Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
8RFfyRrdWT.elf

Overview

General Information

Sample name:8RFfyRrdWT.elf
renamed because original name is a hash value
Original sample name:72e2005ca58f9bafb342fff906042766.elf
Analysis ID:1545507
MD5:72e2005ca58f9bafb342fff906042766
SHA1:cefb9aea7f27bb907a79a401a986619997d1983b
SHA256:f60766a94bbda92a2bab16cc02733929bd837fe67f36ed02cf73abeac2b40a31
Tags:32elfmiraisparc
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1545507
Start date and time:2024-10-30 16:21:58 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:8RFfyRrdWT.elf
renamed because original name is a hash value
Original Sample Name:72e2005ca58f9bafb342fff906042766.elf
Detection:MAL
Classification:mal56.linELF@0/0@75/0
  • VT rate limit hit for: 8RFfyRrdWT.elf
Command:/tmp/8RFfyRrdWT.elf
PID:5412
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
unstable_is_the_history_of_universe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
8RFfyRrdWT.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xaee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb00c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb05c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb070:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5412.1.00007f94ac02c000.00007f94ac02d000.rw-.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xd4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xe8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x124:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x138:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x14c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x160:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x174:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x188:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x19c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5412.1.00007f94ac011000.00007f94ac01d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xaee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaf94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xafe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb00c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb05c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb070:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: 8RFfyRrdWT.elf PID: 5412Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x871:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x885:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x899:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x8ad:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x8c1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x8d5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x8e9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x8fd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x911:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x925:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x939:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x94d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x961:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x975:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x989:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x99d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x9b1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x9c5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x9d9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x9ed:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa01:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 8RFfyRrdWT.elfReversingLabs: Detection: 42%
Source: /tmp/8RFfyRrdWT.elf (PID: 5412)Socket: 127.0.0.1:46157Jump to behavior
Source: unknownDNS traffic detected: query: 154.216.20.94 replaycode: Name error (3)
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: unknownTCP traffic detected without corresponding DNS query: 217.32.184.17
Source: global trafficDNS traffic detected: DNS query: 154.216.20.94

System Summary

barindex
Source: 8RFfyRrdWT.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5412.1.00007f94ac02c000.00007f94ac02d000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5412.1.00007f94ac011000.00007f94ac01d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: 8RFfyRrdWT.elf PID: 5412, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: 8RFfyRrdWT.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5412.1.00007f94ac02c000.00007f94ac02d000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5412.1.00007f94ac011000.00007f94ac01d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: 8RFfyRrdWT.elf PID: 5412, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal56.linELF@0/0@75/0
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/230/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/110/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/231/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/111/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/232/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/112/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/233/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/113/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/234/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/114/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/235/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/115/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/236/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/116/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/237/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/117/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/238/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/118/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/239/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/119/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/914/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/10/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/917/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/11/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/12/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/13/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/14/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/15/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/5397/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/16/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/3770/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/5398/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/17/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/18/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/19/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/240/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/3095/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/120/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/241/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/121/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/242/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/1/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/122/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/243/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/2/