Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
4l9YKCc7qQ.elf

Overview

General Information

Sample name:4l9YKCc7qQ.elf
renamed because original name is a hash value
Original sample name:9008278c8d10f1fd784983ffc069faec.elf
Analysis ID:1546902
MD5:9008278c8d10f1fd784983ffc069faec
SHA1:14a1a461deb79a39ca005346e38b0481f6946c30
SHA256:4bee1419ae6dcdee90de4ba370577d2713743d4a472eb2b1332340cef1422662
Tags:32elfmipsmirai
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1546902
Start date and time:2024-11-01 17:27:03 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:4l9YKCc7qQ.elf
renamed because original name is a hash value
Original Sample Name:9008278c8d10f1fd784983ffc069faec.elf
Detection:MAL
Classification:mal56.linELF@0/0@0/0
  • VT rate limit hit for: 4l9YKCc7qQ.elf
Command:/tmp/4l9YKCc7qQ.elf
PID:6217
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
DaddyL33T Infected Your Shit
Standard Error:
  • system is lnxubuntu20
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: 4l9YKCc7qQ.elfAvira: detected
Source: 4l9YKCc7qQ.elfReversingLabs: Detection: 71%
Source: global trafficTCP traffic: 192.168.2.23:42882 -> 95.164.4.65:666
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownTCP traffic detected without corresponding DNS query: 95.164.4.65
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.linELF@0/0@0/0
Source: /tmp/4l9YKCc7qQ.elf (PID: 6217)Queries kernel information via 'uname': Jump to behavior
Source: 4l9YKCc7qQ.elf, 6217.1.00007ffc1ee0c000.00007ffc1ee2d000.rw-.sdmp, 4l9YKCc7qQ.elf, 6220.1.00007ffc1ee0c000.00007ffc1ee2d000.rw-.sdmp, 4l9YKCc7qQ.elf, 6224.1.00007ffc1ee0c000.00007ffc1ee2d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/4l9YKCc7qQ.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/4l9YKCc7qQ.elf
Source: 4l9YKCc7qQ.elf, 6217.1.000055b175e6d000.000055b175ef4000.rw-.sdmp, 4l9YKCc7qQ.elf, 6220.1.000055b175e6d000.000055b175ef4000.rw-.sdmp, 4l9YKCc7qQ.elf, 6224.1.000055b175e6d000.000055b175ef4000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: 4l9YKCc7qQ.elf, 6217.1.000055b175e6d000.000055b175ef4000.rw-.sdmp, 4l9YKCc7qQ.elf, 6220.1.000055b175e6d000.000055b175ef4000.rw-.sdmp, 4l9YKCc7qQ.elf, 6224.1.000055b175e6d000.000055b175ef4000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: 4l9YKCc7qQ.elf, 6217.1.00007ffc1ee0c000.00007ffc1ee2d000.rw-.sdmp, 4l9YKCc7qQ.elf, 6220.1.00007ffc1ee0c000.00007ffc1ee2d000.rw-.sdmp, 4l9YKCc7qQ.elf, 6224.1.00007ffc1ee0c000.00007ffc1ee2d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1546902 Sample: 4l9YKCc7qQ.elf Startdate: 01/11/2024 Architecture: LINUX Score: 56 16 95.164.4.65, 42882, 42884, 42886 NASSIST-ASGI Gibraltar 2->16 18 109.202.202.202, 80 INIT7CH Switzerland 2->18 20 2 other IPs or domains 2->20 22 Antivirus / Scanner detection for submitted sample 2->22 24 Multi AV Scanner detection for submitted file 2->24 8 4l9YKCc7qQ.elf 2->8         started        signatures3 process4 process5 10 4l9YKCc7qQ.elf 8->10         started        12 4l9YKCc7qQ.elf 8->12         started        process6 14 4l9YKCc7qQ.elf 10->14         started       
SourceDetectionScannerLabelLink
4l9YKCc7qQ.elf71%ReversingLabsLinux.Trojan.Mirai
4l9YKCc7qQ.elf100%AviraEXP/ELF.Mirai.T
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
95.164.4.65
unknownGibraltar
29632NASSIST-ASGIfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
95.164.4.65Josho.arm7.elfGet hashmaliciousMiraiBrowse
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
      mips.elfGet hashmaliciousGafgyt, MiraiBrowse
        meow.arm7.elfGet hashmaliciousUnknownBrowse
          main_arm.elfGet hashmaliciousMiraiBrowse
            dlr.x86.elfGet hashmaliciousOkiruBrowse
              dlr.ppc.elfGet hashmaliciousUnknownBrowse
                zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                  zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                    zmap.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                      main_ppc.elfGet hashmaliciousMiraiBrowse
                        91.189.91.42mips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                          x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                            mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                              meow.arm7.elfGet hashmaliciousUnknownBrowse
                                main_arm.elfGet hashmaliciousMiraiBrowse
                                  dlr.x86.elfGet hashmaliciousOkiruBrowse
                                    dlr.ppc.elfGet hashmaliciousUnknownBrowse
                                      zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                        zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                          zmap.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBmips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 185.125.190.26
                                            meow.arm7.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            dlr.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            dlr.x86.elfGet hashmaliciousOkiruBrowse
                                            • 91.189.91.42
                                            dlr.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBmips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 91.189.91.42
                                            armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 185.125.190.26
                                            meow.arm7.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            dlr.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            dlr.x86.elfGet hashmaliciousOkiruBrowse
                                            • 91.189.91.42
                                            dlr.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 91.189.91.42
                                            NASSIST-ASGIJosho.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 95.164.4.65
                                            J3m5xLlT8D.exeGet hashmaliciousDCRatBrowse
                                            • 95.164.6.175
