Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
SSBFSIj3wk

Overview

General Information

Sample Name:SSBFSIj3wk
Analysis ID:679620
MD5:1beaa289a2e5c583a8ade22549a87e45
SHA1:7dcf5380b1d43e2fd3d15e32373edd635427229c
SHA256:63992f68aa03ce566fb5d9cbab680a1c3e04ef381081b51f219461da771cba62
Tags:32elfintelmirai
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Yara signature match
Sample has stripped symbol table
Enumerates processes within the "proc" file system
Detected TCP or UDP traffic on non-standard ports
Sample tries to kill a process (SIGKILL)
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Joe Sandbox Version:35.0.0 Citrine
Analysis ID:679620
Start date and time: 06/08/202206:47:132022-08-06 06:47:13 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 30s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:SSBFSIj3wk
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal68.troj.lin@0/0@43/0
  • Report size exceeded maximum capacity and may have missing network information.
  • TCP Packets have been reduced to 100
Command:/tmp/SSBFSIj3wk
PID:6228
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Connected To CNC
Standard Error:
  • system is lnxubuntu20
  • SSBFSIj3wk (PID: 6228, Parent: 6123, MD5: 1beaa289a2e5c583a8ade22549a87e45) Arguments: /tmp/SSBFSIj3wk
  • cleanup
SourceRuleDescriptionAuthorStrings
SSBFSIj3wkJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    SSBFSIj3wkLinux_Trojan_Mirai_b14f4c5dunknownunknown
    • 0x4c00:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    • 0x4c50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
    SSBFSIj3wkLinux_Trojan_Mirai_24c5b7d6unknownunknown
    • 0xad72:$a: 54 38 1C 80 FA 3E 74 25 80 FA 3A 74 20 80 FA 24 74 1B 80 FA 23
    SSBFSIj3wkLinux_Trojan_Mirai_88de437funknownunknown
    • 0xc722:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
    SSBFSIj3wkLinux_Trojan_Mirai_ae9d0fa6unknownunknown
    • 0xd82:$a: 83 EC 04 8A 44 24 18 8B 5C 24 14 88 44 24 03 8A 44 24 10 25 FF 00
    Click to see the 2 entries
    SourceRuleDescriptionAuthorStrings
    6228.1.0000000008048000.000000000805c000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6228.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x4c00:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      • 0x4c50:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      6228.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_24c5b7d6unknownunknown
      • 0xad72:$a: 54 38 1C 80 FA 3E 74 25 80 FA 3A 74 20 80 FA 24 74 1B 80 FA 23
      6228.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
      • 0xc722:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
      6228.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_ae9d0fa6unknownunknown
      • 0xd82:$a: 83 EC 04 8A 44 24 18 8B 5C 24 14 88 44 24 03 8A 44 24 10 25 FF 00
      Click to see the 16 entries
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: SSBFSIj3wkVirustotal: Detection: 53%Perma Link
      Source: SSBFSIj3wkReversingLabs: Detection: 62%
      Source: SSBFSIj3wkJoe Sandbox ML: detected
      Source: global trafficTCP traffic: 192.168.2.23:53436 -> 46.23.109.40:1312
      Source: unknownDNS traffic detected: queries for: arcticboatz.cz
      Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55578
      Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
      Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
      Source: unknownTCP traffic detected without corresponding DNS query: 68.195.50.67
      Source: unknownTCP traffic detected without corresponding DNS query: 162.167.117.199
      Source: unknownTCP traffic detected without corresponding DNS query: 202.81.32.67
      Source: unknownTCP traffic detected without corresponding DNS query: 86.40.59.64
      Source: unknownTCP traffic detected without corresponding DNS query: 147.74.30.71
      Source: unknownTCP traffic detected without corresponding DNS query: 76.17.6.164
      Source: unknownTCP traffic detected without corresponding DNS query: 69.86.168.58
      Source: unknownTCP traffic detected without corresponding DNS query: 47.108.79.178
      Source: unknownTCP traffic detected without corresponding DNS query: 87.213.96.138
      Source: unknownTCP traffic detected without corresponding DNS query: 58.100.198.137
      Source: unknownTCP traffic detected without corresponding DNS query: 76.246.243.225
      Source: unknownTCP traffic detected without corresponding DNS query: 186.83.62.48
      Source: unknownTCP traffic detected without corresponding DNS query: 217.191.83.36
      Source: unknownTCP traffic detected without corresponding DNS query: 13.174.202.182
      Source: unknownTCP traffic detected without corresponding DNS query: 204.88.189.98
      Source: unknownTCP traffic detected without corresponding DNS query: 107.173.137.9
      Source: unknownTCP traffic detected without corresponding DNS query: 197.24.15.249
      Source: unknownTCP traffic detected without corresponding DNS query: 42.17.65.121
      Source: unknownTCP traffic detected without corresponding DNS query: 96.187.111.50
      Source: unknownTCP traffic detected without corresponding DNS query: 32.216.5.41
      Source: unknownTCP traffic detected without corresponding DNS query: 192.138.244.88
      Source: unknownTCP traffic detected without corresponding DNS query: 213.175.18.187
      Source: unknownTCP traffic detected without corresponding DNS query: 153.235.57.169
      Source: unknownTCP traffic detected without corresponding DNS query: 68.76.31.148
      Source: unknownTCP traffic detected without corresponding DNS query: 41.26.95.169
      Source: unknownTCP traffic detected without corresponding DNS query: 53.200.235.95
      Source: unknownTCP traffic detected without corresponding DNS query: 246.102.69.11
