Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
LxfGfOr9r6

Overview

General Information

Sample Name:LxfGfOr9r6
Analysis ID:679618
MD5:a6a6579914345f3a3f6aa3663ee67e11
SHA1:9b7656bb68fc7b06169e59644b3fb90d80a641f9
SHA256:8f0bc7d0a706edd460cde7cdb729814412e45b9e1c9344fba7e7eca9f1bce528
Tags:32elfmiraimotorola
Infos:

Detection

Mirai
Score:64
Range:0 - 100
Whitelisted:false

Signatures

Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Analysis Advice

Static ELF header machine description suggests that the sample might not execute correctly on this machine.
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work.
Joe Sandbox Version:35.0.0 Citrine
Analysis ID:679618
Start date and time: 06/08/202206:38:122022-08-06 06:38:12 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 39s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:LxfGfOr9r6
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal64.troj.lin@0/0@48/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/LxfGfOr9r6
PID:6228
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Connected To CNC
Standard Error:
  • system is lnxubuntu20
  • LxfGfOr9r6 (PID: 6228, Parent: 6125, MD5: cd177594338c77b895ae27c33f8f86cc) Arguments: /tmp/LxfGfOr9r6
  • cleanup
SourceRuleDescriptionAuthorStrings
LxfGfOr9r6JoeSecurity_Mirai_8Yara detected MiraiJoe Security
    SourceRuleDescriptionAuthorStrings
    dump.pcapJoeSecurity_Mirai_12Yara detected MiraiJoe Security
      SourceRuleDescriptionAuthorStrings
      6240.1.00007f097c001000.00007f097c018000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6228.1.00007f097c001000.00007f097c018000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6328.1.00007f097c001000.00007f097c018000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: LxfGfOr9r6Virustotal: Detection: 50%Perma Link
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:53436 -> 46.23.109.40:1312
            Source: /tmp/LxfGfOr9r6 (PID: 6228)Socket: 127.0.0.1::1312
            Source: /tmp/LxfGfOr9r6 (PID: 6239)Socket: 0.0.0.0::0
            Source: unknownDNS traffic detected: queries for: arcticboatz.cz
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
            Source: unknownTCP traffic detected without corresponding DNS query: 182.212.162.196
            Source: unknownTCP traffic detected without corresponding DNS query: 170.70.176.196
            Source: unknownTCP traffic detected without corresponding DNS query: 184.208.52.196
            Source: unknownTCP traffic detected without corresponding DNS query: 149.122.148.189
            Source: unknownTCP traffic detected without corresponding DNS query: 119.237.15.53
            Source: unknownTCP traffic detected without corresponding DNS query: 18.90.116.15
            Source: unknownTCP traffic detected without corresponding DNS query: 125.255.186.227
            Source: unknownTCP traffic detected without corresponding DNS query: 69.237.77.192
            Source: unknownTCP traffic detected without corresponding DNS query: 220.254.218.102
            Source: unknownTCP traffic detected without corresponding DNS query: 79.153.238.131
            Source: unknownTCP traffic detected without corresponding DNS query: 57.12.238.183
            Source: unknownTCP traffic detected without corresponding DNS query: 106.81.138.170
            Source: unknownTCP traffic detected without corresponding DNS query: 158.192.89.15
            Source: unknownTCP traffic detected without corresponding DNS query: 179.142.233.52
            Source: unknownTCP traffic detected without corresponding DNS query: 99.33.131.140
            Source: unknownTCP traffic detected without corresponding DNS query: 198.24.228.208
            Source: unknownTCP traffic detected without corresponding DNS query: 66.153.92.242
            Source: unknownTCP traffic detected without corresponding DNS query: 117.81.234.178
            Source: unknownTCP traffic detected without corresponding DNS query: 112.30.58.202
            Source: unknownTCP traffic detected without corresponding DNS query: 114.40.120.20
            Source: unknownTCP traffic detected without corresponding DNS query: 72.174.97.188
            Source: unknownTCP traffic detected without corresponding DNS query: 19.232.112.198
            Source: unknownTCP traffic detected without corresponding DNS query: 113.25.4.238
            Source: unknownTCP traffic detected without corresponding DNS query: 14.7.53.190
            Source: unknownTCP traffic detected without corresponding DNS query: 23.16.231.136
            Source: unknownTCP traffic detected without corresponding DNS query: 86.136.66.37
            Source: unknownTCP traffic detected without corresponding DNS query: 192.136.184.43
            Source: unknownTCP traffic detected without corresponding DNS query: 190.128.142.230
            Source: unknownTCP traffic detected without corresponding DNS query: 72.166.196.154
            Source: unknownTCP traffic detected without corresponding DNS query: 107.108.89.34
            Source: unknownTCP traffic detected without corresponding DNS query: 169.63.92.163
            Source: unknownTCP traffic detected without corresponding DNS query: 117.190.206.254
            Source: unknownTCP traffic detected without corresponding DNS query: 183.122.155.210
            Source: unknownTCP traffic detected without corresponding DNS query: 193.167.89.128
            Source: unknownTCP traffic detected without corresponding DNS query: 80.207.188.37
            Source: unknownTCP traffic detected without corresponding DNS query: 185.158.142.250
