Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
qkbfi86.elf

Overview

General Information

Sample name:qkbfi86.elf
Analysis ID:1544586
MD5:341e40c80cf54c01e50088bf85fecad4
SHA1:3140fdfa5a0ccafc61421b4679a0803651369b74
SHA256:5a217f011181d1f210b590161bf89153a7483733ffc2e713582f1473752d70ad
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:92
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Machine Learning detection for sample
Sample deletes itself
Sends malformed DNS queries
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1544586
Start date and time:2024-10-29 15:53:15 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:qkbfi86.elf
Detection:MAL
Classification:mal92.troj.evad.linELF@0/0@61/0
  • VT rate limit hit for: qkbfi86.elf
Command:/tmp/qkbfi86.elf
PID:5519
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
about to cum inside a femboy btw
Standard Error:
  • system is lnxubuntu20
  • qkbfi86.elf (PID: 5519, Parent: 5446, MD5: 341e40c80cf54c01e50088bf85fecad4) Arguments: /tmp/qkbfi86.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
qkbfi86.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    qkbfi86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      qkbfi86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x11e68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11e90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ea4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11eb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11f94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11fa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11fbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11fd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11fe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x11ff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      qkbfi86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x5a20:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      qkbfi86.elfLinux_Trojan_Mirai_5f7b67b8unknownunknown
      • 0xac8d:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
      Click to see the 5 entries
      SourceRuleDescriptionAuthorStrings
      5519.1.0000000008048000.000000000805c000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        5519.1.0000000008048000.000000000805c000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5519.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0x11e68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11e7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11e90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11ea4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11eb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11ecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11ee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11ef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11f94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11fa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11fbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11fd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11fe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0x11ff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5519.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
          • 0x5a20:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
          5519.1.0000000008048000.000000000805c000.r-x.sdmpLinux_Trojan_Mirai_5f7b67b8unknownunknown
          • 0xac8d:$a: 89 38 83 CF FF 89 F8 5A 59 5F C3 57 56 83 EC 04 8B 7C 24 10 8B 4C
          Click to see the 8 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: qkbfi86.elfAvira: detected
          Source: qkbfi86.elfReversingLabs: Detection: 42%
          Source: qkbfi86.elfJoe Sandbox ML: detected
          Source: qkbfi86.elfString: /proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverraw.eye-network.ruabcdefghijklmnopqrstuvwxyz/proc/%d/proc/self/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbin/poweroff/usr/bin/poweroff/usr/sbin/halt/usr/bin/halt

          Networking

          barindex
          Source: global trafficDNS traffic detected: malformed DNS query: raw.eye-network.ru. [malformed]
          Source: global trafficTCP traffic: 192.168.2.15:49926 -> 213.232.235.18:33966
          Source: global trafficDNS traffic detected: DNS query: raw.eye-network.ru
          Source: global trafficDNS traffic detected: DNS query: raw.eye-network.ru. [malformed]

          System Summary

          barindex
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: Process Memory Space: qkbfi86.elf PID: 5519, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Initial sampleString containing 'busybox' found: /bin/busybox
          Source: Initial sampleString containing 'busybox' found: /proc/proc/%d/cmdlinenetstatwgetcurl/bin/busybox/proc//proc/%s/exe/proc/self/exevar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/anko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-serverraw.eye-network.ruabcdefghijklmnopqrstuvwxyz/proc/%d/proc/self/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sbin/poweroff/usr/bin/poweroff/usr/sbin/halt/usr/bin/halt
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: qkbfi86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_ae9d0fa6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = ca2bf2771844bec95563800d19a35dd230413f8eff0bd44c8ab0b4c596f81bfc, id = ae9d0fa6-be06-4656-9b13-8edfc0ee9e71, last_modified = 2021-09-16
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: Process Memory Space: qkbfi86.elf PID: 5519, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal92.troj.evad.linELF@0/0@61/0
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/110/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/231/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/111/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/112/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/233/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/113/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/114/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/235/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/115/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1333/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/116/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1695/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/117/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/118/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/3751/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/119/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/911/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/914/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/10/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/917/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/11/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/12/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/13/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/14/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/15/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/16/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/17/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/18/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/19/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1591/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/120/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/121/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/122/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/243/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/2/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/123/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/3/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/124/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1588/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/125/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/4/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/246/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/126/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/5/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/127/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/6/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1585/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/128/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/7/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/129/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