Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
sync.arm5.elf

Overview

General Information

Sample name:sync.arm5.elf
Analysis ID:1635869
MD5:0963fa62224be7012055304b3d869fe7
SHA1:46315d5fb6753df273fde83b39897fe3bf90a3cd
SHA256:5e8fba87950b6960cca067ca9bc79a1e797e3ebeb6e57674c4e86de6f99183ef
Tags:user-elfdigest
Infos:

Detection

Score:60
Range:0 - 100

Signatures

Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Performs DNS TXT record lookups
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1635869
Start date and time:2025-03-12 03:40:15 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 51s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sync.arm5.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@15/0
  • VT rate limit hit for: dnsresolve.socialgains.cf
Command:/tmp/sync.arm5.elf
PID:6253
Exit Code:
Exit Code Info:
Killed:True
Standard Output:
main():267:We successfully started the killer module.
init_kill():436:Kill process initialized (scanner disabled)!
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6242, Parent: 4332)
  • rm (PID: 6242, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.adPqtEvgfg /tmp/tmp.PhDVFGLrB5 /tmp/tmp.EaMJjm4Eml
  • dash New Fork (PID: 6243, Parent: 4332)
  • rm (PID: 6243, Parent: 4332, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.adPqtEvgfg /tmp/tmp.PhDVFGLrB5 /tmp/tmp.EaMJjm4Eml
  • sync.arm5.elf (PID: 6253, Parent: 6176, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/sync.arm5.elf
  • cleanup
No yara matches
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2025-03-12T03:41:04.429436+010020135141A Network Trojan was detected192.168.2.23592201.0.0.153UDP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: sync.arm5.elfReversingLabs: Detection: 44%

Networking

barindex
Source: Network trafficSuricata IDS: 2013514 - Severity 1 - ET MALWARE Potential DNS Command and Control via TXT queries : 192.168.2.23:59220 -> 1.0.0.1:53
Source: global trafficTCP traffic: 192.168.2.23:57644 -> 138.197.122.150:61003
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownDNS traffic detected: query: dnsresolve.socialgains.cf replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 138.197.122.150
Source: unknownTCP traffic detected without corresponding DNS query: 138.197.122.150
Source: unknownTCP traffic detected without corresponding DNS query: 138.197.122.150
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 138.197.122.150
Source: unknownTCP traffic detected without corresponding DNS query: 138.197.122.150
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.0.0.1
Source: global trafficDNS traffic detected: DNS query: dnsresolve.socialgains.cf
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal60.evad.linELF@0/0@15/0
Source: /usr/bin/dash (PID: 6242)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.adPqtEvgfg /tmp/tmp.PhDVFGLrB5 /tmp/tmp.EaMJjm4EmlJump to behavior
Source: /usr/bin/dash (PID: 6243)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.adPqtEvgfg /tmp/tmp.PhDVFGLrB5 /tmp/tmp.EaMJjm4EmlJump to behavior
Source: /tmp/sync.arm5.elf (PID: 6255)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm5.elf (PID: 6255)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/sync.arm5.elf (PID: 6253)Queries kernel information via 'uname': Jump to behavior
Source: sync.arm5.elf, 6253.1.00007ffe40d25000.00007ffe40d46000.rw-.sdmpBinary or memory string: dx86_64/usr/bin/qemu-arm/tmp/sync.arm5.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sync.arm5.elf
Source: sync.arm5.elf, 6253.1.000055d0b9406000.000055d0b9534000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: sync.arm5.elf, 6253.1.000055d0b9406000.000055d0b9534000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: sync.arm5.elf, 6253.1.00007ffe40d25000.00007ffe40d46000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm

HIPS / PFW / Operating System Protection Evasion

barindex
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
Source: TrafficDNS traffic detected: queries for: dnsresolve.socialgains.cf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Virtualization/Sandbox Evasion
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Application Layer Protocol
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
sync.arm5.elf45%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
dnsresolve.socialgains.cf
unknown
unknowntrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    138.197.122.150
    unknownUnited States
    14061DIGITALOCEAN-ASNUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43na.elfGet hashmaliciousPrometeiBrowse
      morte.x64.elfGet hashmaliciousUnknownBrowse
        morte.arm.elfGet hashmaliciousUnknownBrowse
          re.bot.mips.elfGet hashmaliciousUnknownBrowse
            morte.arm6.elfGet hashmaliciousUnknownBrowse
              na.elfGet hashmaliciousPrometeiBrowse
                demon.x86.elfGet hashmaliciousUnknownBrowse
                  na.elfGet hashmaliciousPrometeiBrowse
                    demon.x86.elfGet hashmaliciousUnknownBrowse
                      demon.mips.elfGet hashmaliciousUnknownBrowse
                        91.189.91.42na.elfGet hashmaliciousPrometeiBrowse
                          morte.x64.elfGet hashmaliciousUnknownBrowse
                            morte.arm.elfGet hashmaliciousUnknownBrowse
                              re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                morte.arm6.elfGet hashmaliciousUnknownBrowse
                                  na.elfGet hashmaliciousPrometeiBrowse
                                    demon.x86.elfGet hashmaliciousUnknownBrowse
                                      na.elfGet hashmaliciousPrometeiBrowse
                                        demon.x86.elfGet hashmaliciousUnknownBrowse
                                          demon.mips.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            morte.x64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            morte.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            morte.arm6.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            demon.x86.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            demon.x86.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            demon.mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBna.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            morte.x64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            morte.arm.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            morte.arm6.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            demon.x86.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 91.189.91.42
                                            demon.x86.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            demon.mips.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            DIGITALOCEAN-ASNUSVirusSick.exeGet hashmaliciousUnknownBrowse
                                            • 162.243.121.232
                                            Setup.exeGet hashmaliciousUnknownBrowse
                                            • 104.248.126.225
                                            cbr.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 46.101.242.248
                                            rbot.elfGet hashmaliciousUnknownBrowse
                                            • 188.166.241.150
                                            https://gamma.app/docs/Innovative-Industrial-Fabricators-LLC-l9jiky9l79t1mba?mode=present#card-04miadc3h3yvc0wGet hashmaliciousHTMLPhisherBrowse
                                            • 178.128.55.71
                                            https://gamma.app/docs/Innovative-Industrial-Fabricators-LLC-l9jiky9l79t1mba?mode=present#card-04miadc3h3yvc0wGet hashmaliciousHTMLPhisherBrowse
                                            • 178.128.55.71
                                            cbr.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 45.55.195.230
                                            BJtPlI.dllGet hashmaliciousUnknownBrowse
                                            • 188.166.28.204
                                            https://ancollc.mrsnolas.com/Get hashmaliciousUnknownBrowse
                                            • 206.189.101.113
                                            https://ancollc.mrsnolas.com/Get hashmaliciousUnknownBrowse
                                            • 206.189.101.113
                                            INIT7CHna.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            morte.x64.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            morte.arm.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            re.bot.mips.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            morte.arm6.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            demon.x86.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            na.elfGet hashmaliciousPrometeiBrowse
                                            • 109.202.202.202
                                            demon.x86.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            demon.mips.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):6.140056197907347
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:sync.arm5.elf
                                            File size:82'860 bytes
                                            MD5:0963fa62224be7012055304b3d869fe7
                                            SHA1:46315d5fb6753df273fde83b39897fe3bf90a3cd
                                            SHA256:5e8fba87950b6960cca067ca9bc79a1e797e3ebeb6e57674c4e86de6f99183ef
                                            SHA512:137f5dc97dab10cb82bd0a18429137727079751c8008877f55537be6b59ddded04e86b8e5705470068f0949d56a435e986823bee8c1e7199abfea762ffdc83d3
                                            SSDEEP:1536:3Wn9HNC9eOq1c0aeFqxtvbbWsTlmMhkXQPqY3FjhguOgbhJNPO7dcYIJ1AW6e2r:KNC9eOq1cDeFqxtWsTlmgkXQPqY1DOg0
                                            TLSH:75832C56F8409B2AC4D0127EFE1E418D73131FB8E3DB32129D19AF307B9AA5E0E6B551
                                            File Content Preview:.ELF..............(.....l...4....A......4. ...(........p.7...........................................7...7...............@...@...@..p...............Q.td.............................@-..@............/..@-.,@...0....S..... 0....S.........../..0...0...@..../