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/123/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/244/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/3/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/124/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/245/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/1588/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/125/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/4/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/246/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/126/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/5/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/247/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/127/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/6/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/248/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/128/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/7/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/249/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/129/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/8/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/800/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/9/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/1906/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/802/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/803/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/20/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/21/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/22/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/23/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/24/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/25/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/5044/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/26/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/27/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/28/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/29/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/3420/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/1482/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/490/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/1480/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/250/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/371/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/130/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/251/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/131/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/252/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/132/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/253/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/254/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/1238/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/134/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/255/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/256/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/257/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/378/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/3413/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/258/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/259/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/1475/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5418)File opened: /proc/936/cmdlineJump to behavior
Source: /tmp/8RFfyRrdWT.elf (PID: 5412)Queries kernel information via 'uname': Jump to behavior
Source: 8RFfyRrdWT.elf, 5412.1.0000561048241000.00005610482a6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
Source: 8RFfyRrdWT.elf, 5412.1.0000561048241000.00005610482a6000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/sparc
Source: 8RFfyRrdWT.elf, 5412.1.00007ffd1afe4000.00007ffd1b005000.rw-.sdmpBinary or memory string: A=Dx86_64/usr/bin/qemu-sparc/tmp/8RFfyRrdWT.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/8RFfyRrdWT.elf
Source: 8RFfyRrdWT.elf, 5412.1.00007ffd1afe4000.00007ffd1b005000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
8RFfyRrdWT.elf42%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
154.216.20.94
unknown
unknowntrue
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    217.32.184.17
    unknownUnited Kingdom
    6871PLUSNETUKInternetServiceProviderGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    217.32.184.17vhsr56PI3r.elfGet hashmaliciousUnknownBrowse
      TXVo7pIaEB.elfGet hashmaliciousUnknownBrowse
        CaKRRsqLWL.elfGet hashmaliciousUnknownBrowse
          7GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
            sora.arm.elfGet hashmaliciousUnknownBrowse
              sora.mips.elfGet hashmaliciousUnknownBrowse
                sora.mpsl.elfGet hashmaliciousUnknownBrowse
                  sora.x86.elfGet hashmaliciousUnknownBrowse
                    sh4.elfGet hashmaliciousUnknownBrowse
                      debug.dbg.elfGet hashmaliciousMiraiBrowse
                        No context
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        PLUSNETUKInternetServiceProviderGBvhsr56PI3r.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        TXVo7pIaEB.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        CaKRRsqLWL.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        7GxZ3z6CMA.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        sora.arm.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        sora.mips.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        sora.mpsl.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        sora.x86.elfGet hashmaliciousUnknownBrowse
                        • 217.32.184.17
                        jew.mpsl.elfGet hashmaliciousMiraiBrowse
                        • 143.159.228.252
                        arm5.elfGet hashmaliciousUnknownBrowse
                        • 84.93.57.1
                        No context
                        No context
                        No created / dropped files found
                        File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                        Entropy (8bit):6.082206220382103
                        TrID:
                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                        File name:8RFfyRrdWT.elf
                        File size:48'848 bytes
                        MD5:72e2005ca58f9bafb342fff906042766
                        SHA1:cefb9aea7f27bb907a79a401a986619997d1983b
                        SHA256:f60766a94bbda92a2bab16cc02733929bd837fe67f36ed02cf73abeac2b40a31
                        SHA512:b2847ca2bc9da7a6a13a53cd6f4b4a2c5b37d6ce3026b7436e778954f11a6bb235570b5298d13fc7bdaf5b1ff20b5a5711350a925b7af98392f59402238fa843
                        SSDEEP:768:3BoBCKHvxxNDs+trBy1ZBpUc7X8slf4AQjqO++PWuVOw4:3B8zHvxnjrBy1/pUcT8sSAQj4+uq4
                        TLSH:CD232A35BA761F17C0D168B521FB4B6876F146CE26A8CA4E3DB20D9EFF618406503AF4
                        File Content Preview:.ELF...........................4...@.....4. ...(.......................................................4............dt.Q................................@..(....@.+<................#.....a...`.....!....."...@.....".........`......$"..."...@...........`....

