Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
vhsr56PI3r.elf

Overview

General Information

Sample name:vhsr56PI3r.elf
renamed because original name is a hash value
Original sample name:5853a3bcb813748bca8a06b91e3eff11.elf
Analysis ID:1545506
MD5:5853a3bcb813748bca8a06b91e3eff11
SHA1:b15d7d903673035eb54e0bef2e683bdf9b80c20c
SHA256:16199bda061a5575d9f226981569c9a92b7562babc1e829631e50cbc2eb8cfcf
Tags:32elfmiraipowerpc
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1545506
Start date and time:2024-10-30 16:20:53 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:vhsr56PI3r.elf
renamed because original name is a hash value
Original Sample Name:5853a3bcb813748bca8a06b91e3eff11.elf
Detection:MAL
Classification:mal68.evad.linELF@0/0@0/0
  • VT rate limit hit for: vhsr56PI3r.elf
Command:/tmp/vhsr56PI3r.elf
PID:6212
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
unstable_is_the_history_of_universe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
6212.1.00007efe30005000.00007efe3000b000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x5ae0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5af4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5ba8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5bbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5bd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5be4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5bf8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: vhsr56PI3r.elf PID: 6212Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x3a89:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3a9d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ab1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ac5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ad9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3aed:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b01:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b15:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b29:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b3d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b51:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b65:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b79:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b8d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ba1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bb5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bc9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bdd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bf1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c05:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c19:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: vhsr56PI3r.elfAvira: detected
Source: vhsr56PI3r.elfReversingLabs: Detection: 39%
Source: /tmp/vhsr56PI3r.elf (PID: 6212)Socket: 127.0.0.1:46157Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: vhsr56PI3r.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6212.1.00007efe30005000.00007efe3000b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: vhsr56PI3r.elf PID: 6212, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6212.1.00007efe30005000.00007efe3000b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: vhsr56PI3r.elf PID: 6212, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6232/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6231/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6234/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6233/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6236/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6235/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1582/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/3088/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1579/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1699/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1335/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1698/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1334/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1576/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/2302/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/910/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/912/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/2307/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/918/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6241/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6240/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6243/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6242/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6245/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6244/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6247/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6246/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1594/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1349/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1344/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1465/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1586/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1463/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6238/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/801/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6237/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6239/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/1900/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6251/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/491/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/6250/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/vhsr56PI3r.elf (PID: 6216)File opened: /proc/255/cmdlineJump to behavior
Source: vhsr56PI3r.elfSubmission file: segment LOAD with 7.8998 entropy (max. 8.0)
Source: /tmp/vhsr56PI3r.elf (PID: 6212)Queries kernel information via 'uname': Jump to behavior
Source: vhsr56PI3r.elf, 6212.1.00007ffcbe9f0000.00007ffcbea11000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-ppc/tmp/vhsr56PI3r.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/vhsr56PI3r.elf
Source: vhsr56PI3r.elf, 6212.1.000055c5bcebf000.000055c5bcf6f000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: vhsr56PI3r.elf, 6212.1.000055c5bcebf000.000055c5bcf6f000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: vhsr56PI3r.elf, 6212.1.00007ffcbe9f0000.00007ffcbea11000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
vhsr56PI3r.elf39%ReversingLabsLinux.Trojan.Mirai
vhsr56PI3r.elf100%AviraEXP/ELF.Agent.F.118
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://upx.sf.net0%URL Reputationsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netvhsr56PI3r.elftrue
  • URL Reputation: safe
unknown
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
217.32.184.17
unknownUnited Kingdom
6871PLUSNETUKInternetServiceProviderGBfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
217.32.184.17TXVo7pIaEB.elfGet hashmaliciousUnknownBrowse
    CaKRRsqLWL.elfGet hashmaliciousUnknownBrowse
      7GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
        sora.arm.elfGet hashmaliciousUnknownBrowse
          sora.mips.elfGet hashmaliciousUnknownBrowse
            sora.mpsl.elfGet hashmaliciousUnknownBrowse
              sora.x86.elfGet hashmaliciousUnknownBrowse
                sh4.elfGet hashmaliciousUnknownBrowse
                  debug.dbg.elfGet hashmaliciousMiraiBrowse
                    na.elfGet hashmaliciousMiraiBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.437GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
                        la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                          sora.arm.elfGet hashmaliciousUnknownBrowse