            Source: unknownTCP traffic detected without corresponding DNS query: 167.139.113.59
            Source: unknownTCP traffic detected without corresponding DNS query: 74.142.140.23
            Source: unknownTCP traffic detected without corresponding DNS query: 249.93.172.43
            Source: unknownTCP traffic detected without corresponding DNS query: 146.106.136.12
            Source: unknownTCP traffic detected without corresponding DNS query: 103.29.222.19
            Source: unknownTCP traffic detected without corresponding DNS query: 78.117.198.49
            Source: unknownTCP traffic detected without corresponding DNS query: 77.37.118.145
            Source: unknownTCP traffic detected without corresponding DNS query: 179.133.123.111
            Source: unknownTCP traffic detected without corresponding DNS query: 203.56.127.2
            Source: unknownTCP traffic detected without corresponding DNS query: 46.88.253.194
            Source: unknownTCP traffic detected without corresponding DNS query: 2.133.14.183
            Source: unknownTCP traffic detected without corresponding DNS query: 251.217.142.17
            Source: unknownTCP traffic detected without corresponding DNS query: 96.72.106.135
            Source: unknownTCP traffic detected without corresponding DNS query: 241.165.134.90
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: /tmp/LxfGfOr9r6 (PID: 6239)SIGKILL sent: pid: 936, result: successful
            Source: Initial sampleString containing 'busybox' found: /bin/busybox AK1K2
            Source: Initial sampleString containing 'busybox' found: /bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t
            Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -en '%s' %s %s && /bin/busybox echo -en '\x45\x43\x48\x4f\x44\x4f\x4e\x45'
            Source: Initial sampleString containing 'busybox' found: >%st && cd %s && >retrieve; >.t/bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t
            Source: Initial sampleString containing 'busybox' found: >>retrieve/bin/busybox echo -en '%s' %s %s && /bin/busybox echo -en '\x45\x43\x48\x4f\x44\x4f\x4e\x45'
            Source: classification engineClassification label: mal64.troj.lin@0/0@48/0
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/491/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/793/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/772/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/796/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/774/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/797/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/777/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/799/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/658/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/912/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/759/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/936/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/918/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/1/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/761/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/785/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/884/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/720/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/721/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/788/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/789/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/800/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/801/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/847/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6239)File opened: /proc/904/fd
            Source: /tmp/LxfGfOr9r6 (PID: 6228)Queries kernel information via 'uname':
            Source: LxfGfOr9r6, 6228.1.00005576c4867000.00005576c48ec000.rw-.sdmp, LxfGfOr9r6, 6328.1.00005576c4867000.00005576c48ec000.rw-.sdmp, LxfGfOr9r6, 6240.1.00005576c4867000.00005576c48ec000.rw-.sdmpBinary or memory string: vU!/etc/qemu-binfmt/m68k
            Source: LxfGfOr9r6, 6228.1.00007ffe5901f000.00007ffe59040000.rw-.sdmp, LxfGfOr9r6, 6328.1.00007ffe5901f000.00007ffe59040000.rw-.sdmp, LxfGfOr9r6, 6240.1.00007ffe5901f000.00007ffe59040000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
            Source: LxfGfOr9r6, 6228.1.00007ffe5901f000.00007ffe59040000.rw-.sdmp, LxfGfOr9r6, 6328.1.00007ffe5901f000.00007ffe59040000.rw-.sdmp, LxfGfOr9r6, 6240.1.00007ffe5901f000.00007ffe59040000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/LxfGfOr9r6SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/LxfGfOr9r6
            Source: LxfGfOr9r6, 6228.1.00005576c4867000.00005576c48ec000.rw-.sdmp, LxfGfOr9r6, 6328.1.00005576c4867000.00005576c48ec000.rw-.sdmp, LxfGfOr9r6, 6240.1.00005576c4867000.00005576c48ec000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: dump.pcap, type: PCAP
            Source: Yara matchFile source: LxfGfOr9r6, type: SAMPLE
            Source: Yara matchFile source: 6240.1.00007f097c001000.00007f097c018000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6228.1.00007f097c001000.00007f097c018000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6328.1.00007f097c001000.00007f097c018000.r-x.sdmp, type: MEMORY

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: dump.pcap, type: PCAP
            Source: Yara matchFile source: LxfGfOr9r6, type: SAMPLE