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            na.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            SecuriteInfo.com.ELF.Mirai-CVD.31968.3467.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            SecuriteInfo.com.ELF.Mirai-CVD.11330.22523.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            SecuriteInfo.com.ELF.Mirai-CVD.17384.13664.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            SecuriteInfo.com.ELF.Mirai-CVD.12952.14309.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            SecuriteInfo.com.ELF.Mirai-CVD.5487.13505.elfGet hashmaliciousUnknownBrowse
                                            • 94.131.118.154
                                            INIT7CHmips64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 109.202.202.202
                                            x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 109.202.202.202
                                            mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            • 109.202.202.202
                                            meow.arm7.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            dlr.x86.elfGet hashmaliciousOkiruBrowse
                                            • 109.202.202.202
                                            dlr.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            zmap.arm.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            zmap.sh4.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            zmap.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.395820097704116
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:4l9YKCc7qQ.elf
                                            File size:69'100 bytes
                                            MD5:9008278c8d10f1fd784983ffc069faec
                                            SHA1:14a1a461deb79a39ca005346e38b0481f6946c30
                                            SHA256:4bee1419ae6dcdee90de4ba370577d2713743d4a472eb2b1332340cef1422662
                                            SHA512:cd4154033799a05942f2d1a798df3f9e022315c4badebb77803d28de436b58b8664f7317bb53491eeb4190c151992e2dade6f0d28bba839a89246e260bfe22ff
                                            SSDEEP:768:sklXdDZfWi+DmBfizI8CZ0vwLlyitTDdtTPFSWcRjX+CPPota93pWj4UpapRr4+G:3fiza0vwhyGbcR0a936oRc+gR
                                            TLSH:2563C71A6E168FECF79A973547B7CB15964C37862AA2C5C5E04EDB011E7024E340FFA8
                                            File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................D...D.....D............dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, big endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:68540
                                            Section Header Size:40
                                            Number of Section Headers:14
                                            Header String Table Index:13
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200xf1400x00x6AX0016
                                            .finiPROGBITS0x40f2600xf2600x5c0x00x6AX004
                                            .rodataPROGBITS0x40f2c00xf2c00xa500x00x2A0016
                                            .ctorsPROGBITS0x44fd140xfd140x80x00x3WA004
                                            .dtorsPROGBITS0x44fd1c0xfd1c0x80x00x3WA004
                                            .data.rel.roPROGBITS0x44fd280xfd280x81c0x00x3WA004
                                            .dataPROGBITS0x4505500x105500x2500x00x3WA0016
                                            .gotPROGBITS0x4507a00x107a00x3b80x40x10000003WAp0016
                                            .sbssNOBITS0x450b580x10b580x140x00x10000003WAp004
                                            .bssNOBITS0x450b700x10b580x2600x00x3WA0016
                                            .mdebug.abi32PROGBITS0x6780x10b580x00x00x0001
                                            .shstrtabSTRTAB0x00x10b580x640x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000xfd100xfd105.38740x5R E0x10000.init .text .fini .rodata
                                            LOAD0xfd140x44fd140x44fd140xe440x10bc4.10260x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSource PortDest PortSource IPDest IP
                                            Nov 1, 2024 17:27:45.800162077 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:45.805324078 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:45.805448055 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:45.849338055 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:45.854412079 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:45.854458094 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:45.859301090 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.209152937 CET43928443192.168.2.2391.189.91.42
                                            Nov 1, 2024 17:27:47.365458012 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.365474939 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.365487099 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.365701914 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.365710020 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.365710974 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.365710974 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.365761995 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.365984917 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.366272926 CET6664288295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.366344929 CET42882666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.366628885 CET42884666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.375138998 CET6664288495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.375225067 CET42884666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.376233101 CET42884666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.381062031 CET6664288495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:47.381117105 CET42884666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:47.386028051 CET6664288495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:48.279037952 CET6664288495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:48.279295921 