      Source: unknownTCP traffic detected without corresponding DNS query: 46.69.90.219
      Source: unknownTCP traffic detected without corresponding DNS query: 46.219.79.180
      Source: unknownTCP traffic detected without corresponding DNS query: 165.221.112.169
      Source: unknownTCP traffic detected without corresponding DNS query: 96.4.121.61
      Source: unknownTCP traffic detected without corresponding DNS query: 27.96.57.37
      Source: unknownTCP traffic detected without corresponding DNS query: 113.155.135.253
      Source: unknownTCP traffic detected without corresponding DNS query: 37.115.7.130
      Source: unknownTCP traffic detected without corresponding DNS query: 156.254.243.153
      Source: unknownTCP traffic detected without corresponding DNS query: 82.84.103.132
      Source: unknownTCP traffic detected without corresponding DNS query: 46.50.141.75
      Source: unknownTCP traffic detected without corresponding DNS query: 70.21.242.15
      Source: unknownTCP traffic detected without corresponding DNS query: 171.189.146.162
      Source: unknownTCP traffic detected without corresponding DNS query: 91.215.171.38
      Source: unknownTCP traffic detected without corresponding DNS query: 105.113.252.83
      Source: unknownTCP traffic detected without corresponding DNS query: 98.242.35.32
      Source: unknownTCP traffic detected without corresponding DNS query: 254.246.149.1
      Source: unknownTCP traffic detected without corresponding DNS query: 98.71.162.169
      Source: unknownTCP traffic detected without corresponding DNS query: 163.190.194.226
      Source: unknownTCP traffic detected without corresponding DNS query: 12.221.134.193
      Source: unknownTCP traffic detected without corresponding DNS query: 178.226.172.132
      Source: unknownTCP traffic detected without corresponding DNS query: 8.195.127.199
      Source: unknownTCP traffic detected without corresponding DNS query: 88.234.97.251

      System Summary

      barindex
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_24c5b7d6 Author: unknown
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_24c5b7d6 Author: unknown
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_24c5b7d6 Author: unknown
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_24c5b7d6 Author: unknown
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_24c5b7d6 reference_sample = 7c2f8ba2d6f1e67d1b4a3a737a449429c322d945d49dafb9e8c66608ab2154c4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3411b624f02dd1c7a0e663f1f119c8d5e47a81892bb7c445b7695c605b0b8ee2, id = 24c5b7d6-1aa8-4d8e-9983-c7234f57c3de, last_modified = 2021-09-16
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: SSBFSIj3wk, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_24c5b7d6 reference_sample = 7c2f8ba2d6f1e67d1b4a3a737a449429c322d945d49dafb9e8c66608ab2154c4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3411b624f02dd1c7a0e663f1f119c8d5e47a81892bb7c445b7695c605b0b8ee2, id = 24c5b7d6-1aa8-4d8e-9983-c7234f57c3de, last_modified = 2021-09-16
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_24c5b7d6 reference_sample = 7c2f8ba2d6f1e67d1b4a3a737a449429c322d945d49dafb9e8c66608ab2154c4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3411b624f02dd1c7a0e663f1f119c8d5e47a81892bb7c445b7695c605b0b8ee2, id = 24c5b7d6-1aa8-4d8e-9983-c7234f57c3de, last_modified = 2021-09-16
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_24c5b7d6 reference_sample = 7c2f8ba2d6f1e67d1b4a3a737a449429c322d945d49dafb9e8c66608ab2154c4, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3411b624f02dd1c7a0e663f1f119c8d5e47a81892bb7c445b7695c605b0b8ee2, id = 24c5b7d6-1aa8-4d8e-9983-c7234f57c3de, last_modified = 2021-09-16
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
      Source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: /tmp/SSBFSIj3wk (PID: 6234)SIGKILL sent: pid: 936, result: successful
      Source: Initial sampleString containing 'busybox' found: /bin/busybox AK1K2
      Source: Initial sampleString containing 'busybox' found: /bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t
      Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -en '%s' %s %s && /bin/busybox echo -en '\x45\x43\x48\x4f\x44\x4f\x4e\x45'
      Source: Initial sampleString containing 'busybox' found: Connected To CNCrootarm5arm6arm7oginsernamevrdvsccountenterasswordusyboxulti-callhelp$#~nvalidailedncorrecteniedrroroodbyebad: applet not found/var//dev//mnt//var/run//var/tmp//dev/netslink//dev/shm//bin//etc//boot//usr//sys/xc3511xmhdipcklv123hi3518jvbzd1234562wj9fsa2>%st && cd %s && >retrieve; >.t/bin/busybox cp /bin/busybox retrieve && >retrieve && /bin/busybox chmod 777 retrieve && /bin/busybox cp /bin/busybox .t && >.t && /bin/busybox chmod 777 .t
      Source: classification engineClassification label: mal68.troj.lin@0/0@43/0
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/6234/exe
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/491/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/793/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/772/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/796/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/774/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/797/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/777/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/799/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/658/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/912/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/759/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/936/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/918/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/1/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/761/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/785/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/884/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/720/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/721/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/788/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/789/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/800/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/801/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/847/fd