            Source: Yara matchFile source: 6240.1.00007f097c001000.00007f097c018000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6228.1.00007f097c001000.00007f097c018000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6328.1.00007f097c001000.00007f097c018000.r-x.sdmp, type: MEMORY
            Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
            Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
            OS Credential Dumping
            11
            Security Software Discovery
            Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
            Encrypted Channel
            Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
            Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
            Non-Standard Port
            Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
            Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
            Non-Application Layer Protocol
            Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
            Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer2
            Application Layer Protocol
            SIM Card SwapCarrier Billing Fraud
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 679618 Sample: LxfGfOr9r6 Startdate: 06/08/2022 Architecture: LINUX Score: 64 25 arcticboatz.cz 2->25 27 12.194.48.32 WORLDNET5-10US United States 2->27 29 99 other IPs or domains 2->29 31 Multi AV Scanner detection for submitted file 2->31 33 Yara detected Mirai 2->33 9 LxfGfOr9r6 2->9         started        signatures3 process4 process5 11 LxfGfOr9r6 9->11         started        13 LxfGfOr9r6 9->13         started        15 LxfGfOr9r6 9->15         started        17 LxfGfOr9r6 9->17         started        process6 19 LxfGfOr9r6 11->19         started        21 LxfGfOr9r6 11->21         started        process7 23 LxfGfOr9r6 19->23         started       
            SourceDetectionScannerLabelLink
            LxfGfOr9r651%VirustotalBrowse
            No Antivirus matches
            SourceDetectionScannerLabelLink
            arcticboatz.cz12%VirustotalBrowse
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            arcticboatz.cz
            46.23.109.40
            truetrueunknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            24.248.177.23
            unknownUnited States
            22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
            59.1.141.13
            unknownKorea Republic of
            4766KIXS-AS-KRKoreaTelecomKRfalse
            46.34.150.41
            unknownRussian Federation
            8492OBIT-ASOBITLtdRUfalse
            76.227.143.237
            unknownUnited States
            7018ATT-INTERNET4USfalse
            38.217.51.210
            unknownUnited States
            174COGENT-174USfalse
            152.71.209.240
            unknownUnited Kingdom
            786JANETJiscServicesLimitedGBfalse
            244.75.164.126
            unknownReserved
            unknownunknownfalse
            98.10.210.66
            unknownUnited States
            11351TWC-11351-NORTHEASTUSfalse
            77.11.97.25
            unknownGermany
            6805TDDE-ASN1DEfalse
            141.126.207.100
            unknownUnited States
            20115CHARTER-20115USfalse
            154.165.199.187
            unknownGhana
            30986SCANCOMGHfalse
            157.91.221.217
            unknownUnited States
            1767ILIGHT-NETUSfalse
            177.110.235.117
            unknownBrazil
            26615TIMSABRfalse
            69.131.200.183
            unknownUnited States
            4181TDS-ASUSfalse
            125.184.32.102
            unknownKorea Republic of
            17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
            83.109.79.253
            unknownNorway
            2119TELENOR-NEXTELTelenorNorgeASNOfalse
            182.67.111.205
            unknownIndia
            45609BHARTI-MOBILITY-AS-APBhartiAirtelLtdASforGPRSServicefalse
            191.160.203.230
            unknownBrazil
            26615TIMSABRfalse
            156.97.115.154
            unknownChile
            16629CTCCORPSATELEFONICAEMPRESASCLfalse
            209.216.88.25
            unknownUnited States
            22549TBDSL-01USfalse
            75.84.125.27
            unknownUnited States
            20001TWC-20001-PACWESTUSfalse
            201.239.99.189
            unknownChile
            22047VTRBANDAANCHASACLfalse
            147.189.118.50
            unknownUnited Kingdom
            786JANETJiscServicesLimitedGBfalse
            109.84.171.197
            unknownGermany
            3209VODANETInternationalIP-BackboneofVodafoneDEfalse
            149.210.216.115
            unknownNetherlands
            20857TRANSIP-ASAmsterdamtheNetherlandsNLfalse
            209.195.34.30
            unknownUnited States
            6597CBDC-6597USfalse
            53.47.79.45
            unknownGermany
            31399DAIMLER-ASITIGNGlobalNetworkDEfalse
            61.106.75.80
            unknownKorea Republic of
            9943KNCTV-ASKangNamCableTVKRfalse
            136.96.77.194
            unknownUnited States
            60311ONEFMCHfalse
            152.31.80.223
            unknownUnited States
            6559NCIHUSfalse
            143.2.114.89
            unknownUnited States
            11003PANDGUSfalse
            141.47.146.196
            unknownGermany
            553BELWUEBelWue-KoordinationEUfalse
            207.1.98.117
            unknownUnited States
            3561CENTURYLINK-LEGACY-SAVVISUSfalse
            207.114.244.71
            unknownUnited States
            15292LIFESIZEUSfalse
            19.130.7.95
