Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm.elf

Overview

General Information

Sample name:arm.elf
Analysis ID:1564144
MD5:672e5e2fe024d48bd7b078636e2c8dc7
SHA1:f0336d57682eb36954597b3b4d2dfd198dd7ccff
SHA256:789b111acdd4db48bfa20b404e744aeec665e97a4763a7f32d8e90dcfa01e399
Tags:elfuser-abuse_ch
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Connects to many ports of the same IP (likely port scanning)
Sample reads /proc/mounts (often used for finding a writable filesystem)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1564144
Start date and time:2024-11-27 22:02:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 53s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm.elf
Detection:MAL
Classification:mal56.troj.linELF@0/0@5/0
  • VT rate limit hit for: arm.elf
Command:/tmp/arm.elf
PID:5522
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
I jun ok ter my cats, man.
Standard Error:
  • system is lnxubuntu20
  • arm.elf (PID: 5522, Parent: 5446, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm.elf
    • arm.elf New Fork (PID: 5545, Parent: 5522)
      • arm.elf New Fork (PID: 5598, Parent: 5545)
      • arm.elf New Fork (PID: 5599, Parent: 5545)
    • arm.elf New Fork (PID: 5547, Parent: 5522)
    • arm.elf New Fork (PID: 5563, Parent: 5522)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: arm.elfReversingLabs: Detection: 13%

Networking

barindex
Source: global trafficTCP traffic: 195.133.53.106 ports 21736,1,2,3,6,7
Source: global trafficTCP traffic: 192.168.2.15:44480 -> 195.133.53.106:21736
Source: global trafficTCP traffic: 192.168.2.15:34106 -> 185.22.155.213:1985
Source: /tmp/arm.elf (PID: 5522)Socket: 127.0.0.1:1172Jump to behavior
Source: unknownTCP traffic detected without corresponding DNS query: 195.133.53.106
Source: unknownTCP traffic detected without corresponding DNS query: 195.133.53.106
Source: unknownTCP traffic detected without corresponding DNS query: 195.133.53.106
Source: unknownTCP traffic detected without corresponding DNS query: 195.133.53.106
Source: unknownTCP traffic detected without corresponding DNS query: 195.133.53.106
Source: unknownTCP traffic detected without corresponding DNS query: 195.133.53.106
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownTCP traffic detected without corresponding DNS query: 185.22.155.213
Source: unknownUDP traffic detected without corresponding DNS query: 168.138.12.137
Source: unknownUDP traffic detected without corresponding DNS query: 168.138.12.137
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 109.91.184.21
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 109.91.184.21
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 81.169.136.222
Source: unknownUDP traffic detected without corresponding DNS query: 80.152.203.134
Source: unknownUDP traffic detected without corresponding DNS query: 109.91.184.21
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 109.91.184.21
Source: unknownUDP traffic detected without corresponding DNS query: 109.91.184.21
Source: unknownUDP traffic detected without corresponding DNS query: 109.91.184.21
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 109.91.184.21
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 185.181.61.24
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: unknownUDP traffic detected without corresponding DNS query: 152.53.15.127
Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 202.61.197.122
Source: unknownUDP traffic detected without corresponding DNS query: 217.160.70.42
Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
Source: unknownUDP traffic detected without corresponding DNS query: 168.235.111.72
Source: global trafficDNS traffic detected: DNS query: catvision.dyn
Source: global trafficDNS traffic detected: DNS query: hikvision.geek
Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal56.troj.linELF@0/0@5/0

Persistence and Installation Behavior

barindex
Source: /tmp/arm.elf (PID: 5522)File: /proc/5522/mountsJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5690/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5680/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5691/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5681/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5692/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5682/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5693/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5683/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5694/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5365/cmdlineJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5684/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5685/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5653/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5686/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5676/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5687/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5677/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5688/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5678/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5689/statusJump to behavior
