2.148.8.8.80x7f8eStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:43.489700079 CEST192.168.2.148.8.8.80xa929Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:43.600148916 CEST192.168.2.148.8.8.80xa929Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:43.710794926 CEST192.168.2.148.8.8.80xa929Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:43.821305037 CEST192.168.2.148.8.8.80xa929Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:43.932028055 CEST192.168.2.148.8.8.80xa929Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:52.363703012 CEST192.168.2.148.8.8.80x7103Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:52.474282026 CEST192.168.2.148.8.8.80x7103Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:52.585081100 CEST192.168.2.148.8.8.80x7103Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:52.695348024 CEST192.168.2.148.8.8.80x7103Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:52.805814028 CEST192.168.2.148.8.8.80x7103Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:55.212709904 CEST192.168.2.148.8.8.80x4e5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:55.323045969 CEST192.168.2.148.8.8.80x4e5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:55.433780909 CEST192.168.2.148.8.8.80x4e5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:55.544241905 CEST192.168.2.148.8.8.80x4e5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:55.654519081 CEST192.168.2.148.8.8.80x4e5cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:58.085813999 CEST192.168.2.148.8.8.80xc599Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:58.196366072 CEST192.168.2.148.8.8.80xc599Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:58.306726933 CEST192.168.2.148.8.8.80xc599Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:58.417012930 CEST192.168.2.148.8.8.80xc599Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:36:58.527309895 CEST192.168.2.148.8.8.80xc599Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:05.932672977 CEST192.168.2.148.8.8.80x1d2bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:06.043417931 CEST192.168.2.148.8.8.80x1d2bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:06.153891087 CEST192.168.2.148.8.8.80x1d2bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:06.264405012 CEST192.168.2.148.8.8.80x1d2bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:06.374989033 CEST192.168.2.148.8.8.80x1d2bStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:11.782170057 CEST192.168.2.148.8.8.80x3f7cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:11.892983913 CEST192.168.2.148.8.8.80x3f7cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:12.003731966 CEST192.168.2.148.8.8.80x3f7cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:12.114449978 CEST192.168.2.148.8.8.80x3f7cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:12.224869967 CEST192.168.2.148.8.8.80x3f7cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:16.631946087 CEST192.168.2.148.8.8.80x5446Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:16.742271900 CEST192.168.2.148.8.8.80x5446Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:16.852829933 CEST192.168.2.148.8.8.80x5446Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:16.963259935 CEST192.168.2.148.8.8.80x5446Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:17.073538065 CEST192.168.2.148.8.8.80x5446Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:20.479739904 CEST192.168.2.148.8.8.80x6e6cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:20.590285063 CEST192.168.2.148.8.8.80x6e6cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:20.700660944 CEST192.168.2.148.8.8.80x6e6cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:20.810986042 CEST192.168.2.148.8.8.80x6e6cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:20.922801971 CEST192.168.2.148.8.8.80x6e6cStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:31.330609083 CEST192.168.2.148.8.8.80x4668Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:31.441097021 CEST192.168.2.148.8.8.80x4668Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:31.551711082 CEST192.168.2.148.8.8.80x4668Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:31.662432909 CEST192.168.2.148.8.8.80x4668Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:31.772984982 CEST192.168.2.148.8.8.80x4668Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:39.175451040 CEST192.168.2.148.8.8.80xe36fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:39.285955906 CEST192.168.2.148.8.8.80xe36fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:39.396469116 CEST192.168.2.148.8.8.80xe36fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:39.506943941 CEST192.168.2.148.8.8.80xe36fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:39.617381096 CEST192.168.2.148.8.8.80xe36fStandard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:44.023943901 CEST192.168.2.148.8.8.80xcab7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:44.134815931 CEST192.168.2.148.8.8.80xcab7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:44.245371103 CEST192.168.2.148.8.8.80xcab7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:44.355856895 CEST192.168.2.148.8.8.80xcab7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:44.470386028 CEST192.168.2.148.8.8.80xcab7Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:50.876216888 CEST192.168.2.148.8.8.80xb767Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:50.986282110 CEST192.168.2.148.8.8.80xb767Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:51.096741915 CEST192.168.2.148.8.8.80xb767Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:51.207231045 CEST192.168.2.148.8.8.80xb767Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:37:51.317687988 CEST192.168.2.148.8.8.80xb767Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:38:00.722796917 CEST192.168.2.148.8.8.80xf202Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:38:00.833425999 CEST192.168.2.148.8.8.80xf202Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:38:00.944044113 CEST192.168.2.148.8.8.80xf202Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:38:01.054349899 CEST192.168.2.148.8.8.80xf202Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false
            Apr 25, 2024 14:38:01.164791107 CEST192.168.2.148.8.8.80xf202Standard query (0)www.sushiking.worldA (IP address)IN (0x0001)false

            System Behavior

            Start time (UTC):12:35:51
            Start date (UTC):25/04/2024
            Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            Arguments:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            File size:4956856 bytes
            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

            Start time (UTC):12:35:51
            Start date (UTC):25/04/2024
            Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            Arguments:-
            File size:4956856 bytes
            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

            Start time (UTC):12:35:51
            Start date (UTC):25/04/2024
            Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            Arguments:-
            File size:4956856 bytes
            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

            Start time (UTC):12:35:51
            Start date (UTC):25/04/2024
            Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            Arguments:-
            File size:4956856 bytes
            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

            Start time (UTC):12:35:51
            Start date (UTC):25/04/2024
            Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            Arguments:-
            File size:4956856 bytes
            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

            Start time (UTC):12:35:51
            Start date (UTC):25/04/2024
            Path:/tmp/SecuriteInfo.com.Linux.Siggen.9999.23595.2512.elf
            Arguments:-
            File size:4956856 bytes
            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1