Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.mips.elf

Overview

General Information

Sample name:Space.mips.elf
Analysis ID:1575717
MD5:47a3da5b7a3334ad0d7d3e319d5e5876
SHA1:8710045d8e4ad5ab0561af69d328ba5bfe85ae85
SHA256:467f8730b3df7738935b68efa0309ed7b154dc14ca2e87d04e00fddd49d34a2e
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:68
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1575717
Start date and time:2024-12-16 08:56:15 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 16s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mips.elf
Detection:MAL
Classification:mal68.troj.evad.linELF@0/0@0/0
Command:/tmp/Space.mips.elf
PID:6262
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6281, Parent: 4331)
  • rm (PID: 6281, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.drTjJyhArt /tmp/tmp.gkLWWzaWTF /tmp/tmp.zTIoASQolq
  • dash New Fork (PID: 6282, Parent: 4331)
  • rm (PID: 6282, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.drTjJyhArt /tmp/tmp.gkLWWzaWTF /tmp/tmp.zTIoASQolq
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6264.1.00007f9de8400000.00007f9de8418000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    6264.1.00007f9de8400000.00007f9de8418000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x1470c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1475c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14798:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x147ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x147c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x147d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x147e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x147fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14810:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14824:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14838:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1484c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14860:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14874:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x14888:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1489c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    6266.1.00007f9de8400000.00007f9de8418000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6266.1.00007f9de8400000.00007f9de8418000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x1470c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14720:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14734:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14748:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1475c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14770:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14784:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14798:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x147ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x147c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x147d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x147e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x147fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14810:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14824:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14838:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1484c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14860:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14874:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x14888:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1489c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      6262.1.00007f9de8400000.00007f9de8418000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        Click to see the 10 entries
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: Space.mips.elfReversingLabs: Detection: 36%
        Source: Space.mips.elfVirustotal: Detection: 37%Perma Link
        Source: global trafficTCP traffic: 192.168.2.23:50962 -> 89.169.4.44:3778
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
        Source: Space.mips.elfString found in binary or memory: http://upx.sf.net
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
        Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443

        System Summary

        barindex
        Source: 6264.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6266.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6262.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6274.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.mips.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.mips.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.mips.elf PID: 6266, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: Space.mips.elf PID: 6274, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: LOAD without section mappingsProgram segment: 0x100000
        Source: 6264.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6266.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6262.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6274.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.mips.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.mips.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.mips.elf PID: 6266, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: Space.mips.elf PID: 6274, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: classification engineClassification label: mal68.troj.evad.linELF@0/0@0/0