Source: /tmp/arm.elf (PID: 5598)File opened: /proc/5679/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5680/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5681/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5682/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5683/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5365/cmdlineJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5684/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5685/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5686/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5676/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5599/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5677/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5678/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5679/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5659/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5690/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5691/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5692/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5693/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5694/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5597/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5598/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5687/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5688/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5689/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5648/statusJump to behavior
Source: /tmp/arm.elf (PID: 5547)File opened: /proc/5649/statusJump to behavior
Source: /tmp/arm.elf (PID: 5522)Queries kernel information via 'uname': Jump to behavior
Source: arm.elf, 5522.1.00007ffd0a734000.00007ffd0a755000.rw-.sdmp, arm.elf, 5545.1.00007ffd0a734000.00007ffd0a755000.rw-.sdmpBinary or memory string: 'Px86_64/usr/bin/qemu-arm/tmp/arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm.elf
Source: arm.elf, 5522.1.000055c079bac000.000055c079cfd000.rw-.sdmp, arm.elf, 5545.1.000055c079bac000.000055c079cfd000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: arm.elf, 5545.1.000055c079bac000.000055c079cfd000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
Source: arm.elf, 5522.1.000055c079bac000.000055c079cfd000.rw-.sdmp, arm.elf, 5545.1.000055c079bac000.000055c079cfd000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: arm.elf, 5545.1.000055c079bac000.000055c079cfd000.rw-.sdmpBinary or memory string: !/proc/1588/exe0!/usr/bin/vmtoolsd1/proc/3316/exe/arm/sr10!/usr/bin/ibus-daemon!/proc/740/exe1/proc/3469/exe/arm/ro10!/proc/1585/exe0!/proc/764/exe!/proc/3197/exe/arm/pro!/usr/bin/dash/arm/proa0L
Source: arm.elf, 5522.1.00007ffd0a734000.00007ffd0a755000.rw-.sdmp, arm.elf, 5545.1.00007ffd0a734000.00007ffd0a755000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
File and Directory Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1564144 Sample: arm.elf Startdate: 27/11/2024 Architecture: LINUX Score: 56 21 195.133.53.106, 21736, 44480 FLEX-ASRU Russian Federation 2->21 23 185.22.155.213, 1985, 34106 ASBAXETRU Russian Federation 2->23 25 4 other IPs or domains 2->25 27 Multi AV Scanner detection for submitted file 2->27 29 Connects to many ports of the same IP (likely port scanning) 2->29 8 arm.elf 2->8         started        signatures3 process4 signatures5 31 Sample reads /proc/mounts (often used for finding a writable filesystem) 8->31 11 arm.elf 8->11         started        13 arm.elf 8->13         started        15 arm.elf 8->15         started        process6 process7 17 arm.elf 11->17         started        19 arm.elf 11->19         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
arm.elf13%ReversingLabsLinux.Backdoor.Mirai
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
daisy.ubuntu.com
162.213.35.24
truefalse
    high
    catvision.dyn
    unknown
    unknownfalse
      unknown
      hikvision.geek
      unknown
      unknownfalse
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        185.22.155.213
        unknownRussian Federation
        51659ASBAXETRUfalse
        195.133.53.106
        unknownRussian Federation
        21453FLEX-ASRUtrue
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        185.22.155.213hmips.elfGet hashmaliciousUnknownBrowse