      Source: /tmp/SSBFSIj3wk (PID: 6234)File opened: /proc/904/fd

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: SSBFSIj3wk, type: SAMPLE
      Source: Yara matchFile source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: SSBFSIj3wk, type: SAMPLE
      Source: Yara matchFile source: 6228.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6318.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
      Source: Yara matchFile source: 6235.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
      Valid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
      OS Credential Dumping
      System Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network Medium1
      Encrypted Channel
      Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
      Non-Standard Port
      Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
      Non-Application Layer Protocol
      Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer2
      Application Layer Protocol
      SIM Card SwapCarrier Billing Fraud
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 679620 Sample: SSBFSIj3wk Startdate: 06/08/2022 Architecture: LINUX Score: 68 25 arcticboatz.cz 2->25 27 94.142.35.113, 23 ZAIN-JO Jordan 2->27 29 99 other IPs or domains 2->29 31 Malicious sample detected (through community Yara rule) 2->31 33 Multi AV Scanner detection for submitted file 2->33 35 Yara detected Mirai 2->35 37 Machine Learning detection for sample 2->37 9 SSBFSIj3wk 2->9         started        signatures3 process4 process5 11 SSBFSIj3wk 9->11         started        13 SSBFSIj3wk 9->13         started        15 SSBFSIj3wk 9->15         started        17 SSBFSIj3wk 9->17         started        process6 19 SSBFSIj3wk 11->19         started        21 SSBFSIj3wk 11->21         started        process7 23 SSBFSIj3wk 19->23         started       
      SourceDetectionScannerLabelLink
      SSBFSIj3wk54%VirustotalBrowse
      SSBFSIj3wk62%ReversingLabsLinux.Trojan.Mirai
      SSBFSIj3wk100%Joe Sandbox ML
      No Antivirus matches
      SourceDetectionScannerLabelLink
      arcticboatz.cz12%VirustotalBrowse
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      arcticboatz.cz
      46.23.109.40
      truetrueunknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      44.103.235.54
      unknownUnited States
      54869ROCKCOM-COUSfalse
      83.32.29.72
      unknownSpain
      3352TELEFONICA_DE_ESPANAESfalse
      218.134.63.159
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      240.153.133.162
      unknownReserved
      unknownunknownfalse
      153.177.50.112
      unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
      188.97.99.57
      unknownGermany
      3209VODANETInternationalIP-BackboneofVodafoneDEfalse
      250.168.161.155
      unknownReserved
      unknownunknownfalse
      163.208.145.140
      unknownJapan7502IP-KYOTOAdvancedSoftwareTechnologyManagementResearchfalse
      95.131.166.89
      unknownSpain
      43402CABLEMURCIA-ASESfalse
      156.147.203.4
      unknownKorea Republic of
      4668LGNET-AS-KRLGCNSKRfalse
      255.165.202.25
      unknownReserved
      unknownunknownfalse
      63.167.147.153
      unknownUnited States
      1239SPRINTLINKUSfalse
      73.152.2.152
      unknownUnited States
      7922COMCAST-7922USfalse
      59.46.183.89
      unknownChina
      134762CHINANET-LIAONING-DALIAN-MANCHINANETLiaoningprovinceDalifalse
      73.184.255.191
      unknownUnited States
      7922COMCAST-7922USfalse
      207.252.205.231
      unknownUnited States
      10844VASTNETUSfalse
      57.81.243.103
      unknownBelgium
      51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
      37.87.36.218
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      95.205.71.207
      unknownSweden
      3301TELIANET-SWEDENTeliaCompanySEfalse
      200.231.73.25
      unknownBrazil
      4230CLAROSABRfalse
      241.184.140.21
      unknownReserved
      unknownunknownfalse
      218.134.15.254
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      58.192.126.26
      unknownChina
      4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
      255.235.190.240
      unknownReserved
      unknownunknownfalse
      143.0.247.198
      unknownArgentina
      12150COTELCAMARfalse
      154.212.36.122
      unknownSeychelles
      54600PEGTECHINCUSfalse
      223.115.154.186
      unknownChina
      9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
      116.60.113.195
      unknownChina
      4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
      61.153.236.127
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      195.70.86.194
      unknownUnited Kingdom
      5413AS5413GBfalse
      203.139.210.85
      unknownJapan7522STCNSTNetIncorporatedJPfalse
      166.135.50.33
      unknownUnited States
      20057ATT-MOBILITY-LLC-AS20057USfalse
      100.202.107.221
      unknownUnited States
      21928T-MOBILE-AS21928USfalse
      94.142.35.113
      unknownJordan
      48832ZAIN-JOfalse
      157.5.26.205
      unknownunknown
      7671MCNETNTTSmartConnectCorporationJPfalse
      141.251.187.126
      unknownUnited States
      137ASGARRConsortiumGARREUfalse
      169.23.102.21
      unknownUnited States
      37611AfrihostZAfalse
      24.161.107.219
      unknownUnited States
      12271TWC-12271-NYCUSfalse
      37.160.127.180
      unknownFrance
      51207FREEMFRfalse
      91.203.191.63