/8/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/800/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/9/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/802/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/803/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/804/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/20/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/21/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/3407/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/22/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/23/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/24/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/25/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/26/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/27/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/28/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/29/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1484/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/490/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/250/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/130/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/251/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/131/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/132/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/133/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1479/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/378/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/258/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/259/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/931/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1595/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/812/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/933/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/30/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/3419/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/35/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/3310/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/260/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/261/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/262/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/142/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/263/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/264/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/265/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/145/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/266/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/267/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/268/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/3303/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/269/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1486/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/1806/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/3440/cmdlineJump to behavior
          Source: /tmp/qkbfi86.elf (PID: 5521)File opened: /proc/270/cmdlineJump to behavior

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/qkbfi86.elf (PID: 5520)File: /tmp/qkbfi86.elfJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: qkbfi86.elf, type: SAMPLE
          Source: Yara matchFile source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: qkbfi86.elf PID: 5519, type: MEMORYSTR
          Source: Yara matchFile source: qkbfi86.elf, type: SAMPLE
          Source: Yara matchFile source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: qkbfi86.elf PID: 5519, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: qkbfi86.elf, type: SAMPLE
          Source: Yara matchFile source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: qkbfi86.elf PID: 5519, type: MEMORYSTR
          Source: Yara matchFile source: qkbfi86.elf, type: SAMPLE
          Source: Yara matchFile source: 5519.1.0000000008048000.000000000805c000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: qkbfi86.elf PID: 5519, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity Information1
          Scripting
          Valid AccountsWindows Management Instrumentation1
          Scripting
          Path Interception1
          File Deletion
          1
          OS Credential Dumping
          System Service DiscoveryRemote ServicesData from Local System1
          Non-Standard Port
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Application Layer Protocol
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          qkbfi86.elf42%ReversingLabsLinux.Backdoor.Mirai
          qkbfi86.elf100%AviraEXP/ELF.Mirai.Z.A
          qkbfi86.elf100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          raw.eye-network.ru
          213.232.235.18
          truetrue
            unknown
            raw.eye-network.ru. [malformed]
            unknown
            unknowntrue
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              213.232.235.18
              raw.eye-network.ruRussian Federation
              39824ALMANET-ASKZtrue
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              213.232.235.18qkehusl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                vkjqpc.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                  vqsjh4.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                    jwwofba5.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                      qkehusl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                        vqkjf64.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                          vwkjebwi686.elfGet hashmaliciousMirai, OkiruBrowse
                            dvwkja7.elfGet hashmaliciousMirai, OkiruBrowse
                              wheiuwa4.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                qkbfi86.elfGet hashmaliciousMirai, OkiruBrowse
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  raw.eye-network.ruqkehusl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  vkjqpc.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  qkehusl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  vqkjf64.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  ALMANET-ASKZqkehusl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  vkjqpc.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  vqsjh4.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  jwwofba5.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  qkehusl.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  vqkjf64.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  vwkjebwi686.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 213.232.235.18
                                  dvwkja7.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 213.232.235.18
                                  wheiuwa4.elfGet hashmaliciousGafgyt, Mirai, OkiruBrowse
                                  • 213.232.235.18
                                  qkbfi86.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 213.232.235.18
                                  No context
                                  No context
                                  No created / dropped files found
                                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                  Entropy (8bit):5.803115463531146
                                  TrID:
                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                  File name:qkbfi86.elf
                                  File size:100'808 bytes
                                  MD5:341e40c80cf54c01e50088bf85fecad4
                                  SHA1:3140fdfa5a0ccafc61421b4679a0803651369b74
                                  SHA256:5a217f011181d1f210b590161bf89153a7483733ffc2e713582f1473752d70ad
                                  SHA512:a63c064cec482047956d0b7ca55d9ef32dd76a9b06c3a72f8e8ab6ff307a44c8a1d9e759b6ca43b04fa244626ad0ed552cfdf26cca9f8f0163ec9aa4e5736fc9
                                  SSDEEP:1536:wkQZkU4MS392FgaQzRDGAefdCiuZHp3S+FPQ6zZBy85V7qOLcSCtv0:wNkU4MS3qgfGAe43S+xDfj5IYZW0
                                  TLSH:5CA37DD4F243D5F5E84704B5613BFB378B32F0B91129DA43D3AD6E32AC52901DA0A6AC
                                  File Content Preview:.ELF....................d...4...8.......4. ...(.....................3?..3?...............@...........G..............Q.td............................U..S.......{?...h........[]...$.............U......=.....t..5....D......D.......u........t....h4...........