                        ELF header

                        Class:ELF32
                        Data:2's complement, big endian
                        Version:1 (current)
                        Machine:Sparc
                        Version Number:0x1
                        Type:EXEC (Executable file)
                        OS/ABI:UNIX - System V
                        ABI Version:0
                        Entry Point Address:0x101a4
                        Flags:0x0
                        ELF Header Size:52
                        Program Header Offset:52
                        Program Header Size:32
                        Number of Program Headers:3
                        Section Header Offset:48448
                        Section Header Size:40
                        Number of Section Headers:10
                        Header String Table Index:9
                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                        NULL0x00x00x00x00x0000
                        .initPROGBITS0x100940x940x1c0x00x6AX004
                        .textPROGBITS0x100b00xb00xad280x00x6AX004
                        .finiPROGBITS0x1add80xadd80x140x00x6AX004
                        .rodataPROGBITS0x1adf00xadf00xcd80x00x2A008
                        .ctorsPROGBITS0x2bacc0xbacc0x80x00x3WA004
                        .dtorsPROGBITS0x2bad40xbad40x80x00x3WA004
                        .dataPROGBITS0x2bae00xbae00x2200x00x3WA008
                        .bssNOBITS0x2bd000xbd000x1900x00x3WA004
                        .shstrtabSTRTAB0x00xbd000x3e0x00x0001
                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                        LOAD0x00x100000x100000xbac80xbac86.11350x5R E0x10000.init .text .fini .rodata
                        LOAD0xbacc0x2bacc0x2bacc0x2340x3c42.96200x6RW 0x10000.ctors .dtors .data .bss
                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 30, 2024 16:22:46.587678909 CET3706823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:46.593059063 CET2337068217.32.184.17192.168.2.13
                        Oct 30, 2024 16:22:46.593113899 CET3706823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:46.596103907 CET3706823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:46.601624012 CET2337068217.32.184.17192.168.2.13
                        Oct 30, 2024 16:22:46.601666927 CET3706823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:46.607033014 CET2337068217.32.184.17192.168.2.13
                        Oct 30, 2024 16:22:55.078583002 CET2337068217.32.184.17192.168.2.13
                        Oct 30, 2024 16:22:55.078943014 CET3706823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:55.084552050 CET2337068217.32.184.17192.168.2.13
                        Oct 30, 2024 16:22:55.123159885 CET3707023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:55.128524065 CET2337070217.32.184.17192.168.2.13
                        Oct 30, 2024 16:22:55.128592014 CET3707023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:55.129170895 CET3707023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:55.134521008 CET2337070217.32.184.17192.168.2.13
                        Oct 30, 2024 16:22:55.134601116 CET3707023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:22:55.139986038 CET2337070217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:03.603796959 CET2337070217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:03.603971004 CET3707023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:03.609442949 CET2337070217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:03.645944118 CET3707223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:03.651391983 CET2337072217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:03.651467085 CET3707223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:03.652054071 CET3707223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:03.657382011 CET2337072217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:03.657428026 CET3707223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:03.662934065 CET2337072217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:12.145670891 CET2337072217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:12.145982981 CET3707223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:12.153146982 CET2337072217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:12.193511009 CET3707423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:12.198940992 CET2337074217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:12.199006081 CET3707423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:12.199613094 CET3707423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:12.205461979 CET2337074217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:12.205518961 CET3707423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:12.211191893 CET2337074217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:20.702850103 CET2337074217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:20.703154087 CET3707423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:20.708656073 CET2337074217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:20.757117987 CET3707623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:20.762557030 CET2337076217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:20.762645960 CET3707623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:20.763504982 CET3707623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:20.768942118 CET2337076217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:20.769012928 CET3707623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:20.774406910 CET2337076217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:29.254738092 CET2337076217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:29.254991055 CET3707623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:29.260647058 CET2337076217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:29.300962925 CET3707823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:29.306516886 CET2337078217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:29.306608915 CET3707823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:29.307447910 CET3707823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:29.313057899 CET2337078217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:29.313123941 CET3707823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:29.318701029 CET2337078217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:37.803114891 CET2337078217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:37.803435087 CET3707823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:37.810652971 CET2337078217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:37.850707054 