          195.133.53.106hmips.elfGet hashmaliciousUnknownBrowse
            ppc.elfGet hashmaliciousUnknownBrowse
              arm7.elfGet hashmaliciousUnknownBrowse
                ppc.elfGet hashmaliciousUnknownBrowse
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  daisy.ubuntu.comxblkpfZ8Y3.elfGet hashmaliciousUnknownBrowse
                  • 162.213.35.25
                  xblkpfZ8Y1.elfGet hashmaliciousUnknownBrowse
                  • 162.213.35.24
                  xblkpfZ8Y0.elfGet hashmaliciousXmrigBrowse
                  • 162.213.35.25
                  sshd.elfGet hashmaliciousUnknownBrowse
                  • 162.213.35.25
                  hidakibest.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 162.213.35.25
                  hidakibest.arm4.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 162.213.35.25
                  hidakibest.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 162.213.35.24
                  hidakibest.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 162.213.35.24
                  hidakibest.arm5.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 162.213.35.24
                  hidakibest.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 162.213.35.24
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  ASBAXETRUhmips.elfGet hashmaliciousUnknownBrowse
                  • 45.140.168.235
                  ARRIVAL NOTICE.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                  • 176.32.38.130
                  ppc.elfGet hashmaliciousUnknownBrowse
                  • 176.32.39.112
                  mips.elfGet hashmaliciousUnknownBrowse
                  • 45.140.168.235
                  arm7.elfGet hashmaliciousUnknownBrowse
                  • 45.140.168.235
                  x86.elfGet hashmaliciousUnknownBrowse
                  • 176.32.39.112
                  arm5.elfGet hashmaliciousUnknownBrowse
                  • 45.140.169.21
                  Delivery_Notification_00000207899.doc.jsGet hashmaliciousUnknownBrowse
                  • 185.22.155.63
                  Quotation request -30112024_pdf.exeGet hashmaliciousFormBookBrowse
                  • 176.32.38.130
                  ppc.elfGet hashmaliciousUnknownBrowse
                  • 45.140.168.235
                  FLEX-ASRUhmips.elfGet hashmaliciousUnknownBrowse
                  • 195.133.53.106
                  ppc.elfGet hashmaliciousUnknownBrowse
                  • 195.133.53.106
                  arm7.elfGet hashmaliciousUnknownBrowse
                  • 195.133.53.106
                  ppc.elfGet hashmaliciousUnknownBrowse
                  • 195.133.53.106
                  la.bot.arm5.elfGet hashmaliciousUnknownBrowse
                  • 178.167.66.6
                  la.bot.sh4.elfGet hashmaliciousUnknownBrowse
                  • 195.133.29.42
                  IlyNpnwGBF.elfGet hashmaliciousMiraiBrowse
                  • 94.253.22.173
                  bin.x86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 195.133.7.148
                  bin.i686.elfGet hashmaliciousGafgyt, MiraiBrowse
                  • 178.167.93.209
                  qpqsIVPt88.elfGet hashmaliciousMiraiBrowse
                  • 94.253.22.199
                  No context
                  No context
                  No created / dropped files found
                  File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                  Entropy (8bit):6.057791807124935
                  TrID:
                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                  File name:arm.elf
                  File size:65'844 bytes
                  MD5:672e5e2fe024d48bd7b078636e2c8dc7
                  SHA1:f0336d57682eb36954597b3b4d2dfd198dd7ccff
                  SHA256:789b111acdd4db48bfa20b404e744aeec665e97a4763a7f32d8e90dcfa01e399
                  SHA512:237557a9a60da815e105cc966127df3456dd1ed773a046598c0580acd8c642c27c270e3f0948ed3a17f873e1225fad0f00fe9d013ba617e02bf1755738dda589
                  SSDEEP:1536:3ov7//j4KL90s5JbUhElmvBpg190yzvqyD:Wb/020eJbUWKwq
                  TLSH:9E533A85BD819713C6C122BBFB1E42CD7B2613A8D2EE32039E156F21378796B0E7B551
                  File Content Preview:.ELF...a..........(.........4...........4. ...(..........................................................T..........Q.td..................................-...L."...L9..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                  ELF header

                  Class:ELF32
                  Data:2's complement, little endian
                  Version:1 (current)
                  Machine:ARM
                  Version Number:0x1