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:ARM
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x816c
                                            Flags:0x4000002
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:4
                                            Section Header Offset:82380
                                            Section Header Size:40
                                            Number of Section Headers:12
                                            Header String Table Index:11
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x80b40xb40x140x00x6AX001
                                            .textPROGBITS0x80c80xc80x1141c0x00x6AX004
                                            .finiPROGBITS0x194e40x114e40x140x00x6AX001
                                            .rodataPROGBITS0x194f80x114f80x22180x00x2A004
                                            .ARM.exidxARM_EXIDX0x1b7100x137100xc80x00x82AL204
                                            .init_arrayINIT_ARRAY0x240040x140040x40x00x3WA004
                                            .fini_arrayFINI_ARRAY0x240080x140080x40x00x3WA004
                                            .gotPROGBITS0x240100x140100x280x40x3WA004
                                            .dataPROGBITS0x240380x140380x13c0x00x3WA008
                                            .bssNOBITS0x241780x141740x8b8c0x00x3WA008
                                            .shstrtabSTRTAB0x00x141740x580x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            EXIDX0x137100x1b7100x1b7100xc80xc84.36360x4R 0x4.ARM.exidx
                                            LOAD0x00x80000x80000x137d80x137d86.24500x5R E0x8000.init .text .fini .rodata .ARM.exidx
                                            LOAD0x140040x240040x240040x1700x8d003.99140x6RW 0x8000.init_array .fini_array .got .data .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2025-03-12T03:41:04.429436+01002013514ET MALWARE Potential DNS Command and Control via TXT queries1192.168.2.23592201.0.0.153UDP
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 12, 2025 03:41:06.133725882 CET43928443192.168.2.2391.189.91.42
                                            Mar 12, 2025 03:41:11.764919996 CET42836443192.168.2.2391.189.91.43
                                            Mar 12, 2025 03:41:12.788755894 CET4251680192.168.2.23109.202.202.202
                                            Mar 12, 2025 03:41:20.795027018 CET5764461003192.168.2.23138.197.122.150
                                            Mar 12, 2025 03:41:20.799877882 CET6100357644138.197.122.150192.168.2.23
                                            Mar 12, 2025 03:41:20.799978971 CET5764461003192.168.2.23138.197.122.150
                                            Mar 12, 2025 03:41:20.800235987 CET5764461003192.168.2.23138.197.122.150
                                            Mar 12, 2025 03:41:20.804910898 CET6100357644138.197.122.150192.168.2.23
                                            Mar 12, 2025 03:41:26.610744953 CET43928443192.168.2.2391.189.91.42
                                            Mar 12, 2025 03:41:38.896975040 CET42836443192.168.2.2391.189.91.43
                                            Mar 12, 2025 03:41:42.992311954 CET4251680192.168.2.23109.202.202.202
                                            Mar 12, 2025 03:41:49.456664085 CET5764461003192.168.2.23138.197.122.150
                                            Mar 12, 2025 03:41:49.461847067 CET6100357644138.197.122.150192.168.2.23
                                            Mar 12, 2025 03:41:49.461901903 CET5764461003192.168.2.23138.197.122.150
                                            Mar 12, 2025 03:42:07.565469980 CET43928443192.168.2.2391.189.91.42
                                            TimestampSource PortDest PortSource IPDest IP
                                            Mar 12, 2025 03:41:04.429435968 CET5922053192.168.2.231.0.0.1
                                            Mar 12, 2025 03:41:04.566381931 CET53592201.0.0.1192.168.2.23
                                            Mar 12, 2025 03:41:05.568531036 CET5937853192.168.2.238.8.4.4
                                            Mar 12, 2025 03:41:05.584244013 CET53593788.8.4.4192.168.2.23
                                            Mar 12, 2025 03:41:06.585915089 CET4770153192.168.2.238.8.4.4
                                            Mar 12, 2025 03:41:06.602552891 CET53477018.8.4.4192.168.2.23
                                            Mar 12, 2025 03:41:07.604181051 CET3957653192.168.2.231.0.0.1
                                            Mar 12, 2025 03:41:07.742079973 CET53395761.0.0.1192.168.2.23
                                            Mar 12, 2025 03:41:08.744604111 CET4796153192.168.2.231.1.1.1
                                            Mar 12, 2025 03:41:08.860898018 CET53479611.1.1.1192.168.2.23
                                            Mar 12, 2025 03:41:09.862710953 CET4080753192.168.2.231.0.0.1
                                            Mar 12, 2025 03:41:09.969402075 CET53408071.0.0.1192.168.2.23
                                            Mar 12, 2025 03:41:10.971750975 CET5950953192.168.2.231.1.1.1
                                            Mar 12, 2025 03:41:11.105971098 CET53595091.1.1.1192.168.2.23
                                            Mar 12, 2025 03:41:12.107821941 CET4969053192.168.2.231.0.0.1
                                            Mar 12, 2025 03:41:12.219579935 CET53496901.0.0.1192.168.2.23
                                            Mar 12, 2025 03:41:13.222127914 CET5622853192.168.2.231.1.1.1
                                            Mar 12, 2025 03:41:13.324872971 CET53562281.1.1.1192.168.2.23
                                            Mar 12, 2025 03:41:14.327217102 CET5937653192.168.2.238.8.4.4
                                            Mar 12, 2025 03:41:14.355659008 CET53593768.8.4.4192.168.2.23