            unknownUnited States
            3MIT-GATEWAYSUSfalse
            82.186.137.172
            unknownItaly
            3269ASN-IBSNAZITfalse
            31.85.38.42
            unknownUnited Kingdom
            12576EELtdGBfalse
            88.228.3.243
            unknownTurkey
            9121TTNETTRfalse
            98.53.252.212
            unknownUnited States
            7922COMCAST-7922USfalse
            177.124.101.190
            unknownBrazil
            52617WFCOMERCIODESUPRIMENTOSDEINFORMATICALTDABRfalse
            86.251.252.121
            unknownFrance
            3215FranceTelecom-OrangeFRfalse
            136.45.143.121
            unknownUnited States
            16591GOOGLE-FIBERUSfalse
            123.128.154.45
            unknownChina
            4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
            159.51.229.159
            unknownGermany
            20561AS20561-INADEfalse
            118.235.135.111
            unknownKorea Republic of
            4766KIXS-AS-KRKoreaTelecomKRfalse
            188.199.66.32
            unknownSlovenia
            5603SIOL-NETTelekomSlovenijeddSIfalse
            19.237.174.84
            unknownUnited States
            3MIT-GATEWAYSUSfalse
            13.225.136.141
            unknownUnited States
            16509AMAZON-02USfalse
            255.219.101.59
            unknownReserved
            unknownunknownfalse
            42.64.126.222
            unknownTaiwan; Republic of China (ROC)
            4249LILLY-ASUSfalse
            9.165.62.165
            unknownUnited States
            3356LEVEL3USfalse
            221.182.222.246
            unknownChina
            9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
            12.194.48.32
            unknownUnited States
            8030WORLDNET5-10USfalse
            161.51.227.255
            unknownUnited States
            16525KBRUSfalse
            1.96.96.196
            unknownKorea Republic of
            4766KIXS-AS-KRKoreaTelecomKRfalse
            99.227.190.159
            unknownCanada
            812ROGERS-COMMUNICATIONSCAfalse
            46.103.57.45
            unknownGreece
            3329HOL-GRAthensGreeceGRfalse
            116.5.97.26
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            88.89.170.32
            unknownNorway
            2119TELENOR-NEXTELTelenorNorgeASNOfalse
            69.203.119.147
            unknownUnited States
            12271TWC-12271-NYCUSfalse
            17.200.5.128
            unknownUnited States
            714APPLE-ENGINEERINGUSfalse
            104.119.246.22
            unknownUnited States
            16625AKAMAI-ASUSfalse
            193.128.174.108
            unknownUnited Kingdom
            702UUNETUSfalse
            182.20.170.123
            unknownJapan10010TOKAITOKAICommunicationsCorporationJPfalse
            128.8.55.84
            unknownUnited States
            27UMDNETUSfalse
            194.23.108.6
            unknownSweden
            3301TELIANET-SWEDENTeliaCompanySEfalse
            173.11.223.22
            unknownUnited States
            7922COMCAST-7922USfalse
            135.43.26.41
            unknownUnited States
            8030WORLDNET5-10USfalse
            199.30.171.213
            unknownUnited States
            13337EVWI-NET-01USfalse
            23.219.94.244
            unknownUnited States
            16625AKAMAI-ASUSfalse
            205.164.254.239
            unknownUnited States
            174COGENT-174USfalse
            1.190.106.84
            unknownChina
            4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
            198.163.126.0
            unknownCanada
            53443CITY-OF-WINNIPEGCAfalse
            46.152.198.116
            unknownSaudi Arabia
            35819MOBILY-ASEtihadEtisalatCompanyMobilySAfalse
            95.44.121.65
            unknownIreland
            5466EIRCOMInternetHouseIEfalse
            219.242.193.99
            unknownChina
            4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
            170.92.57.104
            unknownUnited States
            16595TOROUSfalse
            223.211.122.194
            unknownChina
            7497CSTNET-AS-APComputerNetworkInformationCenterCNfalse
            176.237.112.153
            unknownTurkey
            16135TURKCELL-ASTurkcellASTRfalse
            63.20.97.235
            unknownUnited States
            701UUNETUSfalse
            181.210.230.135
            unknownHonduras
            7727HondutelHNfalse
            92.48.31.65
            unknownSaudi Arabia
            35819MOBILY-ASEtihadEtisalatCompanyMobilySAfalse
            92.128.153.129
            unknownFrance
            3215FranceTelecom-OrangeFRfalse
            223.34.72.151
            unknownKorea Republic of
            9644SKTELECOM-NET-ASSKTelecomKRfalse
            99.119.115.88
            unknownUnited States
            7018ATT-INTERNET4USfalse
            193.227.223.120
            unknownPoland
            12966PolskieLinieLotniczeLOTPLfalse
            247.76.179.180
            unknownReserved
            unknownunknownfalse
            78.52.46.188
            unknownGermany
            6805TDDE-ASN1DEfalse
            114.240.17.20
            unknownChina
            4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
            140.235.31.103
            unknownReserved
            6932EBSCOPUBUSfalse
            101.160.35.91
            unknownAustralia
            1221ASN-TELSTRATelstraCorporationLtdAUfalse