                  Type:EXEC (Executable file)
                  OS/ABI:ARM - ABI
                  ABI Version:0
                  Entry Point Address:0x8190
                  Flags:0x202
                  ELF Header Size:52
                  Program Header Offset:52
                  Program Header Size:32
                  Number of Program Headers:3
                  Section Header Offset:65444
                  Section Header Size:40
                  Number of Section Headers:10
                  Header String Table Index:9
                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                  NULL0x00x00x00x00x0000
                  .initPROGBITS0x80940x940x180x00x6AX004
                  .textPROGBITS0x80b00xb00xe5680x00x6AX0016
                  .finiPROGBITS0x166180xe6180x140x00x6AX004
                  .rodataPROGBITS0x1662c0xe62c0x15900x00x2A004
                  .ctorsPROGBITS0x1fbc00xfbc00x80x00x3WA004
                  .dtorsPROGBITS0x1fbc80xfbc80x80x00x3WA004
                  .dataPROGBITS0x1fbd40xfbd40x3900x00x3WA004
                  .bssNOBITS0x1ff640xff640x50640x00x3WA004
                  .shstrtabSTRTAB0x00xff640x3e0x00x0001
                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                  LOAD0x00x80000x80000xfbbc0xfbbc6.09340x5R E0x8000.init .text .fini .rodata
                  LOAD0xfbc00x1fbc00x1fbc00x3a40x54082.85700x6RW 0x8000.ctors .dtors .data .bss
                  GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 27, 2024 22:02:58.036921978 CET4448021736192.168.2.15195.133.53.106
                  Nov 27, 2024 22:02:58.159663916 CET2173644480195.133.53.106192.168.2.15
                  Nov 27, 2024 22:02:58.159787893 CET4448021736192.168.2.15195.133.53.106
                  Nov 27, 2024 22:02:58.159993887 CET4448021736192.168.2.15195.133.53.106
                  Nov 27, 2024 22:02:58.281296015 CET2173644480195.133.53.106192.168.2.15
                  Nov 27, 2024 22:02:58.281377077 CET4448021736192.168.2.15195.133.53.106
                  Nov 27, 2024 22:02:58.401309967 CET2173644480195.133.53.106192.168.2.15
                  Nov 27, 2024 22:03:00.038387060 CET2173644480195.133.53.106192.168.2.15
                  Nov 27, 2024 22:03:00.038487911 CET4448021736192.168.2.15195.133.53.106
                  Nov 27, 2024 22:03:00.038659096 CET4448021736192.168.2.15195.133.53.106
                  Nov 27, 2024 22:03:05.308670044 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:03:05.429374933 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:03:05.429450035 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:03:05.429476976 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:03:05.549565077 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:03:05.549603939 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:03:05.669569016 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:03:15.438239098 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:03:15.558257103 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:03:16.045479059 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:03:16.045531988 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:04:36.107903004 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:04:36.234746933 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:04:36.712379932 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:04:36.712513924 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:05:56.778062105 CET341061985192.168.2.15185.22.155.213
                  Nov 27, 2024 22:05:56.898015022 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:05:57.380311966 CET198534106185.22.155.213192.168.2.15
                  Nov 27, 2024 22:05:57.380412102 CET341061985192.168.2.15185.22.155.213
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 27, 2024 22:02:52.780363083 CET5505153192.168.2.15168.138.12.137
                  Nov 27, 2024 22:02:52.864291906 CET4063453192.168.2.15168.138.12.137
                  Nov 27, 2024 22:02:57.785269976 CET3747153192.168.2.1551.158.108.203
                  Nov 27, 2024 22:02:57.871432066 CET4708253192.168.2.1551.158.108.203
                  Nov 27, 2024 22:02:58.035892963 CET533747151.158.108.203192.168.2.15
                  Nov 27, 2024 22:02:58.119765997 CET534708251.158.108.203192.168.2.15
                  Nov 27, 2024 22:02:58.122684002 CET4954053192.168.2.15109.91.184.21
                  Nov 27, 2024 22:03:03.127545118 CET4897153192.168.2.15152.53.15.127
                  Nov 27, 2024 22:03:03.380497932 CET5348971152.53.15.127192.168.2.15
                  Nov 27, 2024 22:03:05.040920019 CET5134853192.168.2.15109.91.184.21