CET42884666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:48.279335976 CET42884666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:48.280174971 CET42886666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:48.281198978 CET6664288495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:48.281253099 CET42884666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:48.285046101 CET6664288695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:48.285104990 CET42886666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:48.286135912 CET42886666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:48.291057110 CET6664288695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:48.291107893 CET42886666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:48.295957088 CET6664288695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:49.184791088 CET6664288695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:49.184911013 CET42886666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:49.185054064 CET42886666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:49.185703993 CET42888666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:49.191636086 CET6664288895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:49.191704035 CET42888666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:49.192452908 CET42888666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:49.197402000 CET6664288895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:49.197458982 CET42888666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:49.202649117 CET6664288895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.075289965 CET6664288895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.075434923 CET42888666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.075434923 CET42888666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.075993061 CET42890666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.080977917 CET6664289095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.081068993 CET42890666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.081945896 CET42890666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.086874962 CET6664289095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.086947918 CET42890666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.091895103 CET6664289095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.960876942 CET6664289095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.961024046 CET42890666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.961024046 CET42890666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.961826086 CET42892666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.967499018 CET6664289295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.967597008 CET42892666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.968743086 CET42892666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.973609924 CET6664289295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:50.973669052 CET42892666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:50.978559971 CET6664289295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.045583010 CET6664289295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.045789957 CET42892666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.045789957 CET42892666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.046412945 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.054012060 CET6664289495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.054095030 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.054989100 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.060220003 CET6664289495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.060309887 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.065191984 CET6664289495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.584367037 CET42836443192.168.2.2391.189.91.43
                                            Nov 1, 2024 17:27:52.965954065 CET6664289495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.966094971 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.966180086 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.966995001 CET42896666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.967081070 CET6664289495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.967176914 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.967511892 CET6664289495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.967560053 CET42894666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.972117901 CET6664289695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.972179890 CET42896666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.973009109 CET42896666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.977796078 CET6664289695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:52.977850914 CET42896666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:52.982848883 CET6664289695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:53.879183054 CET6664289695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:53.879344940 CET42896666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:53.879381895 CET42896666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:53.880137920 CET42898666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:53.885663986 CET6664289895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:53.885725021 CET42898666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:53.886862040 CET42898666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:53.892611027 CET6664289895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:53.892672062 CET42898666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:53.897700071 CET6664289895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:54.120146036 CET4251680192.168.2.23109.202.202.202