            208.217.74.14
            unknownUnited States
            701UUNETUSfalse
            161.69.90.38
            unknownUnited States
            7754MCAFEEUSfalse
            247.134.43.201
            unknownReserved
            unknownunknownfalse
            141.79.232.208
            unknownGermany
            553BELWUEBelWue-KoordinationEUfalse
            220.167.243.17
            unknownChina
            4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
            158.225.179.58
            unknownGermany
            702UUNETUSfalse
            188.163.235.142
            unknownUkraine
            15895KSNET-ASUAfalse
            104.36.207.50
            unknownUnited States
            1640TGTELUSfalse
            98.10.209.44
            unknownUnited States
            11351TWC-11351-NORTHEASTUSfalse
            No context
            No context
            No context
            No context
            No context
            No created / dropped files found
            File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
            Entropy (8bit):6.376536609867213
            TrID:
            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
            File name:LxfGfOr9r6
            File size:92692
            MD5:a6a6579914345f3a3f6aa3663ee67e11
            SHA1:9b7656bb68fc7b06169e59644b3fb90d80a641f9
            SHA256:8f0bc7d0a706edd460cde7cdb729814412e45b9e1c9344fba7e7eca9f1bce528
            SHA512:439a63097e60c41d599568c6ab6974fb3a889b09cf6356e81405886ee6a34c49502a5c6bd12b0675bb429ea8b6a95690b581e804da95330cb8f474fb1169d89c
            SSDEEP:1536:fovGApny8PGNrq0Arhc2TppCal8tayo3i/o/C1x2bPSlbc411YyK8:fovFpy868tNpCapooK1s14bzK8
            TLSH:02935CC6BC00DD3CF84BD77A44630E09B231A3540A531B377A66FE93BD671E469A2E49
            File Content Preview:.ELF.......................D...4..h......4. ...(......................a...a....... .......a4...4...4......2|...... .dt.Q............................NV..a....da...@.N^NuNV..J9...Df>"y...L QJ.g.X.#....LN."y...L QJ.f.A.....J.g.Hy..a0N.X........DN^NuNV..N^NuN

            ELF header

            Class:ELF32
            Data:2's complement, big endian
            Version:1 (current)
            Machine:MC68000
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - System V
            ABI Version:0
            Entry Point Address:0x80000144
            Flags:0x0
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:92292
            Section Header Size:40
            Number of Section Headers:10
            Header String Table Index:9
            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
            NULL0x00x00x00x00x0000
            .initPROGBITS0x800000940x940x140x00x6AX002
            .textPROGBITS0x800000a80xa80x1403e0x00x6AX004
            .finiPROGBITS0x800140e60x140e60xe0x00x6AX002
            .rodataPROGBITS0x800140f40x140f40x203a0x00x2A002
            .ctorsPROGBITS0x800181340x161340x80x00x3WA004
            .dtorsPROGBITS0x8001813c0x1613c0x80x00x3WA004
            .dataPROGBITS0x800181480x161480x6fc0x00x3WA004
            .bssNOBITS0x800188440x168440x2b6c0x00x3WA004
            .shstrtabSTRTAB0x00x168440x3e0x00x0001
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00x800000000x800000000x1612e0x1612e6.39530x5R E0x2000.init .text .fini .rodata
            LOAD0x161340x800181340x800181340x7100x327c4.55370x6RW 0x2000.ctors .dtors .data .bss
            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
            TimestampSource PortDest PortSource IPDest IP
            Aug 6, 2022 06:38:57.955658913 CEST3648723192.168.2.23182.212.162.196
            Aug 6, 2022 06:38:57.955697060 CEST3648723192.168.2.23170.70.176.196
            Aug 6, 2022 06:38:57.955707073 CEST3648723192.168.2.23184.208.52.196
            Aug 6, 2022 06:38:57.955715895 CEST3648723192.168.2.23149.122.148.189
            Aug 6, 2022 06:38:57.955782890 CEST3648723192.168.2.23119.237.15.53
            Aug 6, 2022 06:38:57.955781937 CEST3648723192.168.2.2318.90.116.15
            Aug 6, 2022 06:38:57.955785036 CEST3648723192.168.2.23125.255.186.227
            Aug 6, 2022 06:38:57.955781937 CEST3648723192.168.2.2369.237.77.192
            Aug 6, 2022 06:38:57.955795050 CEST3648723192.168.2.23220.254.218.102
            Aug 6, 2022 06:38:57.955835104 CEST3648723192.168.2.2379.153.238.131
            Aug 6, 2022 06:38:57.955837011 CEST3648723192.168.2.2357.12.238.183
            Aug 6, 2022 06:38:57.958296061 CEST3648723192.168.2.23106.81.138.170
            Aug 6, 2022 06:38:57.958300114 CEST3648723192.168.2.23158.192.89.15
            Aug 6, 2022 06:38:57.958308935 CEST3648723192.168.2.23179.142.233.52
            Aug 6, 2022 06:38:57.958348989 CEST3648723192.168.2.2399.33.131.140
            Aug 6, 2022 06:38:57.958355904 CEST3648723192.168.2.23198.24.228.208
            Aug 6, 2022 06:38:57.958357096 CEST3648723192.168.2.2366.153.92.242
            Aug 6, 2022 06:38:57.958388090 CEST3648723192.168.2.23117.81.234.178
            Aug 6, 2022 06:38:57.958399057 CEST3648723192.168.2.23112.30.58.202
            Aug 6, 2022 06:38:57.958405972 CEST3648723192.168.2.23114.40.120.20
            Aug 6, 2022 06:38:57.958434105 CEST3648723192.168.2.2372.174.97.188
            Aug 6, 2022 06:38:57.958441973 CEST3648723192.168.2.2319.232.112.198
            Aug 6, 2022 06:38:57.958462954 CEST3648723192.168.2.23113.25.4.238
            Aug 6, 2022 06:38:57.958467007 CEST3648723192.168.2.2314.7.53.190
            Aug 6, 2022 06:38:57.958471060 CEST3648723192.168.2.2323.16.231.136