                  Nov 27, 2024 22:03:05.308187962 CET5351348109.91.184.21192.168.2.15
                  Nov 27, 2024 22:03:05.385890007 CET5414553192.168.2.15194.36.144.87
                  Nov 27, 2024 22:03:05.631402969 CET5354145194.36.144.87192.168.2.15
                  Nov 27, 2024 22:03:05.632154942 CET4269753192.168.2.1580.152.203.134
                  Nov 27, 2024 22:03:05.967657089 CET534269780.152.203.134192.168.2.15
                  Nov 27, 2024 22:03:05.968441010 CET4414053192.168.2.15185.181.61.24
                  Nov 27, 2024 22:03:06.230659962 CET5344140185.181.61.24192.168.2.15
                  Nov 27, 2024 22:03:06.231484890 CET3930253192.168.2.1580.152.203.134
                  Nov 27, 2024 22:03:06.537276030 CET533930280.152.203.134192.168.2.15
                  Nov 27, 2024 22:03:12.539619923 CET4680453192.168.2.1581.169.136.222
                  Nov 27, 2024 22:03:12.782567024 CET534680481.169.136.222192.168.2.15
                  Nov 27, 2024 22:03:12.783487082 CET3961753192.168.2.1580.152.203.134
                  Nov 27, 2024 22:03:13.037343025 CET533961780.152.203.134192.168.2.15
                  Nov 27, 2024 22:03:13.039580107 CET4776053192.168.2.15109.91.184.21
                  Nov 27, 2024 22:03:13.313638926 CET5347760109.91.184.21192.168.2.15
                  Nov 27, 2024 22:03:13.314443111 CET4172053192.168.2.15185.181.61.24
                  Nov 27, 2024 22:03:13.574987888 CET5341720185.181.61.24192.168.2.15
                  Nov 27, 2024 22:03:14.579159975 CET5021353192.168.2.15185.181.61.24
                  Nov 27, 2024 22:03:14.845160007 CET5350213185.181.61.24192.168.2.15
                  Nov 27, 2024 22:03:14.845933914 CET4398053192.168.2.15109.91.184.21
                  Nov 27, 2024 22:03:15.175460100 CET5343980109.91.184.21192.168.2.15
                  Nov 27, 2024 22:03:15.177167892 CET5646053192.168.2.15109.91.184.21
                  Nov 27, 2024 22:03:15.440167904 CET5356460109.91.184.21192.168.2.15
                  Nov 27, 2024 22:03:15.440789938 CET4757353192.168.2.15109.91.184.21
                  Nov 27, 2024 22:03:15.725224018 CET5347573109.91.184.21192.168.2.15
                  Nov 27, 2024 22:03:23.727222919 CET4895053192.168.2.15185.181.61.24
                  Nov 27, 2024 22:03:23.992350101 CET5348950185.181.61.24192.168.2.15
                  Nov 27, 2024 22:03:23.993179083 CET5269453192.168.2.15109.91.184.21
                  Nov 27, 2024 22:03:24.285908937 CET5352694109.91.184.21192.168.2.15
                  Nov 27, 2024 22:03:24.286736965 CET4403553192.168.2.15194.36.144.87
                  Nov 27, 2024 22:03:24.525669098 CET5344035194.36.144.87192.168.2.15
                  Nov 27, 2024 22:03:24.526475906 CET3301653192.168.2.15185.181.61.24
                  Nov 27, 2024 22:03:24.795087099 CET5333016185.181.61.24192.168.2.15
                  Nov 27, 2024 22:03:33.797413111 CET3708353192.168.2.15152.53.15.127
                  Nov 27, 2024 22:03:34.058864117 CET5337083152.53.15.127192.168.2.15
                  Nov 27, 2024 22:03:34.059827089 CET5759153192.168.2.15152.53.15.127
                  Nov 27, 2024 22:03:34.299097061 CET5357591152.53.15.127192.168.2.15
                  Nov 27, 2024 22:03:34.299923897 CET5099153192.168.2.15194.36.144.87
                  Nov 27, 2024 22:03:34.549737930 CET5350991194.36.144.87192.168.2.15
                  Nov 27, 2024 22:03:34.550710917 CET4961653192.168.2.15168.235.111.72
                  Nov 27, 2024 22:03:34.860981941 CET5349616168.235.111.72192.168.2.15
                  Nov 27, 2024 22:03:43.863550901 CET3897053192.168.2.15152.53.15.127
                  Nov 27, 2024 22:03:44.108633995 CET5338970152.53.15.127192.168.2.15
                  Nov 27, 2024 22:03:44.109750032 CET4954553192.168.2.15194.36.144.87
                  Nov 27, 2024 22:03:44.362617016 CET5349545194.36.144.87192.168.2.15
                  Nov 27, 2024 22:03:44.364058971 CET5243353192.168.2.1551.158.108.203
                  Nov 27, 2024 22:03:44.613706112 CET535243351.158.108.203192.168.2.15
                  Nov 27, 2024 22:03:44.615192890 CET4171153192.168.2.15202.61.197.122
                  Nov 27, 2024 22:03:44.859430075 CET5341711202.61.197.122192.168.2.15
                  Nov 27, 2024 22:03:53.863267899 CET3663453192.168.2.15217.160.70.42
                  Nov 27, 2024 22:03:54.103189945 CET5336634217.160.70.42192.168.2.15
                  Nov 27, 2024 22:03:54.104433060 CET4011953192.168.2.1551.158.108.203
                  Nov 27, 2024 22:03:54.344027996 CET534011951.158.108.203192.168.2.15
                  Nov 27, 2024 22:03:54.345444918 CET5663853192.168.2.15168.235.111.72
                  Nov 27, 2024 22:03:54.671298027 CET5356638168.235.111.72192.168.2.15