                                  ELF header

                                  Class:ELF32
                                  Data:2's complement, little endian
                                  Version:1 (current)
                                  Machine:Intel 80386
                                  Version Number:0x1
                                  Type:EXEC (Executable file)
                                  OS/ABI:UNIX - System V
                                  ABI Version:0
                                  Entry Point Address:0x8048164
                                  Flags:0x0
                                  ELF Header Size:52
                                  Program Header Offset:52
                                  Program Header Size:32
                                  Number of Program Headers:3
                                  Section Header Offset:100408
                                  Section Header Size:40
                                  Number of Section Headers:10
                                  Header String Table Index:9
                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                  NULL0x00x00x00x00x0000
                                  .initPROGBITS0x80480940x940x1c0x00x6AX001
                                  .textPROGBITS0x80480b00xb00x116260x00x6AX0016
                                  .finiPROGBITS0x80596d60x116d60x170x00x6AX001
                                  .rodataPROGBITS0x80597000x117000x28330x00x2A0032
                                  .ctorsPROGBITS0x805c0000x140000xc0x00x3WA004
                                  .dtorsPROGBITS0x805c00c0x1400c0x80x00x3WA004
                                  .dataPROGBITS0x805c0400x140400x47b80x00x3WA0032
                                  .bssNOBITS0x80608000x187f80x49ec0x00x3WA0032
                                  .shstrtabSTRTAB0x00x187f80x3e0x00x0001
                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                  LOAD0x00x80480000x80480000x13f330x13f336.57650x5R E0x1000.init .text .fini .rodata
                                  LOAD0x140000x805c0000x805c0000x47f80x91ec0.41080x6RW 0x1000.ctors .dtors .data .bss
                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                  TimestampSource PortDest PortSource IPDest IP
                                  Oct 29, 2024 15:54:00.529956102 CET4992633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:00.536798954 CET3396649926213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:00.536890984 CET4992633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:00.536890984 CET4992633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:00.542309999 CET3396649926213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:00.542432070 CET4992633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:00.547934055 CET3396649926213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:01.438714981 CET3396649926213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:01.438793898 CET4992633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:01.438793898 CET4992633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:01.519148111 CET4992833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:01.525404930 CET3396649928213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:01.525471926 CET4992833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:01.525489092 CET4992833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:01.531233072 CET3396649928213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:01.531277895 CET4992833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:01.536977053 CET3396649928213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:02.420346022 CET3396649928213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:02.420479059 CET4992833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:02.420479059 CET4992833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:02.510375023 CET4993033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:02.515815973 CET3396649930213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:02.515960932 CET4993033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:02.515960932 CET4993033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:02.521457911 CET3396649930213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:02.521687031 CET4993033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:02.527482033 CET3396649930213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:03.425896883 CET3396649930213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:03.425981998 CET4993033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:03.426060915 CET4993033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:03.500611067 CET4993233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:03.506038904 CET3396649932213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:03.506119013 CET4993233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:03.506119013 CET4993233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:03.511773109 CET3396649932213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:03.511850119 CET4993233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:03.517437935 CET3396649932213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:04.433820963 CET3396649932213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:04.433902979 CET4993233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:04.433902979 CET4993233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:04.514709949 CET4993433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:04.520597935 CET3396649934213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:04.520683050 CET4993433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:04.520683050 CET4993433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:04.526385069 CET3396649934213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:04.526628017 CET4993433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:04.532383919 CET3396649934213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:05.408495903 CET3396649934213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:05.408581018 CET4993433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:05.408581018 CET4993433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:05.490586042 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:05.496119022 CET3396649936213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:05.496220112 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:05.496220112 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:05.502429008 CET3396649936213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:05.502494097 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:05.508057117 CET3396649936213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:07.314549923 