                                            Mar 12, 2025 03:41:15.358675003 CET5395653192.168.2.231.0.0.1
                                            Mar 12, 2025 03:41:15.477442980 CET53539561.0.0.1192.168.2.23
                                            Mar 12, 2025 03:41:16.480099916 CET3485253192.168.2.238.8.8.8
                                            Mar 12, 2025 03:41:16.495152950 CET53348528.8.8.8192.168.2.23
                                            Mar 12, 2025 03:41:17.497360945 CET5481653192.168.2.238.8.4.4
                                            Mar 12, 2025 03:41:17.512887001 CET53548168.8.4.4192.168.2.23
                                            Mar 12, 2025 03:41:18.515373945 CET5840553192.168.2.231.0.0.1
                                            Mar 12, 2025 03:41:18.649385929 CET53584051.0.0.1192.168.2.23
                                            Mar 12, 2025 03:41:19.652498960 CET3545353192.168.2.231.0.0.1
                                            Mar 12, 2025 03:41:19.790580034 CET53354531.0.0.1192.168.2.23
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Mar 12, 2025 03:41:04.429435968 CET192.168.2.231.0.0.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:05.568531036 CET192.168.2.238.8.4.40x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:06.585915089 CET192.168.2.238.8.4.40x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:07.604181051 CET192.168.2.231.0.0.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:08.744604111 CET192.168.2.231.1.1.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:09.862710953 CET192.168.2.231.0.0.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:10.971750975 CET192.168.2.231.1.1.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:12.107821941 CET192.168.2.231.0.0.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:13.222127914 CET192.168.2.231.1.1.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:14.327217102 CET192.168.2.238.8.4.40x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:15.358675003 CET192.168.2.231.0.0.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:16.480099916 CET192.168.2.238.8.8.80x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:17.497360945 CET192.168.2.238.8.4.40x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:18.515373945 CET192.168.2.231.0.0.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            Mar 12, 2025 03:41:19.652498960 CET192.168.2.231.0.0.10x69e2Standard query (0)dnsresolve.socialgains.cf16IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Mar 12, 2025 03:41:04.566381931 CET1.0.0.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:05.584244013 CET8.8.4.4192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:06.602552891 CET8.8.4.4192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:07.742079973 CET1.0.0.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:08.860898018 CET1.1.1.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:09.969402075 CET1.0.0.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:11.105971098 CET1.1.1.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:12.219579935 CET1.0.0.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:13.324872971 CET1.1.1.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:14.355659008 CET8.8.4.4192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:15.477442980 CET1.0.0.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:16.495152950 CET8.8.8.8192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:17.512887001 CET8.8.4.4192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:18.649385929 CET1.0.0.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false
                                            Mar 12, 2025 03:41:19.790580034 CET1.0.0.1192.168.2.230x69e2Name error (3)dnsresolve.socialgains.cfnonenone16IN (0x0001)false

                                            System Behavior

                                            Start time (UTC):02:40:57
                                            Start date (UTC):12/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):02:40:57
                                            Start date (UTC):12/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.adPqtEvgfg /tmp/tmp.PhDVFGLrB5 /tmp/tmp.EaMJjm4Eml
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):02:40:57
                                            Start date (UTC):12/03/2025
                                            Path:/usr/bin/dash
                                            Arguments:-
                                            File size:129816 bytes
                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                            Start time (UTC):02:40:57
                                            Start date (UTC):12/03/2025
                                            Path:/usr/bin/rm
                                            Arguments:rm -f /tmp/tmp.adPqtEvgfg /tmp/tmp.PhDVFGLrB5 /tmp/tmp.EaMJjm4Eml
                                            File size:72056 bytes
                                            MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                            Start time (UTC):02:41:03
                                            Start date (UTC):12/03/2025
                                            Path:/tmp/sync.arm5.elf
                                            Arguments:/tmp/sync.arm5.elf
                                            File size:4956856 bytes
                                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                            Start time (UTC):02:41:03
                                            Start date (UTC):12/03/2025
                                            Path:/tmp/sync.arm5.elf
                                            Arguments:-
                                            File size:4956856 bytes
                                            MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1