            Aug 6, 2022 06:38:57.958492994 CEST3648723192.168.2.2386.136.66.37
            Aug 6, 2022 06:38:57.958515882 CEST3648723192.168.2.23192.136.184.43
            Aug 6, 2022 06:38:57.958522081 CEST3648723192.168.2.23190.128.142.230
            Aug 6, 2022 06:38:57.958561897 CEST3648723192.168.2.2372.166.196.154
            Aug 6, 2022 06:38:57.958561897 CEST3648723192.168.2.23107.108.89.34
            Aug 6, 2022 06:38:57.958584070 CEST3648723192.168.2.23169.63.92.163
            Aug 6, 2022 06:38:57.958584070 CEST3648723192.168.2.23117.190.206.254
            Aug 6, 2022 06:38:57.958595991 CEST3648723192.168.2.23183.122.155.210
            Aug 6, 2022 06:38:57.958614111 CEST3648723192.168.2.23193.167.89.128
            Aug 6, 2022 06:38:57.958616018 CEST3648723192.168.2.2380.207.188.37
            Aug 6, 2022 06:38:57.958653927 CEST3648723192.168.2.23185.158.142.250
            Aug 6, 2022 06:38:57.958661079 CEST3648723192.168.2.23167.139.113.59
            Aug 6, 2022 06:38:57.958683968 CEST3648723192.168.2.2374.142.140.23
            Aug 6, 2022 06:38:57.958709955 CEST3648723192.168.2.23249.93.172.43
            Aug 6, 2022 06:38:57.958720922 CEST3648723192.168.2.23146.106.136.12
            Aug 6, 2022 06:38:57.958728075 CEST3648723192.168.2.23103.29.222.19
            Aug 6, 2022 06:38:57.958739042 CEST3648723192.168.2.2378.117.198.49
            Aug 6, 2022 06:38:57.958748102 CEST3648723192.168.2.2377.37.118.145
            Aug 6, 2022 06:38:57.958755016 CEST3648723192.168.2.23179.133.123.111
            Aug 6, 2022 06:38:57.958764076 CEST3648723192.168.2.23203.56.127.2
            Aug 6, 2022 06:38:57.958766937 CEST3648723192.168.2.2346.88.253.194
            Aug 6, 2022 06:38:57.958774090 CEST3648723192.168.2.232.133.14.183
            Aug 6, 2022 06:38:57.958785057 CEST3648723192.168.2.23251.217.142.17
            Aug 6, 2022 06:38:57.958787918 CEST3648723192.168.2.2396.72.106.135
            Aug 6, 2022 06:38:57.958806038 CEST3648723192.168.2.23241.165.134.90
            Aug 6, 2022 06:38:57.958807945 CEST3648723192.168.2.23211.194.86.215
            Aug 6, 2022 06:38:57.958812952 CEST3648723192.168.2.23152.176.187.140
            Aug 6, 2022 06:38:57.958817005 CEST3648723192.168.2.23242.241.39.108
            Aug 6, 2022 06:38:57.958823919 CEST3648723192.168.2.23217.167.168.91
            Aug 6, 2022 06:38:57.958827019 CEST3648723192.168.2.23218.221.110.57
            Aug 6, 2022 06:38:57.958833933 CEST3648723192.168.2.2371.68.84.50
            Aug 6, 2022 06:38:57.958837032 CEST3648723192.168.2.2327.248.249.120
            Aug 6, 2022 06:38:57.958848953 CEST3648723192.168.2.23184.171.39.117
            Aug 6, 2022 06:38:57.958857059 CEST3648723192.168.2.23198.44.240.44
            Aug 6, 2022 06:38:57.958863020 CEST3648723192.168.2.23185.33.216.213
            Aug 6, 2022 06:38:57.958864927 CEST3648723192.168.2.2370.206.143.91
            Aug 6, 2022 06:38:57.958873034 CEST3648723192.168.2.23195.217.245.83
            Aug 6, 2022 06:38:57.958877087 CEST3648723192.168.2.23141.95.171.11
            Aug 6, 2022 06:38:57.958919048 CEST3648723192.168.2.23242.106.250.22
            Aug 6, 2022 06:38:57.958924055 CEST3648723192.168.2.23146.47.171.166
            Aug 6, 2022 06:38:57.958925962 CEST3648723192.168.2.23120.135.163.189
            Aug 6, 2022 06:38:57.958925962 CEST3648723192.168.2.23189.128.177.15
            Aug 6, 2022 06:38:57.958933115 CEST3648723192.168.2.23181.10.49.78
            Aug 6, 2022 06:38:57.958933115 CEST3648723192.168.2.23158.78.225.64
            Aug 6, 2022 06:38:57.958935022 CEST3648723192.168.2.2348.13.147.223
            Aug 6, 2022 06:38:57.958935976 CEST3648723192.168.2.2366.39.235.201
            Aug 6, 2022 06:38:57.958936930 CEST3648723192.168.2.2378.201.23.72
            Aug 6, 2022 06:38:57.958954096 CEST3648723192.168.2.23156.4.59.193
            Aug 6, 2022 06:38:57.958959103 CEST3648723192.168.2.23113.164.20.252
            Aug 6, 2022 06:38:57.958971024 CEST3648723192.168.2.23219.129.44.109
            Aug 6, 2022 06:38:57.958998919 CEST3648723192.168.2.2358.22.16.254
            Aug 6, 2022 06:38:57.959008932 CEST3648723192.168.2.23189.92.201.149
            Aug 6, 2022 06:38:57.959022045 CEST3648723192.168.2.23192.171.208.167
            Aug 6, 2022 06:38:57.959036112 CEST3648723192.168.2.2342.133.27.209
            Aug 6, 2022 06:38:57.959042072 CEST3648723192.168.2.2313.7.215.209
            Aug 6, 2022 06:38:57.959048986 CEST3648723192.168.2.232.169.224.146
            Aug 6, 2022 06:38:57.959100008 CEST3648723192.168.2.2396.114.165.207
            Aug 6, 2022 06:38:57.959239960 CEST3648723192.168.2.23202.162.220.182
            Aug 6, 2022 06:38:57.959244967 CEST3648723192.168.2.2347.180.130.15
            Aug 6, 2022 06:38:57.959278107 CEST3648723192.168.2.23167.139.146.0
            Aug 6, 2022 06:38:57.959278107 CEST3648723192.168.2.23241.136.125.129
            Aug 6, 2022 06:38:57.959285021 CEST3648723192.168.2.2366.241.34.93
            Aug 6, 2022 06:38:57.959286928 CEST3648723192.168.2.2395.255.140.214
            Aug 6, 2022 06:38:57.959290028 CEST3648723192.168.2.2381.166.95.154
            Aug 6, 2022 06:38:57.959292889 CEST3648723192.168.2.2397.4.105.230
            Aug 6, 2022 06:38:57.959295034 CEST3648723192.168.2.23178.248.178.111
            Aug 6, 2022 06:38:57.959306002 CEST3648723192.168.2.2318.22.78.29
            Aug 6, 2022 06:38:57.959327936 CEST3648723192.168.2.2389.250.139.124
            Aug 6, 2022 06:38:57.959328890 CEST3648723192.168.2.23222.136.123.173