      unknownRussian Federation
      47133PROSERVIS-ASRUfalse
      171.2.26.208
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      109.171.7.56
      unknownRussian Federation
      15774TTK-RTLRetailRUfalse
      75.140.122.162
      unknownUnited States
      20115CHARTER-20115USfalse
      254.230.35.232
      unknownReserved
      unknownunknownfalse
      133.84.38.220
      unknownJapan55904KOGAKUIN-ASKOGAKUINUniversityJPfalse
      88.7.59.13
      unknownSpain
      3352TELEFONICA_DE_ESPANAESfalse
      172.185.86.22
      unknownUnited States
      7018ATT-INTERNET4USfalse
      164.57.104.9
      unknownUnited States
      4583WESTPUB-AUSfalse
      216.112.242.9
      unknownUnited States
      16908ATRGNJ01USfalse
      17.18.116.47
      unknownUnited States
      714APPLE-ENGINEERINGUSfalse
      192.90.239.37
      unknownUnited States
      6BULL-HNUSfalse
      101.192.60.126
      unknownChina
      58519CHINATELECOM-CTCLOUDCloudComputingCorporationCNfalse
      108.163.30.102
      unknownUnited States
      394855STRATUS-VIDEOUSfalse
      27.231.45.60
      unknownJapan9605DOCOMONTTDOCOMOINCJPfalse
      209.164.3.242
      unknownUnited States
      20021LNH-INCUSfalse
      123.50.17.4
      unknownJapan10013FBDCFreeBitCoLtdJPfalse
      14.71.104.161
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      113.243.219.18
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      40.48.11.142
      unknownUnited States
      4249LILLY-ASUSfalse
      241.67.85.216
      unknownReserved
      unknownunknownfalse
      208.239.240.221
      unknownUnited States
      13768COGECO-PEER1CAfalse
      113.109.71.70
      unknownChina
      4816CHINANET-IDC-GDChinaTelecomGroupCNfalse
      183.155.198.11
      unknownChina
      4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
      148.9.92.66
      unknownUnited States
      3745NTTDATA-SERVICES-AS2USfalse
      253.171.215.12
      unknownReserved
      unknownunknownfalse
      70.155.118.151
      unknownUnited States
      7018ATT-INTERNET4USfalse
      68.167.229.184
      unknownUnited States
      18566MEGAPATH5-USfalse
      171.6.150.42
      unknownThailand
      45758TRIPLETNET-AS-APTripleTInternetTripleTBroadbandTHfalse
      168.171.222.80
      unknownUnited States
      26675REGIONIVESCUSfalse
      195.35.225.223
      unknownNetherlands
      33915TNF-ASNLfalse
      186.18.44.202
      unknownArgentina
      27747TelecentroSAARfalse
      60.23.236.124
      unknownChina
      4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
      190.169.220.210
      unknownVenezuela
      19192UniversidadCentraldeVenezuelaVEfalse
      37.64.35.82
      unknownFrance
      15557LDCOMNETFRfalse
      167.70.229.253
      unknownUnited States
      4583WESTPUB-AUSfalse
      117.255.236.170
      unknownIndia
      9829BSNL-NIBNationalInternetBackboneINfalse
      46.93.33.38
      unknownGermany
      3320DTAGInternetserviceprovideroperationsDEfalse
      241.150.197.74
      unknownReserved
      unknownunknownfalse
      85.131.188.72
      unknownGermany
      34309LINK11Link11GmbHDEfalse
      160.24.168.80
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      32.72.230.211
      unknownUnited States
      2686ATGS-MMD-ASUSfalse
      244.10.65.196
      unknownReserved
      unknownunknownfalse
      102.57.17.177
      unknownEgypt
      36992ETISALAT-MISREGfalse
      185.141.123.213
      unknownGermany
      204877DE-KUPPERDEfalse
      130.186.232.206
      unknownItaly
      8612TISCALI-ITfalse
      253.105.21.80
      unknownReserved
      unknownunknownfalse
      149.142.140.161
      unknownUnited States
      52UCLAUSfalse
      187.132.216.121
      unknownMexico
      8151UninetSAdeCVMXfalse
      145.176.119.1
      unknownNetherlands
      59524KPN-IAASNLfalse
      205.237.29.21
      unknownCanada
      54783AS-CSDUROYCAfalse
      126.26.13.179
      unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
      34.227.215.61
      unknownUnited States
      14618AMAZON-AESUSfalse
      107.101.195.20
      unknownUnited States
      7018ATT-INTERNET4USfalse
      65.62.1.156
      unknownUnited States
      32475SINGLEHOP-LLCUSfalse
      5.161.109.193
      unknownGermany
      24940HETZNER-ASDEfalse
      152.45.146.132
      unknownUnited States
      81NCRENUSfalse
      130.237.37.142
      unknownSweden
      1653SUNETSUNETSwedishUniversityNetworkEUfalse
      4.19.51.100
      unknownUnited States
      3356LEVEL3USfalse
      115.17.11.183
      unknownKorea Republic of
      4766KIXS-AS-KRKoreaTelecomKRfalse
      205.215.136.177
      unknownUnited States
      26638MPLS-PUBLIC-SCHOOLSUSfalse
      No context
      No context
      No context
      No context
      No context
      No created / dropped files found
      File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
      Entropy (8bit):6.567228487380409
      TrID:
      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
      File name:SSBFSIj3wk
      File size:81424
      MD5:1beaa289a2e5c583a8ade22549a87e45
      SHA1:7dcf5380b1d43e2fd3d15e32373edd635427229c
      SHA256:63992f68aa03ce566fb5d9cbab680a1c3e04ef381081b51f219461da771cba62
      SHA512:cd326a02bb78fead685b918fb0b3971eb3bbef184683991d3a34c51cbe5c22033d948f24b78debfe5eb9f200ad4c5a1757da75bc07bff13f0d075cb692ef2774
      SSDEEP:1536:nZg6Iau23kSyBep6OAfgeSvxfbVmYjztrJ//euxUqT4pffSYrJYJa:Vl3H+ep6OAfge2xfbVm8Brp/7x1cfXVj
      TLSH:64835DC1A5C2E8F5DC11057930BBA7326A37F03A6079EEDBE3D9A633A851601661339D
      File Content Preview:.ELF....................d...4....<......4. ...(......................5...5...............5..............`6..........Q.td............................U..S.......7E...h........[]...$.............U......=@....t..5...................u........t....h............