CET3396649936213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:07.314682961 CET3396649936213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:07.314718008 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.314718962 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.314806938 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.314856052 CET3396649936213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:07.314898014 CET4993633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.468337059 CET4993833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.473797083 CET3396649938213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:07.473884106 CET4993833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.473884106 CET4993833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.479299068 CET3396649938213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:07.480331898 CET4993833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:07.485580921 CET3396649938213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:08.628127098 CET3396649938213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:08.628249884 CET4993833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:08.628288984 CET4993833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:08.637607098 CET3396649938213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:08.637675047 CET4993833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:08.711361885 CET4994033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:08.717097044 CET3396649940213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:08.717170954 CET4994033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:08.717189074 CET4994033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:08.722554922 CET3396649940213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:08.722593069 CET4994033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:08.728255987 CET3396649940213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:09.622260094 CET3396649940213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:09.622364044 CET4994033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:09.622380018 CET4994033966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:09.755096912 CET4994233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:09.762361050 CET3396649942213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:09.762422085 CET4994233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:09.762459040 CET4994233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:09.769206047 CET3396649942213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:09.769256115 CET4994233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:09.774841070 CET3396649942213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:10.672507048 CET3396649942213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:10.672610044 CET4994233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:10.672610044 CET4994233966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:10.757224083 CET4994433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:10.762684107 CET3396649944213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:10.762741089 CET4994433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:10.762758970 CET4994433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:10.768259048 CET3396649944213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:10.768311024 CET4994433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:10.775361061 CET3396649944213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:11.665796995 CET3396649944213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:11.666002035 CET4994433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:11.666002035 CET4994433966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:11.750698090 CET4994633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:11.756082058 CET3396649946213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:11.756156921 CET4994633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:11.756299019 CET4994633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:11.762096882 CET3396649946213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:54:11.762147903 CET4994633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:54:11.767956018 CET3396649946213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:55:21.800712109 CET4994633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:55:21.806708097 CET3396649946213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:55:31.804387093 CET4994633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:55:31.810945034 CET3396649946213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:56:01.476484060 CET3396649946213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:56:01.476752996 CET4994633966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:56:01.482180119 CET3396649946213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:56:02.553184032 CET4994833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:56:02.558676004 CET3396649948213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:56:02.558772087 CET4994833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:56:02.558814049 CET4994833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:56:02.564258099 CET3396649948213.232.235.18192.168.2.15
                                  Oct 29, 2024 15:56:02.564332962 CET4994833966192.168.2.15213.232.235.18
                                  Oct 29, 2024 15:56:02.569907904 CET3396649948213.232.235.18192.168.2.15
                                  TimestampSource PortDest PortSource IPDest IP
                                  Oct 29, 2024 15:54:00.438857079 CET5462353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:00.493567944 CET53546238.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:00.493685961 CET4654253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:00.501048088 CET53465428.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:00.501127958 CET4853253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:00.508089066 CET53485328.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:00.508222103 CET5092853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:00.515189886 CET53509288.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:00.515259027 CET5822153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:00.522316933 CET53582218.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:00.522392035 CET5648253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:00.529879093 CET53564828.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.438883066 CET3948953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.446638107 CET53394898.