                            sora.mips.elfGet hashmaliciousUnknownBrowse
                              la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                  la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                    la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                      .main.elfGet hashmaliciousXmrigBrowse
                                        Mozi.m.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.427GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
                                            la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                                              sora.arm.elfGet hashmaliciousUnknownBrowse
                                                sora.mips.elfGet hashmaliciousUnknownBrowse
                                                  la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                                    la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                                      la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                        la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                          .main.elfGet hashmaliciousXmrigBrowse
                                                            Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGB7GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.arm.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              .main.elfGet hashmaliciousXmrigBrowse
                                                              • 91.189.91.42
                                                              CANONICAL-ASGB7GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.arm.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              sora.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 185.125.190.26
                                                              la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              .main.elfGet hashmaliciousXmrigBrowse
                                                              • 91.189.91.42
                                                              PLUSNETUKInternetServiceProviderGBTXVo7pIaEB.elfGet hashmaliciousUnknownBrowse
                                                              • 217.32.184.17
                                                              CaKRRsqLWL.elfGet hashmaliciousUnknownBrowse
                                                              • 217.32.184.17
                                                              7GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
                                                              • 217.32.184.17
                                                              sora.arm.elfGet hashmaliciousUnknownBrowse
                                                              • 217.32.184.17
                                                              sora.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 217.32.184.17
                                                              sora.mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 217.32.184.17
                                                              sora.x86.elfGet hashmaliciousUnknownBrowse
                                                              • 217.32.184.17
                                                              jew.mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 143.159.228.252
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 84.93.57.1
                                                              la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                                                              • 80.189.244.34
                                                              INIT7CH7GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              sora.arm.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              sora.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              .main.elfGet hashmaliciousXmrigBrowse
                                                              • 109.202.202.202
                                                              Mozi.m.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, no section header
                                                              Entropy (8bit):7.894767593888515
                                                              TrID:
                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                              File name:vhsr56PI3r.elf
                                                              File size:20'296 bytes
                                                              MD5:5853a3bcb813748bca8a06b91e3eff11
                                                              SHA1:b15d7d903673035eb54e0bef2e683bdf9b80c20c
                                                              SHA256:16199bda061a5575d9f226981569c9a92b7562babc1e829631e50cbc2eb8cfcf
                                                              SHA512:5ec8e61774628405bfcf35c715504b2820e7d178cf651083625b942d8ab46a6bd3aedbe5789ee9761f13f07ee92b1669b8c1aafc5bdaafa74e6995ae49d1e6ab
                                                              SSDEEP:384:d+pkcc9eLCpDiqFwmE4VuTDkVG0WkfQfXXS3WpfM4uVcqgw05VxJ6BT:Mpvc9aFc3VmDDrSQfXXS3Wp04uVcqgwP
                                                              TLSH:2F92CF72E4175E97DF7B9EF85EC9D99093E90E8C3BA38C816061AF051143634BA81ED8
                                                              File Content Preview:.ELF......................<h...4.........4. ...(......................NP..NP...............\...\...\................dt.Q................................UPX!.......................T.......?.E.h4...@b.............=I.......1......T..}.,_......+.8.\.....n~).=

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, big endian
                                                              Version:1 (current)
                                                              Machine:PowerPC
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - Linux
                                                              ABI Version:0
                                                              Entry Point Address:0x103c68
                                                              Flags:0x0
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:0
                                                              Section Header Size:40
                                                              Number of Section Headers:0
                                                              Header String Table Index:0
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x1000000x1000000x4e500x4e507.89980x5R E0x10000
                                                              LOAD0xaa5c0x1001aa5c0x1001aa5c0x00x00.00000x6RW 0x10000
                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Oct 30, 2024 16:21:31.692888975 CET5203023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:31.698743105 CET2352030217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:31.698800087 CET5203023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:31.700880051 CET5203023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:31.706288099 CET2352030217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:31.706329107 CET5203023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:31.711782932 CET2352030217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:32.219392061 CET43928443192.168.2.2391.189.91.42
                                                              Oct 30, 2024 16:21:37.850805998 CET42836443192.168.2.2391.189.91.43
                                                              Oct 30, 2024 16:21:39.130517006 CET4251680192.168.2.23109.202.202.202