      ELF header

      Class:ELF32
      Data:2's complement, little endian
      Version:1 (current)
      Machine:Intel 80386
      Version Number:0x1
      Type:EXEC (Executable file)
      OS/ABI:UNIX - System V
      ABI Version:0
      Entry Point Address:0x8048164
      Flags:0x0
      ELF Header Size:52
      Program Header Offset:52
      Program Header Size:32
      Number of Program Headers:3
      Section Header Offset:81024
      Section Header Size:40
      Number of Section Headers:10
      Header String Table Index:9
      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
      NULL0x00x00x00x00x0000
      .initPROGBITS0x80480940x940x1c0x00x6AX001
      .textPROGBITS0x80480b00xb00x111d60x00x6AX0016
      .finiPROGBITS0x80592860x112860x170x00x6AX001
      .rodataPROGBITS0x80592a00x112a00x231c0x00x2A0032
      .ctorsPROGBITS0x805c5c00x135c00x80x00x3WA004
      .dtorsPROGBITS0x805c5c80x135c80x80x00x3WA004
      .dataPROGBITS0x805c5e00x135e00x6600x00x3WA0032
      .bssNOBITS0x805cc400x13c400x2fe00x00x3WA0032
      .shstrtabSTRTAB0x00x13c400x3e0x00x0001
      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
      LOAD0x00x80480000x80480000x135bc0x135bc6.58780x5R E0x1000.init .text .fini .rodata
      LOAD0x135c00x805c5c00x805c5c00x6800x36604.69420x6RW 0x1000.ctors .dtors .data .bss
      GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
      TimestampSource PortDest PortSource IPDest IP
      Aug 6, 2022 06:47:59.111807108 CEST528696140480.81.219.28192.168.2.23
      Aug 6, 2022 06:47:59.993693113 CEST42836443192.168.2.2391.189.91.43
      Aug 6, 2022 06:48:00.068818092 CEST2596423192.168.2.2368.195.50.67
      Aug 6, 2022 06:48:00.068830013 CEST2596423192.168.2.23162.167.117.199
      Aug 6, 2022 06:48:00.068901062 CEST2596423192.168.2.23202.81.32.67
      Aug 6, 2022 06:48:00.068905115 CEST2596423192.168.2.2386.40.59.64
      Aug 6, 2022 06:48:00.068917036 CEST2596423192.168.2.23147.74.30.71
      Aug 6, 2022 06:48:00.069096088 CEST2596423192.168.2.2376.17.6.164
      Aug 6, 2022 06:48:00.069101095 CEST2596423192.168.2.2369.86.168.58
      Aug 6, 2022 06:48:00.069104910 CEST2596423192.168.2.2347.108.79.178
      Aug 6, 2022 06:48:00.069125891 CEST2596423192.168.2.2387.213.96.138
      Aug 6, 2022 06:48:00.069132090 CEST2596423192.168.2.2358.100.198.137
      Aug 6, 2022 06:48:00.069164038 CEST2596423192.168.2.2376.246.243.225
      Aug 6, 2022 06:48:00.069170952 CEST2596423192.168.2.23186.83.62.48
      Aug 6, 2022 06:48:00.069170952 CEST2596423192.168.2.23217.191.83.36
      Aug 6, 2022 06:48:00.069173098 CEST2596423192.168.2.2313.174.202.182
      Aug 6, 2022 06:48:00.069176912 CEST2596423192.168.2.23204.88.189.98
      Aug 6, 2022 06:48:00.069205999 CEST2596423192.168.2.23107.173.137.9
      Aug 6, 2022 06:48:00.069214106 CEST2596423192.168.2.23197.24.15.249
      Aug 6, 2022 06:48:00.069215059 CEST2596423192.168.2.2342.17.65.121
      Aug 6, 2022 06:48:00.069220066 CEST2596423192.168.2.2396.187.111.50
      Aug 6, 2022 06:48:00.069233894 CEST2596423192.168.2.2332.216.5.41
      Aug 6, 2022 06:48:00.069242001 CEST2596423192.168.2.23192.138.244.88
      Aug 6, 2022 06:48:00.069247007 CEST2596423192.168.2.23213.175.18.187
      Aug 6, 2022 06:48:00.069248915 CEST2596423192.168.2.23153.235.57.169
      Aug 6, 2022 06:48:00.069267988 CEST2596423192.168.2.2368.76.31.148
      Aug 6, 2022 06:48:00.071537018 CEST2596423192.168.2.2341.26.95.169
      Aug 6, 2022 06:48:00.071556091 CEST2596423192.168.2.2353.200.235.95
      Aug 6, 2022 06:48:00.071568012 CEST2596423192.168.2.23246.102.69.11
      Aug 6, 2022 06:48:00.071568966 CEST2596423192.168.2.2324.227.110.35
      Aug 6, 2022 06:48:00.071579933 CEST2596423192.168.2.2346.69.90.219
      Aug 6, 2022 06:48:00.071598053 CEST2596423192.168.2.2346.219.79.180
      Aug 6, 2022 06:48:00.071608067 CEST2596423192.168.2.23165.221.112.169
      Aug 6, 2022 06:48:00.071614981 CEST2596423192.168.2.2396.4.121.61
      Aug 6, 2022 06:48:00.071625948 CEST2596423192.168.2.2327.96.57.37
      Aug 6, 2022 06:48:00.071631908 CEST2596423192.168.2.23113.155.135.253
      Aug 6, 2022 06:48:00.071638107 CEST2596423192.168.2.2337.115.7.130
      Aug 6, 2022 06:48:00.071645021 CEST2596423192.168.2.23156.254.243.153
      Aug 6, 2022 06:48:00.071646929 CEST2596423192.168.2.2382.84.103.132
      Aug 6, 2022 06:48:00.071654081 CEST2596423192.168.2.2346.50.141.75
      Aug 6, 2022 06:48:00.071659088 CEST2596423192.168.2.2370.21.242.15
      Aug 6, 2022 06:48:00.071665049 CEST2596423192.168.2.23171.189.146.162
      Aug 6, 2022 06:48:00.071672916 CEST2596423192.168.2.2391.215.171.38
      Aug 6, 2022 06:48:00.071676016 CEST2596423192.168.2.23105.113.252.83