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.446755886 CET5239453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.455605030 CET53523948.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.455665112 CET5656553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.463723898 CET53565658.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.464318037 CET5156253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.471641064 CET53515628.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.471831083 CET3955953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.481231928 CET53395598.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.481313944 CET5385253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.488557100 CET53538528.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.488663912 CET3963053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.495985031 CET53396308.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.496061087 CET5950353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.503854036 CET53595038.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.503935099 CET3508153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.512058973 CET53350818.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:01.512145996 CET3948853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:01.519062996 CET53394888.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.420490026 CET3574453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.430264950 CET53357448.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.430357933 CET3738353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.439466953 CET53373838.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.439569950 CET6014453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.446290016 CET53601448.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.446440935 CET3328153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.453665972 CET53332818.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.453741074 CET4858653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.460911989 CET53485868.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.462783098 CET5495953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.470837116 CET53549598.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.470969915 CET3974453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.481951952 CET53397448.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.483104944 CET3515653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.491538048 CET53351568.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.491667032 CET5132253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.499109983 CET53513228.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:02.502469063 CET4798353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:02.509691954 CET53479838.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.426065922 CET4423853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.433252096 CET53442388.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.433362961 CET3593453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.440615892 CET53359348.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.440700054 CET4378853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.448693037 CET53437888.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.448781967 CET3528153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.456211090 CET53352818.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.456288099 CET3449553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.463515043 CET53344958.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.463584900 CET5896953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.470629930 CET53589698.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.470714092 CET4993253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.478133917 CET53499328.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.478204966 CET4234453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.485774040 CET53423448.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.485874891 CET5997853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.493284941 CET53599788.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:03.493359089 CET3322153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:03.500540972 CET53332218.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.433984995 CET5176453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.441545010 CET53517648.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.441656113 CET4785253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.451169014 CET53478528.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.451241970 CET5560253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.458529949 CET53556028.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.458590984 CET3295453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.465831041 CET53329548.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.465971947 CET5937553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.473944902 CET53593758.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.474020004 CET5061053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.481587887 CET53506108.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.481668949 CET4697153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.488782883 CET53469718.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.488850117 CET4447253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.496778965 CET53444728.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.496870041 CET5322853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.506942987 CET53532288.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:04.507011890 CET5554353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:04.514600992 CET53555438.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.408669949 CET4132553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.417289019 CET53413258.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.417474031 CET5965553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.424741983 CET53596558.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.424918890 CET4524453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.432041883 CET53452448.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.432157040 CET4151253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.439647913 CET53415128.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.439790010 CET6098153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.448359013 CET53609818.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.448455095 CET4306053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.456553936 CET53430608.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.456666946 CET5283853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.463998079 CET53528388.