                  Nov 27, 2024 22:03:54.672790051 CET5271653192.168.2.15202.61.197.122
                  Nov 27, 2024 22:03:54.925103903 CET5352716202.61.197.122192.168.2.15
                  Nov 27, 2024 22:03:59.928921938 CET3882353192.168.2.15217.160.70.42
                  Nov 27, 2024 22:04:00.169581890 CET5338823217.160.70.42192.168.2.15
                  Nov 27, 2024 22:04:00.171209097 CET3278853192.168.2.15168.235.111.72
                  Nov 27, 2024 22:04:00.484015942 CET5332788168.235.111.72192.168.2.15
                  Nov 27, 2024 22:04:00.485476017 CET4112253192.168.2.1580.152.203.134
                  Nov 27, 2024 22:04:00.770199060 CET534112280.152.203.134192.168.2.15
                  Nov 27, 2024 22:04:00.771954060 CET4818853192.168.2.1580.152.203.134
                  Nov 27, 2024 22:04:10.780833006 CET5107653192.168.2.1581.169.136.222
                  Nov 27, 2024 22:04:11.026921988 CET535107681.169.136.222192.168.2.15
                  Nov 27, 2024 22:04:11.028096914 CET4528253192.168.2.15152.53.15.127
                  Nov 27, 2024 22:04:11.282143116 CET5345282152.53.15.127192.168.2.15
                  Nov 27, 2024 22:04:11.283600092 CET4572253192.168.2.15109.91.184.21
                  Nov 27, 2024 22:04:11.560282946 CET5345722109.91.184.21192.168.2.15
                  Nov 27, 2024 22:04:11.561674118 CET4198553192.168.2.15194.36.144.87
                  Nov 27, 2024 22:04:11.810857058 CET5341985194.36.144.87192.168.2.15
                  Nov 27, 2024 22:04:19.814448118 CET4698853192.168.2.15194.36.144.87
                  Nov 27, 2024 22:04:20.065407991 CET5346988194.36.144.87192.168.2.15
                  Nov 27, 2024 22:04:20.066673994 CET5212053192.168.2.15152.53.15.127
                  Nov 27, 2024 22:04:20.327488899 CET5352120152.53.15.127192.168.2.15
                  Nov 27, 2024 22:04:20.328722954 CET3907853192.168.2.15109.91.184.21
                  Nov 27, 2024 22:04:20.695468903 CET5339078109.91.184.21192.168.2.15
                  Nov 27, 2024 22:04:20.696882010 CET4376153192.168.2.15168.138.12.137
                  Nov 27, 2024 22:04:30.705262899 CET3881553192.168.2.1551.158.108.203
                  Nov 27, 2024 22:04:30.963044882 CET533881551.158.108.203192.168.2.15
                  Nov 27, 2024 22:04:30.963996887 CET3572453192.168.2.15194.36.144.87
                  Nov 27, 2024 22:04:31.215779066 CET5335724194.36.144.87192.168.2.15
                  Nov 27, 2024 22:04:31.217068911 CET5471853192.168.2.15168.138.12.137
                  Nov 27, 2024 22:04:36.221031904 CET3787953192.168.2.15185.181.61.24
                  Nov 27, 2024 22:04:36.486278057 CET5337879185.181.61.24192.168.2.15
                  Nov 27, 2024 22:04:40.489258051 CET5598253192.168.2.1551.158.108.203
                  Nov 27, 2024 22:04:40.738787889 CET535598251.158.108.203192.168.2.15
                  Nov 27, 2024 22:04:40.739480019 CET4477653192.168.2.15202.61.197.122
                  Nov 27, 2024 22:04:40.988971949 CET5344776202.61.197.122192.168.2.15
                  Nov 27, 2024 22:04:40.989548922 CET4161653192.168.2.15152.53.15.127
                  Nov 27, 2024 22:04:41.244141102 CET5341616152.53.15.127192.168.2.15
                  Nov 27, 2024 22:04:41.244720936 CET4809153192.168.2.15168.235.111.72
                  Nov 27, 2024 22:04:41.559381008 CET5348091168.235.111.72192.168.2.15
                  Nov 27, 2024 22:04:47.562515974 CET3390653192.168.2.15109.91.184.21
                  Nov 27, 2024 22:04:47.831238031 CET5333906109.91.184.21192.168.2.15
                  Nov 27, 2024 22:04:47.831924915 CET4282753192.168.2.15109.91.184.21
                  Nov 27, 2024 22:04:52.837063074 CET5336153192.168.2.15109.91.184.21
                  Nov 27, 2024 22:04:53.108227968 CET5353361109.91.184.21192.168.2.15
                  Nov 27, 2024 22:04:53.109280109 CET4156153192.168.2.15168.138.12.137
                  Nov 27, 2024 22:05:08.113890886 CET4513353192.168.2.15217.160.70.42
                  Nov 27, 2024 22:05:08.352632999 CET5345133217.160.70.42192.168.2.15
                  Nov 27, 2024 22:05:08.353899956 CET5138653192.168.2.15213.202.211.221
                  Nov 27, 2024 22:05:08.591379881 CET5351386213.202.211.221192.168.2.15
                  Nov 27, 2024 22:05:08.592628002 CET4252753192.168.2.1580.152.203.134
                  Nov 27, 2024 22:05:08.847580910 CET534252780.152.203.134192.168.2.15
                  Nov 27, 2024 22:05:08.848675966 CET3970753192.168.2.1581.169.136.222
                  Nov 27, 2024 22:05:09.089265108 CET533970781.169.136.222192.168.2.15
                  Nov 27, 2024 22:05:15.092521906 CET5776253192.168.2.15194.36.144.87
                  Nov 27, 2024 22:05:15.348104000 CET5357762194.36.144.87192.168.2.15