      Aug 6, 2022 06:48:00.071681023 CEST2596423192.168.2.2398.242.35.32
      Aug 6, 2022 06:48:00.071692944 CEST2596423192.168.2.23254.246.149.1
      Aug 6, 2022 06:48:00.071700096 CEST2596423192.168.2.2398.71.162.169
      Aug 6, 2022 06:48:00.072156906 CEST2596423192.168.2.23163.190.194.226
      Aug 6, 2022 06:48:00.072164059 CEST2596423192.168.2.2312.221.134.193
      Aug 6, 2022 06:48:00.072170973 CEST2596423192.168.2.23178.226.172.132
      Aug 6, 2022 06:48:00.072184086 CEST2596423192.168.2.238.195.127.199
      Aug 6, 2022 06:48:00.072192907 CEST2596423192.168.2.2388.234.97.251
      Aug 6, 2022 06:48:00.072194099 CEST2596423192.168.2.23219.105.121.50
      Aug 6, 2022 06:48:00.072196960 CEST2596423192.168.2.23176.255.111.68
      Aug 6, 2022 06:48:00.072196960 CEST2596423192.168.2.23107.44.168.244
      Aug 6, 2022 06:48:00.072204113 CEST2596423192.168.2.23111.1.39.77
      Aug 6, 2022 06:48:00.072225094 CEST2596423192.168.2.2388.7.24.53
      Aug 6, 2022 06:48:00.072236061 CEST2596423192.168.2.23179.119.231.4
      Aug 6, 2022 06:48:00.072263956 CEST2596423192.168.2.23157.128.231.78
      Aug 6, 2022 06:48:00.072705030 CEST2596423192.168.2.2344.47.128.132
      Aug 6, 2022 06:48:00.072814941 CEST2596423192.168.2.23192.49.51.216
      Aug 6, 2022 06:48:00.072824955 CEST2596423192.168.2.23120.155.13.97
      Aug 6, 2022 06:48:00.072833061 CEST2596423192.168.2.2369.87.57.91
      Aug 6, 2022 06:48:00.072833061 CEST2596423192.168.2.23216.179.114.59
      Aug 6, 2022 06:48:00.073185921 CEST2596423192.168.2.2348.243.86.158
      Aug 6, 2022 06:48:00.073194027 CEST2596423192.168.2.2331.67.3.79
      Aug 6, 2022 06:48:00.073194981 CEST2596423192.168.2.2341.200.101.239
      Aug 6, 2022 06:48:00.073196888 CEST2596423192.168.2.23174.15.29.243
      Aug 6, 2022 06:48:00.073224068 CEST2596423192.168.2.2367.215.249.73
      Aug 6, 2022 06:48:00.073302031 CEST2596423192.168.2.23125.99.195.108
      Aug 6, 2022 06:48:00.073307037 CEST2596423192.168.2.23245.230.168.207
      Aug 6, 2022 06:48:00.073328018 CEST2596423192.168.2.2327.102.81.175
      Aug 6, 2022 06:48:00.073343039 CEST2596423192.168.2.23212.47.217.222
      Aug 6, 2022 06:48:00.073350906 CEST2596423192.168.2.2373.159.194.98
      Aug 6, 2022 06:48:00.073354959 CEST2596423192.168.2.23170.193.208.67
      Aug 6, 2022 06:48:00.073362112 CEST2596423192.168.2.2386.139.85.152
      Aug 6, 2022 06:48:00.073381901 CEST2596423192.168.2.23167.222.128.51
      Aug 6, 2022 06:48:00.073384047 CEST2596423192.168.2.23193.158.108.82
      Aug 6, 2022 06:48:00.073385000 CEST2596423192.168.2.23196.200.181.73
      Aug 6, 2022 06:48:00.073395014 CEST2596423192.168.2.2369.185.216.116
      Aug 6, 2022 06:48:00.073395967 CEST2596423192.168.2.23118.252.210.217
      Aug 6, 2022 06:48:00.073985100 CEST2596423192.168.2.23128.25.150.123
      Aug 6, 2022 06:48:00.073986053 CEST2596423192.168.2.23218.11.152.206
      Aug 6, 2022 06:48:00.073991060 CEST2596423192.168.2.2395.191.246.45
      Aug 6, 2022 06:48:00.074023962 CEST2596423192.168.2.2324.17.239.195
      Aug 6, 2022 06:48:00.074034929 CEST2596423192.168.2.23149.241.186.119
      Aug 6, 2022 06:48:00.074045897 CEST2596423192.168.2.23106.76.19.86
      Aug 6, 2022 06:48:00.074074984 CEST2596423192.168.2.2343.2.87.111
      Aug 6, 2022 06:48:00.074076891 CEST2596423192.168.2.2380.150.90.124
      Aug 6, 2022 06:48:00.074084044 CEST2596423192.168.2.2370.145.161.155
      Aug 6, 2022 06:48:00.074094057 CEST2596423192.168.2.23170.150.152.209
      Aug 6, 2022 06:48:00.074110031 CEST2596423192.168.2.2376.201.247.242
      Aug 6, 2022 06:48:00.074111938 CEST2596423192.168.2.23140.213.161.150
      Aug 6, 2022 06:48:00.074119091 CEST2596423192.168.2.2344.251.174.96
      Aug 6, 2022 06:48:00.074119091 CEST2596423192.168.2.23173.118.82.67
      Aug 6, 2022 06:48:00.074132919 CEST2596423192.168.2.23149.218.61.48
      Aug 6, 2022 06:48:00.074136972 CEST2596423192.168.2.2318.162.223.82
      Aug 6, 2022 06:48:00.074137926 CEST2596423192.168.2.2390.72.237.128
      Aug 6, 2022 06:48:00.074141026 CEST2596423192.168.2.23207.214.91.62
      Aug 6, 2022 06:48:00.074157000 CEST2596423192.168.2.2313.193.87.81
      TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