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.464099884 CET3718653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.471352100 CET53371868.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.471617937 CET3385753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.479130030 CET53338578.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:05.479231119 CET3495753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:05.490483999 CET53349578.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.314898014 CET5211153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.343285084 CET53521118.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.344336033 CET4069353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.377692938 CET53406938.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.380341053 CET4409853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.387830019 CET53440988.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.388331890 CET3671553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.413391113 CET53367158.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.413505077 CET5371653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.421700954 CET53537168.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.421775103 CET5047353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.429861069 CET53504738.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.432332993 CET3325153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.440248013 CET53332518.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.444335938 CET4400053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.452636003 CET53440008.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.452708006 CET5022053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.460319042 CET53502208.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:07.460383892 CET3973753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:07.467927933 CET53397378.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.628329992 CET5939253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.638111115 CET53593928.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.638197899 CET5733353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.645464897 CET53573338.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.645591974 CET4151053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.652842045 CET53415108.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.652935982 CET3592953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.660341978 CET53359298.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.660419941 CET4109153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.674452066 CET53410918.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.674530983 CET6002553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.681756973 CET53600258.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.681828976 CET3522753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.689356089 CET53352278.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.689418077 CET5112753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.696608067 CET53511278.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.696671963 CET4184353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.703994036 CET53418438.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:08.704055071 CET3699753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:08.711297035 CET53369978.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.622426033 CET6095353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.660227060 CET53609538.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.660377026 CET3661253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.680835009 CET53366128.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.680922031 CET5625353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.690695047 CET53562538.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.690776110 CET5453153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.697626114 CET53545318.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.697695971 CET6091453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.705461979 CET53609148.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.705529928 CET4278953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.712727070 CET53427898.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.712795019 CET4926353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.720755100 CET53492638.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.720819950 CET3561853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.731398106 CET53356188.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.731462955 CET4508353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.743669987 CET53450838.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:09.743796110 CET3301253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:09.754986048 CET53330128.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.672652960 CET5877153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.681914091 CET53587718.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.682009935 CET4720753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.690359116 CET53472078.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.690428972 CET5897553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.697916985 CET53589758.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.697978973 CET4074753192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.708610058 CET53407478.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.708677053 CET5725253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.716223001 CET53572528.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.716300964 CET4608353192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.724939108 CET53460838.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.725009918 CET4996853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.735035896 CET53499688.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.735093117 CET5103053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.742356062 CET53510308.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.742415905 CET6021653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.749746084 CET53602168.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:10.749820948 CET3618653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:10.757091999 CET53361868.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.666055918 CET3410653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.674376011 CET53341068.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.674711943 CET5711053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.683062077 CET53571108.