        Data Obfuscation

        barindex
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1582/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/3088/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/230/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/110/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/231/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/111/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/232/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1579/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/112/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/233/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1699/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/113/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/234/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1335/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1698/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/114/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/235/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1334/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1576/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/2302/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/115/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/236/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/116/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/237/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/117/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/118/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/910/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/119/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/912/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/10/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/2307/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/11/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/918/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/12/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/13/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/14/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/15/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/16/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/17/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/6247/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/18/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/6246/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1594/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/120/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/121/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1349/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/122/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/243/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/123/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/2/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/124/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/3/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/4/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/125/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/126/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1344/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1465/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1586/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/127/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/6/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/248/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/128/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/249/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1463/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/800/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/9/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/801/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/20/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/21/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1900/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/22/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/23/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/24/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/25/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/26/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/27/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/28/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/29/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/491/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/250/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/130/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/251/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/252/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/132/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/253/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/254/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/255/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/256/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1599/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/257/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1477/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/379/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/258/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1476/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/259/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1475/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/936/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/30/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/2208/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/6262/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/35/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/6267/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1809/statusJump to behavior
        Source: /tmp/Space.mips.elf (PID: 6262)File opened: /proc/1494/statusJump to behavior
        Source: /usr/bin/dash (PID: 6281)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.drTjJyhArt /tmp/tmp.gkLWWzaWTF /tmp/tmp.zTIoASQolqJump to behavior
        Source: /usr/bin/dash (PID: 6282)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.drTjJyhArt /tmp/tmp.gkLWWzaWTF /tmp/tmp.zTIoASQolqJump to behavior
        Source: Space.mips.elfSubmission file: segment LOAD with 7.932 entropy (max. 8.0)
        Source: /tmp/Space.mips.elf (PID: 6262)Queries kernel information via 'uname': Jump to behavior
        Source: Space.mips.elf, 6262.1.00007fffe9903000.00007fffe9924000.rw-.sdmp, Space.mips.elf, 6264.1.00007fffe9903000.00007fffe9924000.rw-.sdmp, Space.mips.elf, 6266.1.00007fffe9903000.00007fffe9924000.rw-.sdmp, Space.mips.elf, 6274.1.00007fffe9903000.00007fffe9924000.rw-.sdmpBinary or memory string: >x86_64/usr/bin/qemu-mips/tmp/Space.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mips.elf
        Source: Space.mips.elf, 6262.1.000055d4b4800000.000055d4b48a7000.rw-.sdmp, Space.mips.elf, 6264.1.000055d4b4800000.000055d4b48a7000.rw-.sdmp, Space.mips.elf, 6266.1.000055d4b4800000.000055d4b48a7000.rw-.sdmp, Space.mips.elf, 6274.1.000055d4b4800000.000055d4b48a7000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
        Source: Space.mips.elf, 6262.1.000055d4b4800000.000055d4b48a7000.rw-.sdmp, Space.mips.elf, 6264.1.000055d4b4800000.000055d4b48a7000.rw-.sdmp, Space.mips.elf, 6266.1.000055d4b4800000.000055d4b48a7000.rw-.sdmp, Space.mips.elf, 6274.1.000055d4b4800000.000055d4b48a7000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
        Source: Space.mips.elf, 6262.1.00007fffe9903000.00007fffe9924000.rw-.sdmp, Space.mips.elf, 6264.1.00007fffe9903000.00007fffe9924000.rw-.sdmp, Space.mips.elf, 6266.1.00007fffe9903000.00007fffe9924000.rw-.sdmp, Space.mips.elf, 6274.1.00007fffe9903000.00007fffe9924000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 6264.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6266.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6262.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6274.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Space.mips.elf PID: 6262, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.mips.elf PID: 6264, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.mips.elf PID: 6266, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 6264.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6266.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6262.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6274.1.00007f9de8400000.00007f9de8418000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: Space.mips.elf PID: 6262, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.mips.elf PID: 6264, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: Space.mips.elf PID: 6266, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
        Obfuscated Files or Information
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
        File Deletion
        LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1575717 Sample: Space.mips.elf Startdate: 16/12/2024 Architecture: LINUX Score: 68 24 109.202.202.202, 80 INIT7CH Switzerland 2->24 26 89.169.4.44, 3778, 50962, 50964 INF-NET-ASRU Russian Federation 2->26 28 2 other IPs or domains 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Yara detected Mirai 2->34 36 Sample is packed with UPX 2->36 8 Space.mips.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 Space.mips.elf 8->14         started        16 Space.mips.elf 8->16         started        18 Space.mips.elf 8->18         started        process6 20 Space.mips.elf 14->20         started        22 Space.mips.elf 14->22         started       
        SourceDetectionScannerLabelLink
        Space.mips.elf37%ReversingLabsLinux.Trojan.Mirai
        Space.mips.elf38%VirustotalBrowse
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://upx.sf.netSpace.mips.elffalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          34.249.145.219
          unknownUnited States
          16509AMAZON-02USfalse
          109.202.202.202
          unknownSwitzerland
          13030INIT7CHfalse
          89.169.4.44
          unknownRussian Federation
          31514INF-NET-ASRUfalse
          91.189.91.42
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          34.249.145.219hmips.elfGet hashmaliciousUnknownBrowse
            armv4l.elfGet hashmaliciousUnknownBrowse
              arm6.nn.elfGet hashmaliciousMirai, OkiruBrowse
                x-8.6-.Logicnet.elfGet hashmaliciousGafgyt, MiraiBrowse
                  arm.elfGet hashmaliciousUnknownBrowse
                    mips.xxx.elfGet hashmaliciousGafgyt, MiraiBrowse
                      main_arm5.elfGet hashmaliciousMiraiBrowse
                        arm7.elfGet hashmaliciousUnknownBrowse
                          mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                            roze.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                              89.169.4.44Space.x86.elfGet hashmaliciousMiraiBrowse
                                Space.arm.elfGet hashmaliciousMiraiBrowse
                                  Space.sh4.elfGet hashmaliciousMiraiBrowse
                                    boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                      boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                        boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                          boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                              boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                  91.189.91.42Space.arm.elfGet hashmaliciousMiraiBrowse
                                                    m68k.elfGet hashmaliciousUnknownBrowse
                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                        bin.sh.elfGet hashmaliciousMiraiBrowse
                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                                              spc.elfGet hashmaliciousUnknownBrowse
                                                                m68k.elfGet hashmaliciousUnknownBrowse
                                                                  mips.elfGet hashmaliciousUnknownBrowse
                                                                    arm.elfGet hashmaliciousUnknownBrowse
                                                                      No context
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      CANONICAL-ASGBSpace.arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      m68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      spc.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      m68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      INF-NET-ASRUSpace.x86.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      Space.arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      Space.sh4.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      jade.m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.156.74
                                                                      https://santa-secret.ru/api/verify?a=NjgyODEwNCw1bWluOHE2MHpuX3J1LC9hY2NvdW50L2JveGVzLHZsYWRpbWlyLmdsdXNoZW5rb0Bob2NobGFuZC5ydSwyNDE0MTYzMg==Get hashmaliciousUnknownBrowse
                                                                      • 87.228.10.139
                                                                      boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                                      • 89.169.4.44
                                                                      INIT7CHSpace.arm.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      m68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      x86.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      .i.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      mpsl.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      spc.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      m68k.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      mips.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      arm.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      AMAZON-02USlmao.exeGet hashmaliciousQuasarBrowse
                                                                      • 52.8.11.142
                                                                      executablelol.exeGet hashmaliciousQuasarBrowse
                                                                      • 52.9.128.160
                                                                      negarque.exeGet hashmaliciousQuasarBrowse
                                                                      • 50.18.181.119
                                                                      enai2.exeGet hashmaliciousNjratBrowse
                                                                      • 3.69.115.178
                                                                      fern_wifi_recon%2.34.exeGet hashmaliciousMetasploitBrowse
                                                                      • 3.6.115.64
                                                                      Krishna33.exeGet hashmaliciousAsyncRATBrowse
                                                                      • 13.215.170.190
                                                                      aaa (3).exeGet hashmaliciousAsyncRATBrowse
                                                                      • 3.68.171.119
                                                                      anne.exeGet hashmaliciousAsyncRATBrowse
                                                                      • 52.14.18.129
                                                                      CrSpoofer.exeGet hashmaliciousAsyncRATBrowse
                                                                      • 18.153.198.123
                                                                      http://18.224.21.137/FFmnpShhHMMWeIqsVa2rJ69xinQlZ-7450Get hashmaliciousUnknownBrowse
                                                                      • 18.224.21.137
                                                                      No context
                                                                      No context
                                                                      No created / dropped files found
                                                                      File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
                                                                      Entropy (8bit):7.929137604923233
                                                                      TrID:
                                                                      • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                      • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                      File name:Space.mips.elf
                                                                      File size:38'116 bytes
                                                                      MD5:47a3da5b7a3334ad0d7d3e319d5e5876
                                                                      SHA1:8710045d8e4ad5ab0561af69d328ba5bfe85ae85
                                                                      SHA256:467f8730b3df7738935b68efa0309ed7b154dc14ca2e87d04e00fddd49d34a2e
                                                                      SHA512:498eca619092e02b0529e37b710c8ae2b4cc23f4afb13b46dc90d67b9f5a17e46e32cc4964469a749e4adc7670ad2718f40387950069106a9f0b2507738334ab
                                                                      SSDEEP:768:EyI187beFSc+RX4qCw7kwGDGRfHBoHJgGlzDpbuR1JI:Eyf7beMbIqCw7jcGXoFVJuK
                                                                      TLSH:0003E166F9300989EA6CE0B80FDC0B615D685F61D4854C36B9E3F6178FE30B230966DD
                                                                      File Content Preview:.ELF.......................h...4.........4. ...(...........................................`.E.`.E.`....................UPX!.d.........D...D.......U.......?.E.h4...@b..) ..]....E..n\rc.. ....M.4Xk8....I.......K......{.1.Z..9..+nj.....8Y...r|..{...........