      Aug 6, 2022 06:48:00.078311920 CEST192.168.2.238.8.8.80xbef5Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:48:09.125917912 CEST192.168.2.238.8.8.80xb374Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:48:14.174034119 CEST192.168.2.238.8.8.80xb599Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:48:23.269795895 CEST192.168.2.238.8.8.80xd3f8Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:48:33.403332949 CEST192.168.2.238.8.8.80xa115Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:48:42.453854084 CEST192.168.2.238.8.8.80x9cfbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:48:50.507410049 CEST192.168.2.238.8.8.80xd8bStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:00.754700899 CEST192.168.2.238.8.8.80x90cbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:10.802896023 CEST192.168.2.238.8.8.80x5ddcStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:18.872000933 CEST192.168.2.238.8.8.80x6748Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:25.919867039 CEST192.168.2.238.8.8.80x8b89Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:35.002190113 CEST192.168.2.238.8.8.80x7398Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:43.050901890 CEST192.168.2.238.8.8.80xaf6bStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:44.109100103 CEST192.168.2.238.8.8.80x7229Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:50.156644106 CEST192.168.2.238.8.8.80xbd75Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:49:57.205142975 CEST192.168.2.238.8.8.80xdd9aStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:01.251140118 CEST192.168.2.238.8.8.80x9539Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:08.296968937 CEST192.168.2.238.8.8.80x711eStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:11.342570066 CEST192.168.2.238.8.8.80xc154Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:16.390641928 CEST192.168.2.238.8.8.80x4f29Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:22.456301928 CEST192.168.2.238.8.8.80xe9daStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:23.504879951 CEST192.168.2.238.8.8.80x5e1fStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:28.553596020 CEST192.168.2.238.8.8.80xdddbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:30.601393938 CEST192.168.2.238.8.8.80xf2fcStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:37.649391890 CEST192.168.2.238.8.8.80xf868Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:42.730268002 CEST192.168.2.238.8.8.80x5b52Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:46.605715036 CEST192.168.2.238.8.8.80xbef5Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:46.783771038 CEST192.168.2.238.8.8.80xc95Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:48.832328081 CEST192.168.2.238.8.8.80x9301Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:50.911737919 CEST192.168.2.238.8.8.80xe050Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:55.653640032 CEST192.168.2.238.8.8.80xb374Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:50:56.973839045 CEST192.168.2.238.8.8.80xa839Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:00.701004028 CEST192.168.2.238.8.8.80xb599Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:03.053056955 CEST192.168.2.238.8.8.80xd8efStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:04.104366064 CEST192.168.2.238.8.8.80x6c88Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:06.748928070 CEST192.168.2.238.8.8.80xd3f8Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:12.157315969 CEST192.168.2.238.8.8.80xa5b6Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:16.796652079 CEST192.168.2.238.8.8.80xa115Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:22.213680029 CEST192.168.2.238.8.8.80xb43aStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:24.899380922 CEST192.168.2.238.8.8.80x9cfbStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:30.260056973 CEST192.168.2.238.8.8.80x84b3Standard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:31.947463989 CEST192.168.2.238.8.8.80xd8bStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      Aug 6, 2022 06:51:32.306253910 CEST192.168.2.238.8.8.80x11ceStandard query (0)arcticboatz.czA (IP address)IN (0x0001)
      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
      Aug 6, 2022 06:48:00.095745087 CEST8.8.8.8192.168.2.230xbef5No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:48:09.145636082 CEST8.8.8.8192.168.2.230xb374No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:48:14.200782061 CEST8.8.8.8192.168.2.230xb599No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:48:23.289823055 CEST8.8.8.8192.168.2.230xd3f8No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:48:33.423337936 CEST8.8.8.8192.168.2.230xa115No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:48:42.471218109 CEST8.8.8.8192.168.2.230x9cfbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:48:50.527005911 CEST8.8.8.8192.168.2.230xd8bNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:00.774195910 CEST8.8.8.8192.168.2.230x90cbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:10.822261095 