            Aug 6, 2022 06:38:57.959336042 CEST3648723192.168.2.2337.88.249.190
            Aug 6, 2022 06:38:57.959340096 CEST3648723192.168.2.23173.106.118.74
            Aug 6, 2022 06:38:57.959362030 CEST3648723192.168.2.23255.41.217.232
            Aug 6, 2022 06:38:57.959369898 CEST3648723192.168.2.23128.254.28.173
            Aug 6, 2022 06:38:57.959382057 CEST3648723192.168.2.23175.93.129.171
            Aug 6, 2022 06:38:57.959383965 CEST3648723192.168.2.23148.54.47.45
            TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
            Aug 6, 2022 06:38:58.015841961 CEST192.168.2.238.8.8.80xc902Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:03.063251019 CEST192.168.2.238.8.8.80xa55cStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:12.112843037 CEST192.168.2.238.8.8.80x4b70Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:20.161328077 CEST192.168.2.238.8.8.80x7193Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:28.210354090 CEST192.168.2.238.8.8.80x1dbdStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:34.258898020 CEST192.168.2.238.8.8.80x102Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:37.308526039 CEST192.168.2.238.8.8.80x19e1Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:39.358630896 CEST192.168.2.238.8.8.80x8660Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:44.408814907 CEST192.168.2.238.8.8.80x3d48Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:47.457130909 CEST192.168.2.238.8.8.80x1976Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:48.544106007 CEST192.168.2.238.8.8.80x4e24Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:39:51.592320919 CEST192.168.2.238.8.8.80x7b4dStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:01.638744116 CEST192.168.2.238.8.8.80xaffbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:07.692687988 CEST192.168.2.238.8.8.80x27c2Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:13.758572102 CEST192.168.2.238.8.8.80xfaefStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:14.807538986 CEST192.168.2.238.8.8.80xc2a0Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:19.810678005 CEST192.168.2.238.8.8.80xc2a0Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:24.898312092 CEST192.168.2.238.8.8.80x7236Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:30.944502115 CEST192.168.2.238.8.8.80x94f6Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:32.990680933 CEST192.168.2.238.8.8.80x42d7Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:35.037621021 CEST192.168.2.238.8.8.80xfef0Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:43.089071989 CEST192.168.2.238.8.8.80x9baStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:48.137229919 CEST192.168.2.238.8.8.80x50cbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:54.185642004 CEST192.168.2.238.8.8.80x1341Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:56.233990908 CEST192.168.2.238.8.8.80xef77Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:40:57.288228035 CEST192.168.2.238.8.8.80x1094Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:02.414253950 CEST192.168.2.238.8.8.80xe0afStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:12.473647118 CEST192.168.2.238.8.8.80xb651Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:19.522330999 CEST192.168.2.238.8.8.80x5aa5Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:25.568595886 CEST192.168.2.238.8.8.80xa4dbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:30.617033958 CEST192.168.2.238.8.8.80xe260Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:39.676574945 CEST192.168.2.238.8.8.80x8841Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:46.139307022 CEST192.168.2.238.8.8.80xc902Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:48.738687992 CEST192.168.2.238.8.8.80x2d47Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:49.787352085 CEST192.168.2.238.8.8.80x3382Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:51.188376904 CEST192.168.2.238.8.8.80xa55cStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:41:56.933408022 CEST192.168.2.238.8.8.80xaa1fStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:00.237283945 CEST192.168.2.238.8.8.80x4b70Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:00.987062931 CEST192.168.2.238.8.8.80xbd5bStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:04.063508034 CEST192.168.2.238.8.8.80xe062Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:08.291137934 CEST192.168.2.238.8.8.80x7193Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:13.409574986 CEST192.168.2.238.8.8.80x78d2Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:17.357780933 CEST192.168.2.238.8.8.80x1dbdStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:21.549640894 CEST192.168.2.238.8.8.80x46d1Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:24.435219049 CEST192.168.2.238.8.8.80x102Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:26.901320934 CEST192.168.2.238.8.8.80xe40cStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:27.482821941 CEST192.168.2.238.8.8.80x19e1Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            Aug 6, 2022 06:42:29.594454050 CEST192.168.2.238.8.8.80x8660Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