                                                                      ELF header

                                                                      Class:ELF32
                                                                      Data:2's complement, big endian
                                                                      Version:1 (current)
                                                                      Machine:MIPS R3000
                                                                      Version Number:0x1
                                                                      Type:EXEC (Executable file)
                                                                      OS/ABI:UNIX - System V
                                                                      ABI Version:0
                                                                      Entry Point Address:0x108068
                                                                      Flags:0x1007
                                                                      ELF Header Size:52
                                                                      Program Header Offset:52
                                                                      Program Header Size:32
                                                                      Number of Program Headers:2
                                                                      Section Header Offset:0
                                                                      Section Header Size:40
                                                                      Number of Section Headers:0
                                                                      Header String Table Index:0
                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                      LOAD0x00x1000000x1000000x93ac0x93ac7.93200x5R E0x10000
                                                                      LOAD0xaf600x45af600x45af600x00x00.00000x6RW 0x10000
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Dec 16, 2024 08:57:28.666835070 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:28.786861897 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:28.787133932 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:28.864351034 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 08:57:29.021192074 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:29.141252995 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:29.141309977 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:29.261135101 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:30.110126972 CET37785096289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:30.110358000 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:30.110358953 CET509623778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:30.117027998 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:30.236787081 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:30.236896038 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:30.238781929 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:30.358468056 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:30.358536005 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:30.478368998 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:31.559518099 CET37785096489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:31.559830904 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:31.559832096 CET509643778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:31.560415030 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:31.680315018 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:31.680597067 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:31.681412935 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:31.801424026 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:31.801651955 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:31.921730042 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:33.030785084 CET37785096689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:33.030949116 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:33.030983925 CET509663778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:33.031477928 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:33.153953075 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:33.154067039 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:33.154897928 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:33.274554968 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:33.274672031 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:33.394486904 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:34.481374979 CET37785096889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:34.481621027 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:34.481621027 CET509683778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:34.482508898 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:34.602199078 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:34.602308989 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:34.603634119 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:34.723560095 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:34.723773956 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:34.843522072 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:35.309587002 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:35.429383039 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:35.429450035 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:35.442035913 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:35.562632084 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:35.562679052 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:35.682454109 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:35.929713964 CET37785097089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:35.929930925 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:35.929930925 CET509703778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:35.930557966 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.050277948 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:36.050479889 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.051594019 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.171279907 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:36.171386957 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.291260004 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:36.752084017 CET37785097289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:36.752233028 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.752386093 CET509723778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.753098011 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.872840881 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:36.873016119 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.874006033 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:36.993768930 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:36.993839025 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:37.113868952 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:37.397825956 CET37785097489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:37.397892952 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:37.397942066 CET509743778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:37.400970936 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:37.520925999 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:37.521127939 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:37.522839069 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:37.642553091 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:37.642721891 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:37.762502909 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:38.218452930 CET37785097689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:38.218568087 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.218622923 CET509763778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.219264030 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.339118958 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:38.339365005 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.340310097 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.459995031 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:38.460196018 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.580043077 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:38.845655918 CET37785097889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:38.845855951 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.845855951 CET509783778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.846302986 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.965985060 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:38.966078043 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:38.967540979 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:39.087268114 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:39.087405920 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:39.207137108 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:39.660981894 CET37785098089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:39.661294937 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:39.661294937 CET509803778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:39.662275076 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:39.782044888 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:39.782183886 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:39.784284115 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:39.904257059 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:39.904541969 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:40.024323940 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:40.287306070 CET37785098289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:40.287504911 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:40.287570953 CET509823778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:40.288516045 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:40.408196926 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:40.408441067 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:40.409966946 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:40.529680967 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:40.529941082 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:40.848608971 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.105703115 CET37785098489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.106096029 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.106172085 CET509843778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.107434988 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.227185965 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.227555990 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.229614973 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.349597931 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.349764109 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.469535112 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.729726076 CET37785098689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.729845047 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.729875088 CET509863778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.730529070 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.850318909 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.850394011 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.851758957 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:41.971435070 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:41.971534014 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:42.091602087 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:42.554409981 CET37785098889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:42.554553032 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:42.554613113 CET509883778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:42.555360079 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:42.675149918 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:42.675380945 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:42.676290035 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:42.796039104 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:42.796133995 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:42.915977001 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:43.193372965 CET37785099089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:43.193640947 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:43.193640947 CET509903778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:43.194825888 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:43.314523935 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:43.315097094 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:43.317713022 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:43.437377930 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:43.437603951 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:43.557419062 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:43.586571932 CET4433925634.249.145.219192.168.2.23