CET3708023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:37.856472015 CET2337080217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:37.856534004 CET3708023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:37.857180119 CET3708023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:37.863605976 CET2337080217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:37.863655090 CET3708023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:37.870242119 CET2337080217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:46.344074965 CET2337080217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:46.344737053 CET3708023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:46.350373030 CET2337080217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:46.390769958 CET3708223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:46.396224976 CET2337082217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:46.396286964 CET3708223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:46.396837950 CET3708223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:46.402605057 CET2337082217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:46.402653933 CET3708223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:46.408210039 CET2337082217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:54.873209000 CET2337082217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:54.873605967 CET3708223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:54.879380941 CET2337082217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:54.918545961 CET3708423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:54.924037933 CET2337084217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:54.924159050 CET3708423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:54.924885035 CET3708423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:54.930567026 CET2337084217.32.184.17192.168.2.13
                        Oct 30, 2024 16:23:54.930625916 CET3708423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:23:54.936826944 CET2337084217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:03.487349033 CET2337084217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:03.487642050 CET3708423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:03.493591070 CET2337084217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:03.538548946 CET3708623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:03.544440985 CET2337086217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:03.544539928 CET3708623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:03.545397997 CET3708623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:03.550846100 CET2337086217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:03.550895929 CET3708623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:03.556566954 CET2337086217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:12.050628901 CET2337086217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:12.051136971 CET3708623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:12.056565046 CET2337086217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:12.093909979 CET3708823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:12.099309921 CET2337088217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:12.099428892 CET3708823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:12.100198030 CET3708823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:12.105573893 CET2337088217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:12.105629921 CET3708823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:12.113136053 CET2337088217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:20.589932919 CET2337088217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:20.590161085 CET3708823192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:20.595797062 CET2337088217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:20.633625031 CET3709023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:20.639451027 CET2337090217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:20.639523029 CET3709023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:20.640208960 CET3709023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:20.645982027 CET2337090217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:20.646045923 CET3709023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:20.651498079 CET2337090217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:29.130831003 CET2337090217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:29.131011963 CET3709023192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:29.136420965 CET2337090217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:29.173718929 CET3709223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:29.179119110 CET2337092217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:29.179188967 CET3709223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:29.179747105 CET3709223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:29.185450077 CET2337092217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:29.185497046 CET3709223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:29.190918922 CET2337092217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:37.659410954 CET2337092217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:37.659744978 CET3709223192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:37.665198088 CET2337092217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:37.704087019 CET3709423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:37.709403038 CET2337094217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:37.709486008 CET3709423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:37.710120916 CET3709423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:37.715430021 CET2337094217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:37.715486050 CET3709423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:37.720762968 CET2337094217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:46.186145067 CET2337094217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:46.186554909 CET3709423192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:46.191967964 CET2337094217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:46.232714891 CET3709623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:46.238176107 CET2337096217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:46.238388062 CET3709623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:46.238939047 CET3709623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:46.244288921 CET2337096217.32.184.17192.168.2.13
                        Oct 30, 2024 16:24:46.244412899 CET3709623192.168.2.13217.32.184.17