                                            Nov 1, 2024 17:27:54.759236097 CET6664289895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:54.759358883 CET6664289895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:54.759377956 CET42898666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:54.759412050 CET42898666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:54.759426117 CET42898666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:54.760153055 CET42900666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:54.766118050 CET6664290095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:54.766197920 CET42900666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:54.767208099 CET42900666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:54.772315979 CET6664290095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:54.772372961 CET42900666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:54.778481960 CET6664290095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:55.661026001 CET6664290095.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:55.661215067 CET42900666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:55.661272049 CET42900666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:55.662009954 CET42902666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:55.666986942 CET6664290295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:55.667059898 CET42902666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:55.667920113 CET42902666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:55.672873020 CET6664290295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:55.672943115 CET42902666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:55.677787066 CET6664290295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:56.542406082 CET6664290295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:56.542603970 CET42902666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:56.542629004 CET42902666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:56.543077946 CET6664290295.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:56.543138027 CET42902666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:56.543308020 CET42904666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:56.548188925 CET6664290495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:56.548274040 CET42904666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:56.549334049 CET42904666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:56.554212093 CET6664290495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:56.554260969 CET42904666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:56.559030056 CET6664290495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:57.433846951 CET6664290495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:57.434053898 CET42904666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:57.434102058 CET42904666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:57.434209108 CET6664290495.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:57.434272051 CET42904666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:57.434914112 CET42906666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:57.439858913 CET6664290695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:57.439924955 CET42906666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:57.441253901 CET42906666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:57.446136951 CET6664290695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:57.446193933 CET42906666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:57.451138020 CET6664290695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:58.329917908 CET6664290695.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:58.330178022 CET42906666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:58.330178976 CET42906666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:58.330759048 CET42908666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:58.335668087 CET6664290895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:58.335724115 CET42908666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:58.336597919 CET42908666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:58.341960907 CET6664290895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:27:58.342037916 CET42908666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:27:58.347059965 CET6664290895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:28:07.174397945 CET43928443192.168.2.2391.189.91.42
                                            Nov 1, 2024 17:28:08.345433950 CET42908666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:28:08.350609064 CET6664290895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:28:08.610718012 CET6664290895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:28:08.610873938 CET42908666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:28:19.460680008 CET42836443192.168.2.2391.189.91.43
                                            Nov 1, 2024 17:28:23.556117058 CET4251680192.168.2.23109.202.202.202
                                            Nov 1, 2024 17:28:48.128746033 CET43928443192.168.2.2391.189.91.42
                                            Nov 1, 2024 17:29:08.652301073 CET42908666192.168.2.2395.164.4.65
                                            Nov 1, 2024 17:29:08.658818960 CET6664290895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:29:08.915937901 CET6664290895.164.4.65192.168.2.23
                                            Nov 1, 2024 17:29:08.916068077 CET42908666192.168.2.2395.164.4.65

                                            System Behavior

                                            Start time (UTC):16:27:44
                                            Start date (UTC):01/11/2024
                                            Path:/tmp/4l9YKCc7qQ.elf
                                            Arguments:/tmp/4l9YKCc7qQ.elf
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):16:27:44
                                            Start date (UTC):01/11/2024
                                            Path:/tmp/4l9YKCc7qQ.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):16:27:44
                                            Start date (UTC):01/11/2024
                                            Path:/tmp/4l9YKCc7qQ.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):16:27:44
                                            Start date (UTC):01/11/2024
                                            Path:/tmp/4l9YKCc7qQ.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c