                                                                      Dec 16, 2024 08:57:43.587011099 CET39256443192.168.2.2334.249.145.219
                                                                      Dec 16, 2024 08:57:43.706855059 CET4433925634.249.145.219192.168.2.23
                                                                      Dec 16, 2024 08:57:44.000701904 CET37785099289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:44.000972033 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.001015902 CET509923778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.001693964 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.121690989 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:44.121876955 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.122970104 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.242820024 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:44.242953062 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.362857103 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:44.638344049 CET37785099489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:44.638508081 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.638597965 CET509943778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.639436960 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:44.759085894 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:44.759181023 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.447596073 CET37785099689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:45.447906971 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.447906971 CET509963778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.448843002 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.568614006 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:45.568825006 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.570657969 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.661828995 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.690468073 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:45.690583944 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.781610966 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:45.781702995 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.782883883 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:45.810431957 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:45.902637959 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:45.902862072 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:46.022604942 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:46.893695116 CET37785100089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:46.893817902 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:46.894047976 CET510003778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:46.894702911 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.014441013 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:47.014616013 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.016932964 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.037636995 CET4251680192.168.2.23109.202.202.202
                                                                      Dec 16, 2024 08:57:47.125659943 CET37785099889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:47.125772953 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.125879049 CET509983778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.126961946 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.136624098 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:47.136694908 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.246922016 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:47.247103930 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.249212027 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.256484985 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:47.369342089 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:47.369709015 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:47.489597082 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:48.338044882 CET37785100289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:48.338315964 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.338367939 CET510023778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.338906050 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.458686113 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:48.458899975 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.460546017 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.568789005 CET37785100489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:48.568954945 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.569048882 CET510043778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.569720030 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.580322027 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:48.580391884 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.690387964 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:48.690520048 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:48.700200081 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:49.085469007 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 08:57:49.597372055 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.717423916 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:49.717658997 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.720169067 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.782212973 CET37785100689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:49.782361031 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.782452106 CET510063778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.783063889 CET510103778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.839915991 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:49.840348005 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.902837992 CET37785101089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:49.902964115 CET510103778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.904258966 CET510103778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:49.960284948 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:50.024286032 CET37785101089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:50.024492979 CET510103778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:50.144531965 CET37785101089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.049809933 CET37785100889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.050256014 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.050333977 CET510083778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.051326990 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.171117067 CET37785101289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.171394110 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.174117088 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.230859041 CET37785101089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.231215954 CET510103778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.231259108 CET510103778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.232166052 CET510143778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.293883085 CET37785101289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.293984890 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.351906061 CET37785101489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.352106094 CET510143778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.353636980 CET510143778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.413863897 CET37785101289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.473398924 CET37785101489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:51.473648071 CET510143778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:51.593342066 CET37785101489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:52.675941944 CET37785101489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:52.676244020 CET510143778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:52.676367044 CET510143778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:52.677294970 CET510163778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:52.797044039 CET37785101689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:52.797146082 CET510163778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:52.798259974 CET510163778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:52.917975903 CET37785101689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:52.918303967 CET510163778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:53.038096905 CET37785101689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:54.116909981 CET37785101689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:54.117198944 CET510163778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:54.117198944 CET510163778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:54.117798090 CET510183778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:54.237631083 CET37785101889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:54.237876892 CET510183778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:54.238934994 CET510183778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:54.358867884 CET37785101889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:54.358983040 CET510183778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:54.478910923 CET37785101889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:55.559587955 CET37785101889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:55.559935093 CET510183778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:55.560023069 CET510183778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:55.560734034 CET510203778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:55.680593967 CET37785102089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:55.681034088 CET510203778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:55.682235003 CET510203778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:55.801966906 CET37785102089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:55.802123070 CET510203778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:55.922054052 CET37785102089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:57.002425909 CET37785102089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:57.002749920 CET510203778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:57.002749920 CET510203778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:57.003469944 CET510223778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:57.123450994 CET37785102289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:57.123624086 CET510223778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:57.125021935 CET510223778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:57.245054960 