                        Oct 30, 2024 16:24:46.249790907 CET2337096217.32.184.17192.168.2.13
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 30, 2024 16:22:46.526479959 CET5551053192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:46.534171104 CET53555108.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:46.536000013 CET5739353192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:46.543768883 CET53573938.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:46.551937103 CET3652753192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:46.560094118 CET53365278.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:46.568427086 CET3541453192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:46.576227903 CET53354148.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:46.578541040 CET3535253192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:46.586136103 CET53353528.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:55.079936028 CET5211453192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:55.087599993 CET53521148.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:55.088258028 CET5509453192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:55.095614910 CET53550948.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:55.096362114 CET4206053192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:55.103931904 CET53420608.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:55.104573011 CET4739953192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:55.114751101 CET53473998.8.8.8192.168.2.13
                        Oct 30, 2024 16:22:55.115354061 CET5682653192.168.2.138.8.8.8
                        Oct 30, 2024 16:22:55.122858047 CET53568268.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:03.604722023 CET6095453192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:03.612960100 CET53609548.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:03.613660097 CET3903453192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:03.621026039 CET53390348.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:03.621710062 CET6032953192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:03.629415035 CET53603298.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:03.630038977 CET4536153192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:03.637494087 CET53453618.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:03.638112068 CET3852253192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:03.645633936 CET53385228.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:12.146962881 CET5369253192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:12.154937029 CET53536928.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:12.155757904 CET4641453192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:12.164872885 CET53464148.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:12.165709972 CET4891053192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:12.174416065 CET53489108.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:12.175187111 CET5329553192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:12.184381008 CET53532958.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:12.185103893 CET3425853192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:12.193092108 CET53342588.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:20.704646111 CET3641953192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:20.712259054 CET53364198.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:20.713258982 CET5592353192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:20.721508980 CET53559238.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:20.722424984 CET3794953192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:20.730483055 CET53379498.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:20.731091022 CET5529053192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:20.738913059 CET53552908.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:20.739531040 CET4073153192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:20.756752968 CET53407318.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:29.255974054 CET4003253192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:29.263624907 CET53400328.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:29.264544964 CET5306753192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:29.272664070 CET53530678.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:29.273583889 CET3500053192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:29.281577110 CET53350008.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:29.282566071 CET5652053192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:29.290754080 CET53565208.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:29.291661978 CET4949853192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:29.300508022 CET53494988.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:37.804591894 CET5581353192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:37.813570023 CET53558138.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:37.814587116 CET6090253192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:37.822484970 CET53609028.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:37.823375940 CET4329653192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:37.833065033 CET53432968.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:37.833926916 CET4919453192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:37.841703892 CET53491948.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:37.842551947 CET3712853192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:37.850361109 CET53371288.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:46.345634937 CET5945953192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:46.353590012 CET53594598.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:46.354299068 CET4296153192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:46.362977982 CET53429618.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:46.364126921 CET5013853192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:46.371736050 CET53501388.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:46.372549057 CET3305553192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:46.380625010 CET53330558.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:46.381458044 CET4313353192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:46.390419960 CET53431338.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:54.874372959 CET4986653192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:54.881877899 CET53498668.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:54.882776022 CET4789253192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:54.890746117 CET53478928.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:54.891447067 CET5481753192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:54.899434090 CET53548178.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:54.900190115 CET5509053192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:54.907911062 CET53550908.8.8.8192.168.2.13