                  Nov 27, 2024 22:05:15.349229097 CET5096153192.168.2.15185.181.61.24
                  Nov 27, 2024 22:05:15.611840010 CET5350961185.181.61.24192.168.2.15
                  Nov 27, 2024 22:05:15.612900972 CET3785153192.168.2.15213.202.211.221
                  Nov 27, 2024 22:05:15.846719027 CET5337851213.202.211.221192.168.2.15
                  Nov 27, 2024 22:05:15.847820997 CET3665353192.168.2.1580.152.203.134
                  Nov 27, 2024 22:05:16.186254025 CET533665380.152.203.134192.168.2.15
                  Nov 27, 2024 22:05:25.188075066 CET3961553192.168.2.15213.202.211.221
                  Nov 27, 2024 22:05:25.426135063 CET5339615213.202.211.221192.168.2.15
                  Nov 27, 2024 22:05:25.427841902 CET5527153192.168.2.1551.158.108.203
                  Nov 27, 2024 22:05:25.667260885 CET535527151.158.108.203192.168.2.15
                  Nov 27, 2024 22:05:25.668579102 CET5718753192.168.2.15185.181.61.24
                  Nov 27, 2024 22:05:25.925262928 CET5357187185.181.61.24192.168.2.15
                  Nov 27, 2024 22:05:25.926562071 CET3899753192.168.2.1580.152.203.134
                  Nov 27, 2024 22:05:26.318172932 CET533899780.152.203.134192.168.2.15
                  Nov 27, 2024 22:05:36.320741892 CET5562453192.168.2.1581.169.136.222
                  Nov 27, 2024 22:05:36.560282946 CET535562481.169.136.222192.168.2.15
                  Nov 27, 2024 22:05:36.561661959 CET4205753192.168.2.15152.53.15.127
                  Nov 27, 2024 22:05:36.800705910 CET5342057152.53.15.127192.168.2.15
                  Nov 27, 2024 22:05:36.801786900 CET5856153192.168.2.15217.160.70.42
                  Nov 27, 2024 22:05:37.040452003 CET5358561217.160.70.42192.168.2.15
                  Nov 27, 2024 22:05:37.041657925 CET5394153192.168.2.15217.160.70.42
                  Nov 27, 2024 22:05:37.280500889 CET5353941217.160.70.42192.168.2.15
                  Nov 27, 2024 22:05:38.665862083 CET3811653192.168.2.151.1.1.1
                  Nov 27, 2024 22:05:38.665935040 CET4972053192.168.2.151.1.1.1
                  Nov 27, 2024 22:05:38.808851957 CET53497201.1.1.1192.168.2.15
                  Nov 27, 2024 22:05:38.808862925 CET53381161.1.1.1192.168.2.15
                  Nov 27, 2024 22:05:46.283782005 CET5771453192.168.2.15152.53.15.127
                  Nov 27, 2024 22:05:46.539983034 CET5357714152.53.15.127192.168.2.15
                  Nov 27, 2024 22:05:46.541055918 CET3769053192.168.2.15194.36.144.87
                  Nov 27, 2024 22:05:46.782130003 CET5337690194.36.144.87192.168.2.15
                  Nov 27, 2024 22:05:46.783143044 CET4588853192.168.2.15152.53.15.127
                  Nov 27, 2024 22:05:47.023448944 CET5345888152.53.15.127192.168.2.15
                  Nov 27, 2024 22:05:47.024521112 CET5678553192.168.2.15168.235.111.72
                  Nov 27, 2024 22:05:47.344614029 CET5356785168.235.111.72192.168.2.15
                  Nov 27, 2024 22:05:57.346817970 CET6045053192.168.2.15168.138.12.137
                  Nov 27, 2024 22:06:02.350827932 CET4615553192.168.2.15185.181.61.24
                  Nov 27, 2024 22:06:02.616488934 CET5346155185.181.61.24192.168.2.15
                  Nov 27, 2024 22:06:02.617762089 CET4777853192.168.2.15109.91.184.21
                  Nov 27, 2024 22:06:02.930126905 CET5347778109.91.184.21192.168.2.15
                  Nov 27, 2024 22:06:02.931499004 CET5802753192.168.2.15109.91.184.21
                  Nov 27, 2024 22:06:03.262850046 CET5358027109.91.184.21192.168.2.15
                  Nov 27, 2024 22:06:12.266119957 CET4347753192.168.2.1581.169.136.222
                  Nov 27, 2024 22:06:12.505450010 CET534347781.169.136.222192.168.2.15
                  Nov 27, 2024 22:06:12.506794930 CET5454953192.168.2.15152.53.15.127
                  Nov 27, 2024 22:06:12.764256001 CET5354549152.53.15.127192.168.2.15
                  Nov 27, 2024 22:06:12.766109943 CET4430453192.168.2.15217.160.70.42
                  Nov 27, 2024 22:06:13.008202076 CET5344304217.160.70.42192.168.2.15
                  Nov 27, 2024 22:06:13.009574890 CET3790253192.168.2.15213.202.211.221
                  Nov 27, 2024 22:06:13.242258072 CET5337902213.202.211.221192.168.2.15
                  Nov 27, 2024 22:06:17.246278048 CET4518553192.168.2.1580.152.203.134
                  Nov 27, 2024 22:06:17.600523949 CET534518580.152.203.134192.168.2.15
                  Nov 27, 2024 22:06:17.601998091 CET4550053192.168.2.15168.138.12.137
                  Nov 27, 2024 22:06:22.608401060 CET5733053192.168.2.15152.53.15.127
                  Nov 27, 2024 22:06:22.856523991 CET5357330152.53.15.127192.168.2.15