CEST8.8.8.8192.168.2.230x5ddcNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:18.891434908 CEST8.8.8.8192.168.2.230x6748No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:25.940848112 CEST8.8.8.8192.168.2.230x8b89No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:35.022111893 CEST8.8.8.8192.168.2.230x7398No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:43.079803944 CEST8.8.8.8192.168.2.230xaf6bNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:44.128092051 CEST8.8.8.8192.168.2.230x7229No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:50.173712015 CEST8.8.8.8192.168.2.230xbd75No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:49:57.222553968 CEST8.8.8.8192.168.2.230xdd9aNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:01.268518925 CEST8.8.8.8192.168.2.230x9539No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:08.313884974 CEST8.8.8.8192.168.2.230x711eNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:11.361749887 CEST8.8.8.8192.168.2.230xc154No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:16.409389019 CEST8.8.8.8192.168.2.230x4f29No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:22.475939035 CEST8.8.8.8192.168.2.230xe9daNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:23.524410963 CEST8.8.8.8192.168.2.230x5e1fNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:28.572948933 CEST8.8.8.8192.168.2.230xdddbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:30.619324923 CEST8.8.8.8192.168.2.230xf2fcNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:37.668998957 CEST8.8.8.8192.168.2.230xf868No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:42.749850035 CEST8.8.8.8192.168.2.230x5b52No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:46.624937057 CEST8.8.8.8192.168.2.230xbef5No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:46.803086042 CEST8.8.8.8192.168.2.230xc95No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:48.861555099 CEST8.8.8.8192.168.2.230x9301No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:50.929491043 CEST8.8.8.8192.168.2.230xe050No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:55.671456099 CEST8.8.8.8192.168.2.230xb374No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:50:56.992954969 CEST8.8.8.8192.168.2.230xa839No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:00.720555067 CEST8.8.8.8192.168.2.230xb599No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:03.072695971 CEST8.8.8.8192.168.2.230xd8efNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:04.123748064 CEST8.8.8.8192.168.2.230x6c88No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:06.768574953 CEST8.8.8.8192.168.2.230xd3f8No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:12.176244974 CEST8.8.8.8192.168.2.230xa5b6No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:16.815886974 CEST8.8.8.8192.168.2.230xa115No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:22.231204987 CEST8.8.8.8192.168.2.230xb43aNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:24.918699026 CEST8.8.8.8192.168.2.230x9cfbNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:30.277465105 CEST8.8.8.8192.168.2.230x84b3No error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:31.966412067 CEST8.8.8.8192.168.2.230xd8bNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)
      Aug 6, 2022 06:51:32.323992014 CEST8.8.8.8192.168.2.230x11ceNo error (0)arcticboatz.cz46.23.109.40A (IP address)IN (0x0001)

      System Behavior

      Start time:06:47:59
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:/tmp/SSBFSIj3wk
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45
      Start time:06:47:59
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:n/a
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45
      Start time:06:47:59
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:n/a
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45
      Start time:06:47:59
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:n/a
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45
      Start time:06:47:59
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:n/a
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45
      Start time:06:47:59
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:n/a
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45
      Start time:06:50:46
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:n/a
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45
      Start time:06:47:59
      Start date:06/08/2022
      Path:/tmp/SSBFSIj3wk
      Arguments:n/a
      File size:81424 bytes
      MD5 hash:1beaa289a2e5c583a8ade22549a87e45