                                                              Oct 30, 2024 16:21:40.188666105 CET2352030217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:40.189085960 CET5203023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:40.196424007 CET2352030217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:41.230870962 CET5203223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:41.236238956 CET2352032217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:41.236296892 CET5203223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:41.237020016 CET5203223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:41.242259026 CET2352032217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:41.242302895 CET5203223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:41.247575998 CET2352032217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:49.721549034 CET2352032217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:49.721940041 CET5203223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:49.727371931 CET2352032217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:50.767621040 CET5203423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:50.774023056 CET2352034217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:50.774084091 CET5203423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:50.774775028 CET5203423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:50.782016039 CET2352034217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:50.782067060 CET5203423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:50.788064003 CET2352034217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:52.184779882 CET43928443192.168.2.2391.189.91.42
                                                              Oct 30, 2024 16:21:59.257381916 CET2352034217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:21:59.257714033 CET5203423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:21:59.263276100 CET2352034217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:00.408312082 CET5203623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:00.413872957 CET2352036217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:00.413984060 CET5203623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:00.414658070 CET5203623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:00.419954062 CET2352036217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:00.420109987 CET5203623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:00.425463915 CET2352036217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:04.471054077 CET42836443192.168.2.2391.189.91.43
                                                              Oct 30, 2024 16:22:08.566765070 CET4251680192.168.2.23109.202.202.202
                                                              Oct 30, 2024 16:22:08.895020962 CET2352036217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:08.895474911 CET5203623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:08.901097059 CET2352036217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:09.942529917 CET5203823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:09.947993040 CET2352038217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:09.948177099 CET5203823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:09.949166059 CET5203823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:09.954504013 CET2352038217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:09.954571962 CET5203823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:09.960633993 CET2352038217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:18.433109045 CET2352038217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:18.433479071 CET5203823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:18.438911915 CET2352038217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:19.475086927 CET5204023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:19.480556011 CET2352040217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:19.480674982 CET5204023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:19.481287003 CET5204023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:19.486759901 CET2352040217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:19.486829042 CET5204023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:19.492172956 CET2352040217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:27.972873926 CET2352040217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:27.973141909 CET5204023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:27.978645086 CET2352040217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:29.015626907 CET5204223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:29.021064043 CET2352042217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:29.021150112 CET5204223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:29.021794081 CET5204223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:29.027098894 CET2352042217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:29.027188063 CET5204223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:29.032550097 CET2352042217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:33.139127970 CET43928443192.168.2.2391.189.91.42
                                                              Oct 30, 2024 16:22:37.489888906 CET2352042217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:37.490215063 CET5204223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:37.495733023 CET2352042217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:38.534632921 CET5204423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:38.540080070 CET2352044217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:38.540141106 CET5204423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:38.540968895 CET5204423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:38.546698093 CET2352044217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:38.546758890 CET5204423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:38.552280903 CET2352044217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:47.017287970 CET2352044217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:47.017682076 CET5204423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:47.023191929 CET2352044217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:48.057739019 CET5204623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:48.063256025 CET2352046217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:48.063349009 CET5204623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:48.063980103 CET5204623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:48.069397926 CET2352046217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:48.069482088 CET5204623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:48.074942112 CET2352046217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:56.548197985 CET2352046217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:56.548506021 CET5204623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:56.554703951 CET2352046217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:57.590125084 CET5204823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:57.595519066 CET2352048217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:57.595640898 CET5204823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:57.596700907 CET5204823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:57.602036953 CET2352048217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:22:57.602107048 CET5204823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:22:57.607472897 CET2352048217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:06.081990957 CET2352048217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:06.082227945 CET5204823192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:06.088572979 