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.683209896 CET6072153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.692240953 CET53607218.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.692414045 CET3830153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.699578047 CET53383018.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.699676991 CET5770253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.708720922 CET53577028.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.708811998 CET5863953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.716953039 CET53586398.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.717066050 CET5482553192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.724984884 CET53548258.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.725054026 CET5765853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.734009027 CET53576588.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.734095097 CET4964053192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.742893934 CET53496408.8.8.8192.168.2.15
                                  Oct 29, 2024 15:54:11.742955923 CET4634253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:54:11.750593901 CET53463428.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.478288889 CET4947953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.485284090 CET53494798.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.485430956 CET4361453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.492489100 CET53436148.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.492609978 CET5905153192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.500396967 CET53590518.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.500499964 CET3686853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.508173943 CET53368688.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.508275986 CET3834853192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.515197039 CET53383488.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.515326977 CET5486253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.522735119 CET53548628.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.522850990 CET4393953192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.530019999 CET53439398.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.530122042 CET5618453192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.538091898 CET53561848.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.538201094 CET3980253192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.545797110 CET53398028.8.8.8192.168.2.15
                                  Oct 29, 2024 15:56:02.545917034 CET4684653192.168.2.158.8.8.8
                                  Oct 29, 2024 15:56:02.553072929 CET53468468.8.8.8192.168.2.15
                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                  Oct 29, 2024 15:54:00.438857079 CET192.168.2.158.8.8.80xf9b7Standard query (0)raw.eye-network.ruA (IP address)IN (0x0001)false
                                  Oct 29, 2024 15:54:00.493685961 CET192.168.2.158.8.8.80x7e7aStandard query (0)raw.eye-network.ru. [malformed]256264false
                                  Oct 29, 2024 15:54:00.501127958 CET192.168.2.158.8.8.80x7e7aStandard query (0)raw.eye-network.ru. [malformed]256264false
                                  Oct 29, 2024 15:54:00.508222103 CET192.168.2.158.8.8.80x7e7aStandard query (0)raw.eye-network.ru. [malformed]256264false
                                  Oct 29, 2024 15:54:00.515259027 CET192.168.2.158.8.8.80x7e7aStandard query (0)raw.eye-network.ru. [malformed]256264false
                                  Oct 29, 2024 15:54:00.522392035 CET192.168.2.158.8.8.80x7e7aStandard query (0)raw.eye-network.ru. [malformed]256264false
                                  Oct 29, 2024 15:54:01.481313944 CET192.168.2.158.8.8.80x7a0aStandard query (0)raw.eye-network.ru. [malformed]256265false
                                  Oct 29, 2024 15:54:01.488663912 CET192.168.2.158.8.8.80x7a0aStandard query (0)raw.eye-network.ru. [malformed]256265false
                                  Oct 29, 2024 15:54:01.496061087 CET192.168.2.158.8.8.80x7a0aStandard query (0)raw.eye-network.ru. [malformed]256265false
                                  Oct 29, 2024 15:54:01.503935099 CET192.168.2.158.8.8.80x7a0aStandard query (0)raw.eye-network.ru. [malformed]256265false
                                  Oct 29, 2024 15:54:01.512145996 CET192.168.2.158.8.8.80x7a0aStandard query (0)raw.eye-network.ru. [malformed]256265false
                                  Oct 29, 2024 15:54:02.462783098 CET192.168.2.158.8.8.80x2791Standard query (0)raw.eye-network.ru. [malformed]256266false
                                  Oct 29, 2024 15:54:02.470969915 CET192.168.2.158.8.8.80x2791Standard query (0)raw.eye-network.ru. [malformed]256266false
                                  Oct 29, 2024 15:54:02.483104944 CET192.168.2.158.8.8.80x2791Standard query (0)raw.eye-network.ru. [malformed]256266false
                                  Oct 29, 2024 15:54:02.491667032 CET192.168.2.158.8.8.80x2791Standard query (0)raw.eye-network.ru. [malformed]256266false
                                  Oct 29, 2024 15:54:02.502469063 CET192.168.2.158.8.8.80x2791Standard query (0)raw.eye-network.ru. [malformed]256266false
                                  Oct 29, 2024 15:54:03.463584900 CET192.168.2.158.8.8.80x572aStandard query (0)raw.eye-network.ru. [malformed]256267false
                                  Oct 29, 2024 15:54:03.470714092 CET192.168.2.158.8.8.80x572aStandard query (0)raw.eye-network.ru. [malformed]256267false
                                  Oct 29, 2024 15:54:03.478204966 CET192.168.2.158.8.8.80x572aStandard query (0)raw.eye-network.ru. [malformed]256267false
                                  Oct 29, 2024 15:54:03.485874891 CET192.168.2.158.8.8.80x572aStandard query (0)raw.eye-network.ru. [malformed]256267false
                                  Oct 29, 2024 15:54:03.493359089 CET192.168.2.158.8.8.80x572aStandard query (0)raw.eye-network.ru. [malformed]256267false
                                  Oct 29, 2024 15:54:04.474020004 CET192.168.2.158.8.8.80x9128Standard query (0)raw.eye-network.ru. [malformed]256268false
                                  Oct 29, 2024 15:54:04.481668949 CET192.168.2.158.8.8.80x9128Standard query (0)raw.eye-network.ru. [malformed]256268false
                                  Oct 29, 2024 15:54:04.488850117 CET192.168.2.158.8.8.80x9128Standard query (0)raw.eye-network.ru. [malformed]256268false
                                  Oct 29, 2024 15:54:04.496870041 CET192.168.2.158.8.8.80x9128Standard query (0)raw.eye-network.ru. [malformed]256268false
                                  Oct 29, 2024 15:54:04.507011890 CET192.168.2.158.8.8.80x9128Standard query (0)raw.eye-network.ru. [malformed]256268false