                        Oct 30, 2024 16:23:54.908631086 CET5102653192.168.2.138.8.8.8
                        Oct 30, 2024 16:23:54.918150902 CET53510268.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:03.488759995 CET4411453192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:03.500910044 CET53441148.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:03.501703024 CET4144353192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:03.510473013 CET53414438.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:03.511173964 CET4176653192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:03.519413948 CET53417668.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:03.520275116 CET6091053192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:03.528368950 CET53609108.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:03.529236078 CET5574653192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:03.538079023 CET53557468.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:12.052077055 CET5347153192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:12.059695005 CET53534718.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:12.060470104 CET3759853192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:12.068063974 CET53375988.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:12.068881989 CET4035953192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:12.076467037 CET53403598.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:12.077209949 CET5552953192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:12.085011959 CET53555298.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:12.085817099 CET5772553192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:12.093410015 CET53577258.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:20.591033936 CET4247753192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:20.599351883 CET53424778.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:20.600055933 CET3860353192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:20.607884884 CET53386038.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:20.608572006 CET4816153192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:20.616223097 CET53481618.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:20.616966009 CET5686353192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:20.624743938 CET53568638.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:20.625719070 CET4528353192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:20.633145094 CET53452838.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:29.131731987 CET5281953192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:29.139581919 CET53528198.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:29.140235901 CET5395253192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:29.147707939 CET53539528.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:29.148318052 CET3767853192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:29.156039000 CET53376788.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:29.156611919 CET3930653192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:29.164690018 CET53393068.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:29.165278912 CET5948453192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:29.173408985 CET53594848.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:37.660399914 CET4164653192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:37.668658972 CET53416468.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:37.669416904 CET6020653192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:37.677551985 CET53602068.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:37.678200960 CET4049453192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:37.686120033 CET53404948.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:37.687079906 CET5447553192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:37.695101976 CET53544758.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:37.695766926 CET5519453192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:37.703747034 CET53551948.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:46.187290907 CET4070653192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:46.195673943 CET53407068.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:46.196321011 CET3785853192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:46.204185963 CET53378588.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:46.204832077 CET5643153192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:46.214128971 CET53564318.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:46.214745045 CET5008353192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:46.223581076 CET53500838.8.8.8192.168.2.13
                        Oct 30, 2024 16:24:46.224186897 CET3525453192.168.2.138.8.8.8
                        Oct 30, 2024 16:24:46.232323885 CET53352548.8.8.8192.168.2.13
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Oct 30, 2024 16:22:46.526479959 CET192.168.2.138.8.8.80x3b2Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.536000013 CET192.168.2.138.8.8.80x3b2Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.551937103 CET192.168.2.138.8.8.80x3b2Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.568427086 CET192.168.2.138.8.8.80x3b2Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.578541040 CET192.168.2.138.8.8.80x3b2Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.079936028 CET192.168.2.138.8.8.80x31d0Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.088258028 CET192.168.2.138.8.8.80x31d0Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.096362114 CET192.168.2.138.8.8.80x31d0Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.104573011 CET192.168.2.138.8.8.80x31d0Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.115354061 CET192.168.2.138.8.8.80x31d0Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.604722023 CET192.168.2.138.8.8.80xd54cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.613660097 CET192.168.2.138.8.8.80xd54cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.621710062 CET192.168.2.138.8.8.80xd54cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.630038977 CET192.168.2.138.8.8.80xd54cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.638112068 CET192.168.2.138.8.8.80xd54cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.146962881 