CET2352048217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:07.124819994 CET5205023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:07.130183935 CET2352050217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:07.130270004 CET5205023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:07.130999088 CET5205023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:07.136378050 CET2352050217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:07.136430979 CET5205023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:07.141735077 CET2352050217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:15.613650084 CET2352050217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:15.613851070 CET5205023192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:15.619324923 CET2352050217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:16.657960892 CET5205223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:16.663959026 CET2352052217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:16.664087057 CET5205223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:16.665597916 CET5205223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:16.671006918 CET2352052217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:16.671087027 CET5205223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:16.676500082 CET2352052217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:25.147727966 CET2352052217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:25.147902966 CET5205223192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:25.153640985 CET2352052217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:26.193013906 CET5205423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:26.198838949 CET2352054217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:26.198970079 CET5205423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:26.200243950 CET5205423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:26.205950022 CET2352054217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:26.206008911 CET5205423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:26.211410999 CET2352054217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:34.683727026 CET2352054217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:34.684012890 CET5205423192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:34.689441919 CET2352054217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:35.730521917 CET5205623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:35.736834049 CET2352056217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:35.736901999 CET5205623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:35.737514019 CET5205623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:35.745265961 CET2352056217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:35.745326042 CET5205623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:35.954324007 CET5205623192.168.2.23217.32.184.17
                                                              Oct 30, 2024 16:23:35.983309031 CET2352056217.32.184.17192.168.2.23
                                                              Oct 30, 2024 16:23:35.983345985 CET2352056217.32.184.17192.168.2.23
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Oct 30, 2024 16:21:31.601630926 CET5640853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:31.608814955 CET53564088.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:31.622577906 CET3990053192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:31.630218029 CET53399008.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:31.646279097 CET5185953192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:31.653383970 CET53518598.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:31.655361891 CET4658553192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:31.662230015 CET53465858.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:31.675035000 CET5814153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:31.682239056 CET53581418.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:41.191107035 CET5199153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:41.198045015 CET53519918.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:41.198856115 CET3533553192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:41.205888033 CET53353358.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:41.206680059 CET5830953192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:41.214335918 CET53583098.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:41.215241909 CET4632453192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:41.222682953 CET53463248.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:41.223599911 CET4896753192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:41.230498075 CET53489678.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:50.724518061 CET6001853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:50.732115030 CET53600188.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:50.733203888 CET3683853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:50.741580963 CET53368388.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:50.742547035 CET5261753192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:50.750623941 CET53526178.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:50.751503944 CET5642253192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:50.758830070 CET53564228.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:21:50.759622097 CET4164153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:21:50.767219067 CET53416418.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:00.259654999 CET4185153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:00.376141071 CET53418518.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:00.377341032 CET4971653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:00.385050058 CET53497168.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:00.386045933 CET4472653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:00.392735958 CET53447268.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:00.393538952 CET4238053192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:00.400212049 CET53423808.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:00.400980949 CET5774753192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:00.407918930 CET53577478.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:09.898133993 CET3482053192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:09.905396938 CET53348208.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:09.906776905 CET4938153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:09.914839029 CET53493818.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:09.916009903 CET6056953192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:09.923979044 CET53605698.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:09.925093889 CET3557653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:09.933309078 CET53355768.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:09.934500933 CET5458053192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:09.941879034 CET53545808.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:19.435373068 CET4540853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:19.442362070 CET53454088.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:19.443068981 CET4442653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:19.450432062 CET53444268.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:19.451106071 CET5864853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:19.458175898 CET53586488.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:19.458838940 CET5400553192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:19.465919971 CET53540058.