                                  Oct 29, 2024 15:54:05.448455095 CET192.168.2.158.8.8.80xd6cfStandard query (0)raw.eye-network.ru. [malformed]256269false
                                  Oct 29, 2024 15:54:05.456666946 CET192.168.2.158.8.8.80xd6cfStandard query (0)raw.eye-network.ru. [malformed]256269false
                                  Oct 29, 2024 15:54:05.464099884 CET192.168.2.158.8.8.80xd6cfStandard query (0)raw.eye-network.ru. [malformed]256269false
                                  Oct 29, 2024 15:54:05.471617937 CET192.168.2.158.8.8.80xd6cfStandard query (0)raw.eye-network.ru. [malformed]256269false
                                  Oct 29, 2024 15:54:05.479231119 CET192.168.2.158.8.8.80xd6cfStandard query (0)raw.eye-network.ru. [malformed]256269false
                                  Oct 29, 2024 15:54:07.421775103 CET192.168.2.158.8.8.80x2a58Standard query (0)raw.eye-network.ru. [malformed]256271false
                                  Oct 29, 2024 15:54:07.432332993 CET192.168.2.158.8.8.80x2a58Standard query (0)raw.eye-network.ru. [malformed]256271false
                                  Oct 29, 2024 15:54:07.444335938 CET192.168.2.158.8.8.80x2a58Standard query (0)raw.eye-network.ru. [malformed]256271false
                                  Oct 29, 2024 15:54:07.452708006 CET192.168.2.158.8.8.80x2a58Standard query (0)raw.eye-network.ru. [malformed]256271false
                                  Oct 29, 2024 15:54:07.460383892 CET192.168.2.158.8.8.80x2a58Standard query (0)raw.eye-network.ru. [malformed]256271false
                                  Oct 29, 2024 15:54:08.674530983 CET192.168.2.158.8.8.80x3119Standard query (0)raw.eye-network.ru. [malformed]256272false
                                  Oct 29, 2024 15:54:08.681828976 CET192.168.2.158.8.8.80x3119Standard query (0)raw.eye-network.ru. [malformed]256272false
                                  Oct 29, 2024 15:54:08.689418077 CET192.168.2.158.8.8.80x3119Standard query (0)raw.eye-network.ru. [malformed]256272false
                                  Oct 29, 2024 15:54:08.696671963 CET192.168.2.158.8.8.80x3119Standard query (0)raw.eye-network.ru. [malformed]256272false
                                  Oct 29, 2024 15:54:08.704055071 CET192.168.2.158.8.8.80x3119Standard query (0)raw.eye-network.ru. [malformed]256272false
                                  Oct 29, 2024 15:54:09.705529928 CET192.168.2.158.8.8.80xe6e1Standard query (0)raw.eye-network.ru. [malformed]256273false
                                  Oct 29, 2024 15:54:09.712795019 CET192.168.2.158.8.8.80xe6e1Standard query (0)raw.eye-network.ru. [malformed]256273false
                                  Oct 29, 2024 15:54:09.720819950 CET192.168.2.158.8.8.80xe6e1Standard query (0)raw.eye-network.ru. [malformed]256273false
                                  Oct 29, 2024 15:54:09.731462955 CET192.168.2.158.8.8.80xe6e1Standard query (0)raw.eye-network.ru. [malformed]256273false
                                  Oct 29, 2024 15:54:09.743796110 CET192.168.2.158.8.8.80xe6e1Standard query (0)raw.eye-network.ru. [malformed]256273false
                                  Oct 29, 2024 15:54:10.716300964 CET192.168.2.158.8.8.80x9ee5Standard query (0)raw.eye-network.ru. [malformed]256274false
                                  Oct 29, 2024 15:54:10.725009918 CET192.168.2.158.8.8.80x9ee5Standard query (0)raw.eye-network.ru. [malformed]256274false
                                  Oct 29, 2024 15:54:10.735093117 CET192.168.2.158.8.8.80x9ee5Standard query (0)raw.eye-network.ru. [malformed]256274false
                                  Oct 29, 2024 15:54:10.742415905 CET192.168.2.158.8.8.80x9ee5Standard query (0)raw.eye-network.ru. [malformed]256274false
                                  Oct 29, 2024 15:54:10.749820948 CET192.168.2.158.8.8.80x9ee5Standard query (0)raw.eye-network.ru. [malformed]256274false
                                  Oct 29, 2024 15:54:11.708811998 CET192.168.2.158.8.8.80x84fdStandard query (0)raw.eye-network.ru. [malformed]256275false
                                  Oct 29, 2024 15:54:11.717066050 CET192.168.2.158.8.8.80x84fdStandard query (0)raw.eye-network.ru. [malformed]256275false
                                  Oct 29, 2024 15:54:11.725054026 CET192.168.2.158.8.8.80x84fdStandard query (0)raw.eye-network.ru. [malformed]256275false
                                  Oct 29, 2024 15:54:11.734095097 CET192.168.2.158.8.8.80x84fdStandard query (0)raw.eye-network.ru. [malformed]256275false
                                  Oct 29, 2024 15:54:11.742955923 CET192.168.2.158.8.8.80x84fdStandard query (0)raw.eye-network.ru. [malformed]256275false
                                  Oct 29, 2024 15:56:02.515326977 CET192.168.2.158.8.8.80xe691Standard query (0)raw.eye-network.ru. [malformed]256386false
                                  Oct 29, 2024 15:56:02.522850990 CET192.168.2.158.8.8.80xe691Standard query (0)raw.eye-network.ru. [malformed]256386false
                                  Oct 29, 2024 15:56:02.530122042 CET192.168.2.158.8.8.80xe691Standard query (0)raw.eye-network.ru. [malformed]256386false
                                  Oct 29, 2024 15:56:02.538201094 CET192.168.2.158.8.8.80xe691Standard query (0)raw.eye-network.ru. [malformed]256386false
                                  Oct 29, 2024 15:56:02.545917034 CET192.168.2.158.8.8.80xe691Standard query (0)raw.eye-network.ru. [malformed]256386false
                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                  Oct 29, 2024 15:54:00.493567944 CET8.8.8.8192.168.2.150xf9b7No error (0)raw.eye-network.ru213.232.235.18A (IP address)IN (0x0001)false

                                  System Behavior

                                  Start time (UTC):14:53:59
                                  Start date (UTC):29/10/2024
                                  Path:/tmp/qkbfi86.elf
                                  Arguments:/tmp/qkbfi86.elf
                                  File size:100808 bytes
                                  MD5 hash:341e40c80cf54c01e50088bf85fecad4

                                  Start time (UTC):14:53:59
                                  Start date (UTC):29/10/2024
                                  Path:/tmp/qkbfi86.elf
                                  Arguments:-
                                  File size:100808 bytes
                                  MD5 hash:341e40c80cf54c01e50088bf85fecad4

                                  Start time (UTC):14:53:59
                                  Start date (UTC):29/10/2024
                                  Path:/tmp/qkbfi86.elf
                                  Arguments:-
                                  File size:100808 bytes
                                  MD5 hash:341e40c80cf54c01e50088bf85fecad4