            Aug 6, 2022 06:38:58.033246040 CEST8.8.8.8192.168.2.230xc902No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:03.083034992 CEST8.8.8.8192.168.2.230xa55cNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:12.130494118 CEST8.8.8.8192.168.2.230x4b70No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:20.180969000 CEST8.8.8.8192.168.2.230x7193No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:28.229773045 CEST8.8.8.8192.168.2.230x1dbdNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:34.277985096 CEST8.8.8.8192.168.2.230x102No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:37.328144073 CEST8.8.8.8192.168.2.230x19e1No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:39.378031969 CEST8.8.8.8192.168.2.230x8660No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:44.428303003 CEST8.8.8.8192.168.2.230x3d48No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:47.476232052 CEST8.8.8.8192.168.2.230x1976No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:48.563440084 CEST8.8.8.8192.168.2.230x4e24No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:39:51.610304117 CEST8.8.8.8192.168.2.230x7b4dNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:01.656316996 CEST8.8.8.8192.168.2.230xaffbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:07.729549885 CEST8.8.8.8192.168.2.230x27c2No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:13.778358936 CEST8.8.8.8192.168.2.230xfaefNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:19.830240011 CEST8.8.8.8192.168.2.230xc2a0No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:24.915445089 CEST8.8.8.8192.168.2.230x7236No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:30.962285042 CEST8.8.8.8192.168.2.230x94f6No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:33.008429050 CEST8.8.8.8192.168.2.230x42d7No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:35.057518005 CEST8.8.8.8192.168.2.230xfef0No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:43.107075930 CEST8.8.8.8192.168.2.230x9baNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:48.156894922 CEST8.8.8.8192.168.2.230x50cbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:54.205457926 CEST8.8.8.8192.168.2.230x1341No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:56.252594948 CEST8.8.8.8192.168.2.230xef77No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:40:57.308721066 CEST8.8.8.8192.168.2.230x1094No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:02.442663908 CEST8.8.8.8192.168.2.230xe0afNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:12.491463900 CEST8.8.8.8192.168.2.230xb651No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:19.539896011 CEST8.8.8.8192.168.2.230x5aa5No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:25.588309050 CEST8.8.8.8192.168.2.230xa4dbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:30.636569023 CEST8.8.8.8192.168.2.230xe260No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:39.695657969 CEST8.8.8.8192.168.2.230x8841No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:46.158691883 CEST8.8.8.8192.168.2.230xc902No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:48.758279085 CEST8.8.8.8192.168.2.230x2d47No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:49.804258108 CEST8.8.8.8192.168.2.230x3382No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:51.208085060 CEST8.8.8.8192.168.2.230xa55cNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:41:56.952830076 CEST8.8.8.8192.168.2.230xaa1fNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:00.256917953 CEST8.8.8.8192.168.2.230x4b70No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:01.006757975 CEST8.8.8.8192.168.2.230xbd5bNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:04.080832958 CEST8.8.8.8192.168.2.230xe062No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:08.310482025 CEST8.8.8.8192.168.2.230x7193No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:13.428618908 CEST8.8.8.8192.168.2.230x78d2No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:17.375529051 CEST8.8.8.8192.168.2.230x1dbdNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:21.568782091 CEST8.8.8.8192.168.2.230x46d1No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:24.454607010 CEST8.8.8.8192.168.2.230x102No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:26.920907021 CEST8.8.8.8192.168.2.230xe40cNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:27.502365112 CEST8.8.8.8192.168.2.230x19e1No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
            Aug 6, 2022 06:42:29.613771915 CEST8.8.8.8192.168.2.230x8660No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)

            System Behavior

            Start time:06:38:57
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:/tmp/LxfGfOr9r6
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc
            Start time:06:38:57
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:n/a
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc
            Start time:06:38:57
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:n/a
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc
            Start time:06:38:57
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:n/a
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc
            Start time:06:38:57
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:n/a
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc
            Start time:06:38:57
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:n/a
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc
            Start time:06:41:45
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:n/a
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc
            Start time:06:38:57
            Start date:06/08/2022
            Path:/tmp/LxfGfOr9r6
            Arguments:n/a
            File size:4463432 bytes
            MD5 hash:cd177594338c77b895ae27c33f8f86cc