                  Nov 27, 2024 22:06:22.857382059 CET4283853192.168.2.1580.152.203.134
                  Nov 27, 2024 22:06:23.127012014 CET534283880.152.203.134192.168.2.15
                  Nov 27, 2024 22:06:25.130752087 CET3755453192.168.2.1581.169.136.222
                  Nov 27, 2024 22:06:25.369932890 CET533755481.169.136.222192.168.2.15
                  Nov 27, 2024 22:06:25.371342897 CET4447553192.168.2.15185.181.61.24
                  Nov 27, 2024 22:06:25.632503033 CET5344475185.181.61.24192.168.2.15
                  Nov 27, 2024 22:06:25.634113073 CET4312353192.168.2.15152.53.15.127
                  Nov 27, 2024 22:06:25.882375956 CET5343123152.53.15.127192.168.2.15
                  Nov 27, 2024 22:06:25.883687973 CET5832953192.168.2.1551.158.108.203
                  Nov 27, 2024 22:06:26.128973007 CET535832951.158.108.203192.168.2.15
                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                  Nov 27, 2024 22:02:52.780363083 CET192.168.2.15168.138.12.1370xba79Standard query (0)catvision.dynA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:02:57.785269976 CET192.168.2.1551.158.108.2030x73e0Standard query (0)hikvision.geekA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:03:05.040920019 CET192.168.2.15109.91.184.210x55acStandard query (0)hikvision.geekA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:38.665862083 CET192.168.2.151.1.1.10x6a8dStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:38.665935040 CET192.168.2.151.1.1.10x8f2Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                  Nov 27, 2024 22:03:54.671298027 CET168.235.111.72192.168.2.150x9e4fFormat error (1)hikvision.geeknonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:04:41.559381008 CET168.235.111.72192.168.2.150x8d0cFormat error (1)shitrocket.dynnonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:09.089265108 CET81.169.136.222192.168.2.150x9c3fFormat error (1)hikvision.geeknonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:15.846719027 CET213.202.211.221192.168.2.150xe61fFormat error (1)hikvision.geeknonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:25.426135063 CET213.202.211.221192.168.2.150x1ab7Format error (1)shitrocket.dynnonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:37.040452003 CET217.160.70.42192.168.2.150xe073Format error (1)hikvision.geeknonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:38.808862925 CET1.1.1.1192.168.2.150x6a8dNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                  Nov 27, 2024 22:05:38.808862925 CET1.1.1.1192.168.2.150x6a8dNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                  Nov 27, 2024 22:06:13.008202076 CET217.160.70.42192.168.2.150xa814Format error (1)shitrocket.dynnonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:06:13.242258072 CET213.202.211.221192.168.2.150x9e0aFormat error (1)hikvision.geeknonenoneA (IP address)IN (0x0001)false
                  Nov 27, 2024 22:06:25.632503033 CET185.181.61.24192.168.2.150x58fcFormat error (1)hikvision.geeknonenoneA (IP address)IN (0x0001)false

                  System Behavior

                  Start time (UTC):21:02:51
                  Start date (UTC):27/11/2024
                  Path:/tmp/arm.elf
                  Arguments:/tmp/arm.elf
                  File size:4956856 bytes
                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                  Start time (UTC):21:02:51
                  Start date (UTC):27/11/2024
                  Path:/tmp/arm.elf
                  Arguments:-
                  File size:4956856 bytes
                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                  Start time (UTC):21:02:51
                  Start date (UTC):27/11/2024
                  Path:/tmp/arm.elf
                  Arguments:-
                  File size:4956856 bytes
                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                  Start time (UTC):21:02:51
                  Start date (UTC):27/11/2024
                  Path:/tmp/arm.elf
                  Arguments:-
                  File size:4956856 bytes
                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                  Start time (UTC):21:02:51
                  Start date (UTC):27/11/2024
                  Path:/tmp/arm.elf
                  Arguments:-
                  File size:4956856 bytes
                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                  Start time (UTC):21:02:51
                  Start date (UTC):27/11/2024
                  Path:/tmp/arm.elf
                  Arguments:-
                  File size:4956856 bytes
                  MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1