CET192.168.2.138.8.8.80x83a8Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.155757904 CET192.168.2.138.8.8.80x83a8Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.165709972 CET192.168.2.138.8.8.80x83a8Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.175187111 CET192.168.2.138.8.8.80x83a8Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.185103893 CET192.168.2.138.8.8.80x83a8Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.704646111 CET192.168.2.138.8.8.80xc491Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.713258982 CET192.168.2.138.8.8.80xc491Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.722424984 CET192.168.2.138.8.8.80xc491Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.731091022 CET192.168.2.138.8.8.80xc491Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.739531040 CET192.168.2.138.8.8.80xc491Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.255974054 CET192.168.2.138.8.8.80x29Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.264544964 CET192.168.2.138.8.8.80x29Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.273583889 CET192.168.2.138.8.8.80x29Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.282566071 CET192.168.2.138.8.8.80x29Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.291661978 CET192.168.2.138.8.8.80x29Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.804591894 CET192.168.2.138.8.8.80x1a0bStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.814587116 CET192.168.2.138.8.8.80x1a0bStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.823375940 CET192.168.2.138.8.8.80x1a0bStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.833926916 CET192.168.2.138.8.8.80x1a0bStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.842551947 CET192.168.2.138.8.8.80x1a0bStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.345634937 CET192.168.2.138.8.8.80xe44cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.354299068 CET192.168.2.138.8.8.80xe44cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.364126921 CET192.168.2.138.8.8.80xe44cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.372549057 CET192.168.2.138.8.8.80xe44cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.381458044 CET192.168.2.138.8.8.80xe44cStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.874372959 CET192.168.2.138.8.8.80xa57eStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.882776022 CET192.168.2.138.8.8.80xa57eStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.891447067 CET192.168.2.138.8.8.80xa57eStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.900190115 CET192.168.2.138.8.8.80xa57eStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.908631086 CET192.168.2.138.8.8.80xa57eStandard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.488759995 CET192.168.2.138.8.8.80xef80Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.501703024 CET192.168.2.138.8.8.80xef80Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.511173964 CET192.168.2.138.8.8.80xef80Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.520275116 CET192.168.2.138.8.8.80xef80Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.529236078 CET192.168.2.138.8.8.80xef80Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.052077055 CET192.168.2.138.8.8.80xad75Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.060470104 CET192.168.2.138.8.8.80xad75Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.068881989 CET192.168.2.138.8.8.80xad75Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.077209949 CET192.168.2.138.8.8.80xad75Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.085817099 CET192.168.2.138.8.8.80xad75Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.591033936 CET192.168.2.138.8.8.80xb166Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.600055933 CET192.168.2.138.8.8.80xb166Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.608572006 CET192.168.2.138.8.8.80xb166Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.616966009 CET192.168.2.138.8.8.80xb166Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.625719070 CET192.168.2.138.8.8.80xb166Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.131731987 CET192.168.2.138.8.8.80x7a42Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.140235901 CET192.168.2.138.8.8.80x7a42Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.148318052 CET192.168.2.138.8.8.80x7a42Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.156611919 CET192.168.2.138.8.8.80x7a42Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.165278912 CET192.168.2.138.8.8.80x7a42Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.660399914 CET192.168.2.138.8.8.80x7a7Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.669416904 CET192.168.2.138.8.8.80x7a7Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.678200960 CET192.168.2.138.8.8.80x7a7Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.687079906 CET192.168.2.138.8.8.80x7a7Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.695766926 CET192.168.2.138.8.8.80x7a7Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.187290907 CET192.168.2.138.8.8.80x11d3Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.196321011 CET192.168.2.138.8.8.80x11d3Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.204832077 CET192.168.2.138.8.8.80x11d3Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.214745045 CET192.168.2.138.8.8.80x11d3Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.224186897 CET192.168.2.138.8.8.80x11d3Standard query (0)154.216.20.94A (IP address)IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Oct 30, 2024 16:22:46.534171104 CET8.8.8.8192.168.2.130x3b2Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.543768883 CET8.8.8.8192.168.2.130x3b2Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.560094118 CET8.8.8.8192.168.2.130x3b2Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.576227903 CET8.8.8.8192.168.2.130x3b2Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:46.586136103 CET8.8.8.8192.168.2.130x3b2Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.087599993 CET8.8.8.8192.168.2.130x31d0Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.095614910 CET8.8.8.8192.168.2.130x31d0Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.103931904 CET8.8.8.8192.168.2.130x31d0Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.114751101 CET8.8.8.8192.168.2.130x31d0Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:22:55.122858047 CET8.8.8.8192.168.2.130x31d0Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.612960100 CET8.8.8.8192.168.2.130xd54cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.621026039 CET8.8.8.8192.168.2.130xd54cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.629415035 