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:19.466562986 CET4680253192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:19.474704027 CET53468028.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:28.975029945 CET4046053192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:28.982084990 CET53404608.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:28.982932091 CET3863553192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:28.990413904 CET53386358.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:28.991192102 CET5689753192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:28.999206066 CET53568978.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:29.000010014 CET4861553192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:29.007570982 CET53486158.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:29.008284092 CET3809353192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:29.015225887 CET53380938.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:38.492350101 CET4833753192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:38.501086950 CET53483378.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:38.501924992 CET4229353192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:38.510072947 CET53422938.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:38.510740995 CET3436353192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:38.518110991 CET53343638.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:38.518713951 CET5714553192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:38.526408911 CET53571458.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:38.527102947 CET5042353192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:38.534141064 CET53504238.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:48.019476891 CET3299453192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:48.026753902 CET53329948.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:48.027489901 CET3486253192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:48.034239054 CET53348628.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:48.034889936 CET3375953192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:48.041908979 CET53337598.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:48.042607069 CET5983853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:48.049696922 CET53598388.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:48.050395966 CET5276653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:48.057320118 CET53527668.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:57.551023960 CET5746653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:57.558233976 CET53574668.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:57.559367895 CET5967953192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:57.566469908 CET53596798.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:57.567167997 CET5138953192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:57.574096918 CET53513898.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:57.574726105 CET3522853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:57.582097054 CET53352288.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:22:57.582921982 CET4058153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:22:57.589734077 CET53405818.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:07.084248066 CET3716453192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:07.091480970 CET53371648.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:07.092398882 CET5203153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:07.099858046 CET53520318.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:07.100656033 CET6038753192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:07.107964039 CET53603878.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:07.109081984 CET4396953192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:07.116219044 CET53439698.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:07.116983891 CET4507153192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:07.124420881 CET53450718.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:16.616031885 CET4990253192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:16.623163939 CET53499028.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:16.624021053 CET5724453192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:16.631994963 CET53572448.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:16.632792950 CET4030353192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:16.639869928 CET53403038.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:16.640871048 CET3767353192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:16.648363113 CET53376738.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:16.649224997 CET3852453192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:16.657246113 CET53385248.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:26.150671959 CET5928653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:26.157771111 CET53592868.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:26.158807039 CET4270053192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:26.166498899 CET53427008.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:26.167356968 CET5049053192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:26.174660921 CET53504908.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:26.175441980 CET3798253192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:26.183775902 CET53379828.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:26.184890985 CET3913753192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:26.192445993 CET53391378.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:35.686752081 CET3847253192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:35.694880962 CET53384728.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:35.695703983 CET5956553192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:35.703185081 CET53595658.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:35.703882933 CET5246653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:35.711896896 CET53524668.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:35.712596893 CET4611853192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:35.719867945 CET53461188.8.8.8192.168.2.23
                                                              Oct 30, 2024 16:23:35.720618963 CET4917653192.168.2.238.8.8.8
                                                              Oct 30, 2024 16:23:35.730128050 CET53491768.8.8.8192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):15:21:30
                                                              Start date (UTC):30/10/2024
                                                              Path:/tmp/vhsr56PI3r.elf
                                                              Arguments:/tmp/vhsr56PI3r.elf
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                              Start time (UTC):15:21:30
                                                              Start date (UTC):30/10/2024
                                                              Path:/tmp/vhsr56PI3r.elf
                                                              Arguments:-
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                              Start time (UTC):15:21:30
                                                              Start date (UTC):30/10/2024
                                                              Path:/tmp/vhsr56PI3r.elf
                                                              Arguments:-
                                                              File size:5388968 bytes
                                                              MD5 hash:ae65271c943d3451b7f026d1fadccea6