CET37785102289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:57.245302916 CET510223778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:57.365185976 CET37785102289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:58.450016022 CET37785102289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:58.450350046 CET510223778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:58.450443029 CET510223778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:58.451082945 CET510243778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:58.570862055 CET37785102489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:58.570934057 CET510243778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:58.572266102 CET510243778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:58.692094088 CET37785102489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:58.692186117 CET510243778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:58.811877012 CET37785102489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:59.894962072 CET37785102489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:57:59.895179987 CET510243778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:59.895179987 CET510243778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:57:59.896106005 CET510263778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:00.016263962 CET37785102689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:00.016479969 CET510263778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:00.018064022 CET510263778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:00.137880087 CET37785102689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:00.138180017 CET510263778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:00.258009911 CET37785102689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:01.182991982 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.302958012 CET37785101289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:01.341576099 CET37785102689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:01.341701031 CET510263778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.341876030 CET510263778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.342621088 CET510283778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.462593079 CET37785102889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:01.462752104 CET510283778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.464103937 CET510283778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.585645914 CET37785102889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:01.585777044 CET510283778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.618179083 CET37785101289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:01.618271112 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:01.706583977 CET37785102889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:02.786895037 CET37785102889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:02.787107944 CET510283778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:02.787107944 CET510283778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:02.787990093 CET510303778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:02.907665014 CET37785103089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:02.907824039 CET510303778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:02.909120083 CET510303778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:03.028877020 CET37785103089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:03.029112101 CET510303778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:03.149055958 CET37785103089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:04.229733944 CET37785103089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:04.230113983 CET510303778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:04.230114937 CET510303778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:04.231292963 CET510323778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:04.351135015 CET37785103289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:04.351555109 CET510323778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:04.353037119 CET510323778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:04.472815037 CET37785103289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:04.473067999 CET510323778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:04.592947960 CET37785103289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:05.678777933 CET37785103289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:05.679076910 CET510323778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:05.679207087 CET510323778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:05.679969072 CET510343778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:05.799824953 CET37785103489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:05.800153971 CET510343778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:05.801825047 CET510343778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:05.921888113 CET37785103489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:05.922029018 CET510343778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:06.041953087 CET37785103489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:07.121737957 CET37785103489.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:07.121915102 CET510343778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:07.121958971 CET510343778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:07.122481108 CET510363778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:07.242254972 CET37785103689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:07.242563963 CET510363778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:07.243415117 CET510363778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:07.363167048 CET37785103689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:07.363353014 CET510363778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:07.483392954 CET37785103689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:08.570902109 CET37785103689.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:08.571144104 CET510363778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:08.571144104 CET510363778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:08.571804047 CET510383778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:08.691855907 CET37785103889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:08.692156076 CET510383778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:08.693327904 CET510383778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:08.813429117 CET37785103889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:08.813556910 CET510383778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:08.933756113 CET37785103889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:10.053082943 CET37785103889.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:10.053412914 CET510383778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:10.053412914 CET510383778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:10.054100990 CET510403778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:10.173985004 CET37785104089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:10.174120903 CET510403778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:10.175421000 CET510403778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:10.295267105 CET37785104089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:10.295471907 CET510403778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:10.415666103 CET37785104089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:11.498759031 CET37785104089.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:11.499013901 CET510403778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:11.499059916 CET510403778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:11.499666929 CET510423778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:11.619646072 CET37785104289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:11.619775057 CET510423778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:11.620443106 CET510423778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:11.740232944 CET37785104289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:11.740377903 CET510423778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:11.861118078 CET37785104289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:21.629983902 CET510423778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:21.750202894 CET37785104289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:22.061608076 CET37785104289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:58:22.061944008 CET510423778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:58:30.039438009 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 08:59:01.666040897 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:59:01.786052942 CET37785101289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:59:02.100426912 CET37785101289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:59:02.100754023 CET510123778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:59:22.103843927 CET510423778192.168.2.2389.169.4.44
                                                                      Dec 16, 2024 08:59:22.224523067 CET37785104289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:59:22.536818981 CET37785104289.169.4.44192.168.2.23
                                                                      Dec 16, 2024 08:59:22.537307978 CET510423778192.168.2.2389.169.4.44

                                                                      System Behavior

                                                                      Start time (UTC):07:57:27
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.mips.elf
                                                                      Arguments:/tmp/Space.mips.elf
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):07:57:27
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.mips.elf
                                                                      Arguments:-
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):07:57:27
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.mips.elf
                                                                      Arguments:-
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):07:57:27
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.mips.elf
                                                                      Arguments:-
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):07:57:34
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.mips.elf
                                                                      Arguments:-
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):07:57:34
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/Space.mips.elf
                                                                      Arguments:-
                                                                      File size:5777432 bytes
                                                                      MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                                      Start time (UTC):07:57:42
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):07:57:42
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/rm
                                                                      Arguments:rm -f /tmp/tmp.drTjJyhArt /tmp/tmp.gkLWWzaWTF /tmp/tmp.zTIoASQolq
                                                                      File size:72056 bytes
                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                      Start time (UTC):07:57:42
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):07:57:42
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/rm
                                                                      Arguments:rm -f /tmp/tmp.drTjJyhArt /tmp/tmp.gkLWWzaWTF /tmp/tmp.zTIoASQolq
                                                                      File size:72056 bytes
                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b