CET8.8.8.8192.168.2.130xd54cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.637494087 CET8.8.8.8192.168.2.130xd54cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:03.645633936 CET8.8.8.8192.168.2.130xd54cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.154937029 CET8.8.8.8192.168.2.130x83a8Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.164872885 CET8.8.8.8192.168.2.130x83a8Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.174416065 CET8.8.8.8192.168.2.130x83a8Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.184381008 CET8.8.8.8192.168.2.130x83a8Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:12.193092108 CET8.8.8.8192.168.2.130x83a8Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.712259054 CET8.8.8.8192.168.2.130xc491Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.721508980 CET8.8.8.8192.168.2.130xc491Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.730483055 CET8.8.8.8192.168.2.130xc491Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.738913059 CET8.8.8.8192.168.2.130xc491Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:20.756752968 CET8.8.8.8192.168.2.130xc491Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.263624907 CET8.8.8.8192.168.2.130x29Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.272664070 CET8.8.8.8192.168.2.130x29Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.281577110 CET8.8.8.8192.168.2.130x29Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.290754080 CET8.8.8.8192.168.2.130x29Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:29.300508022 CET8.8.8.8192.168.2.130x29Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.813570023 CET8.8.8.8192.168.2.130x1a0bName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.822484970 CET8.8.8.8192.168.2.130x1a0bName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.833065033 CET8.8.8.8192.168.2.130x1a0bName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.841703892 CET8.8.8.8192.168.2.130x1a0bName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:37.850361109 CET8.8.8.8192.168.2.130x1a0bName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.353590012 CET8.8.8.8192.168.2.130xe44cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.362977982 CET8.8.8.8192.168.2.130xe44cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.371736050 CET8.8.8.8192.168.2.130xe44cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.380625010 CET8.8.8.8192.168.2.130xe44cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:46.390419960 CET8.8.8.8192.168.2.130xe44cName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.881877899 CET8.8.8.8192.168.2.130xa57eName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.890746117 CET8.8.8.8192.168.2.130xa57eName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.899434090 CET8.8.8.8192.168.2.130xa57eName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.907911062 CET8.8.8.8192.168.2.130xa57eName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:23:54.918150902 CET8.8.8.8192.168.2.130xa57eName error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.500910044 CET8.8.8.8192.168.2.130xef80Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.510473013 CET8.8.8.8192.168.2.130xef80Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.519413948 CET8.8.8.8192.168.2.130xef80Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.528368950 CET8.8.8.8192.168.2.130xef80Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:03.538079023 CET8.8.8.8192.168.2.130xef80Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.059695005 CET8.8.8.8192.168.2.130xad75Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.068063974 CET8.8.8.8192.168.2.130xad75Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.076467037 CET8.8.8.8192.168.2.130xad75Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.085011959 CET8.8.8.8192.168.2.130xad75Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:12.093410015 CET8.8.8.8192.168.2.130xad75Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.599351883 CET8.8.8.8192.168.2.130xb166Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.607884884 CET8.8.8.8192.168.2.130xb166Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.616223097 CET8.8.8.8192.168.2.130xb166Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.624743938 CET8.8.8.8192.168.2.130xb166Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:20.633145094 CET8.8.8.8192.168.2.130xb166Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.139581919 CET8.8.8.8192.168.2.130x7a42Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.147707939 CET8.8.8.8192.168.2.130x7a42Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.156039000 CET8.8.8.8192.168.2.130x7a42Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.164690018 CET8.8.8.8192.168.2.130x7a42Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:29.173408985 CET8.8.8.8192.168.2.130x7a42Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.668658972 CET8.8.8.8192.168.2.130x7a7Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.677551985 CET8.8.8.8192.168.2.130x7a7Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.686120033 CET8.8.8.8192.168.2.130x7a7Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.695101976 CET8.8.8.8192.168.2.130x7a7Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:37.703747034 CET8.8.8.8192.168.2.130x7a7Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.195673943 CET8.8.8.8192.168.2.130x11d3Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.204185963 CET8.8.8.8192.168.2.130x11d3Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.214128971 CET8.8.8.8192.168.2.130x11d3Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.223581076 CET8.8.8.8192.168.2.130x11d3Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false
                        Oct 30, 2024 16:24:46.232323885 CET8.8.8.8192.168.2.130x11d3Name error (3)154.216.20.94nonenoneA (IP address)IN (0x0001)false

                        System Behavior

                        Start time (UTC):15:22:45
                        Start date (UTC):30/10/2024
                        Path:/tmp/8RFfyRrdWT.elf
                        Arguments:/tmp/8RFfyRrdWT.elf
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                        Start time (UTC):15:22:46
                        Start date (UTC):30/10/2024
                        Path:/tmp/8RFfyRrdWT.elf
                        Arguments:-
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                        Start time (UTC):15:22:46
                        Start date (UTC):30/10/2024
                        Path:/tmp/8RFfyRrdWT.elf
                        Arguments:-
                        File size:4379400 bytes
                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e