Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.ppc.elf

Overview

General Information

Sample name:Space.ppc.elf
Analysis ID:1575724
MD5:0474965d631bc9d0de2ce54e45ec2113
SHA1:34f123a32b4f02f10f1ef11a3bae307ff7c96d27
SHA256:61dc9e6eb18e4882d8bebf6e046f8fc2d8ea1da0117416ea9dbbedd0cc86c73b
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1575724
Start date and time:2024-12-16 09:04:51 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.ppc.elf
Detection:MAL
Classification:mal76.troj.evad.linELF@0/0@0/0
Command:/tmp/Space.ppc.elf
PID:5475
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5525, Parent: 3633)
  • rm (PID: 5525, Parent: 3633, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.xziUcqrt4D /tmp/tmp.Gwq6tq1fbX /tmp/tmp.2XW13rOwNj
  • dash New Fork (PID: 5526, Parent: 3633)
  • rm (PID: 5526, Parent: 3633, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.xziUcqrt4D /tmp/tmp.Gwq6tq1fbX /tmp/tmp.2XW13rOwNj
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
5475.1.00007fb60c005000.00007fb60c011000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xb54c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb59c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb600:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb614:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb63c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb650:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb664:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb678:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb68c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5489.1.00007fb60c005000.00007fb60c011000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xb54c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb59c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb5ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb600:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb614:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb63c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb650:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb664:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb678:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb68c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xb6dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5477.1.00007fb60c00f000.00007fb60c011000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x154c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x159c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1600:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1614:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x163c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1650:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1664:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1678:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x168c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5479.1.00007fb60c00f000.00007fb60c011000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x154c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1560:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1574:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1588:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x159c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x15ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1600:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1614:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1628:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x163c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1650:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1664:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1678:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x168c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x16dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.ppc.elf PID: 5475JoeSecurity_Mirai_8Yara detected MiraiJoe Security
    Click to see the 7 entries
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: Space.ppc.elfAvira: detected
    Source: Space.ppc.elfVirustotal: Detection: 49%Perma Link
    Source: Space.ppc.elfReversingLabs: Detection: 47%
    Source: global trafficTCP traffic: 192.168.2.14:46686 -> 89.169.4.44:3778
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: unknownTCP traffic detected without corresponding DNS query: 89.169.4.44
    Source: Space.ppc.elfString found in binary or memory: http://upx.sf.net
    Source: unknownNetwork traffic detected: HTTP traffic on port 34592 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34592

    System Summary

    barindex
    Source: 5475.1.00007fb60c005000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5489.1.00007fb60c005000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5477.1.00007fb60c00f000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: 5479.1.00007fb60c00f000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: Space.ppc.elf PID: 5475, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: Space.ppc.elf PID: 5477, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: Space.ppc.elf PID: 5479, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: Process Memory Space: Space.ppc.elf PID: 5489, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
    Source: LOAD without section mappingsProgram segment: 0x100000
    Source: 5475.1.00007fb60c005000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5489.1.00007fb60c005000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5477.1.00007fb60c00f000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: 5479.1.00007fb60c00f000.00007fb60c011000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: Space.ppc.elf PID: 5475, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: Space.ppc.elf PID: 5477, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: Space.ppc.elf PID: 5479, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: Process Memory Space: Space.ppc.elf PID: 5489, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
    Source: classification engineClassification label: mal76.troj.evad.linELF@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1583/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/2672/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/110/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/111/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/112/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/113/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/234/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1577/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/114/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/235/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/115/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/116/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/117/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/118/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/119/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3752/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3753/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3633/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3754/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3755/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/10/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/917/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/11/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/12/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/13/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/14/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/15/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/16/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/17/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/18/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/19/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1593/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/240/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/120/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3094/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/121/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/242/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3406/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/122/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/243/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/2/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/123/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/244/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1589/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/124/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/245/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1588/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/125/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/4/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/246/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3402/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/126/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/5/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/247/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/127/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/6/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/248/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/128/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/7/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/249/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/8/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/129/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/800/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/9/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/801/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/803/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/20/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/806/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/21/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/807/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/928/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/22/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/23/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/24/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/25/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/26/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/27/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/28/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/29/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3420/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/490/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/250/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/130/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/251/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/131/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/252/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/132/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/253/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/254/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/255/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/135/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/256/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1599/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/257/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/378/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/258/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/3412/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/259/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/30/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/35/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/1371/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/260/statusJump to behavior
    Source: /tmp/Space.ppc.elf (PID: 5475)File opened: /proc/261/statusJump to behavior
    Source: /usr/bin/dash (PID: 5525)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.xziUcqrt4D /tmp/tmp.Gwq6tq1fbX /tmp/tmp.2XW13rOwNjJump to behavior
    Source: /usr/bin/dash (PID: 5526)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.xziUcqrt4D /tmp/tmp.Gwq6tq1fbX /tmp/tmp.2XW13rOwNjJump to behavior
    Source: Space.ppc.elfSubmission file: segment LOAD with 7.9573 entropy (max. 8.0)
    Source: /tmp/Space.ppc.elf (PID: 5475)Queries kernel information via 'uname': Jump to behavior
    Source: Space.ppc.elf, 5477.1.000055d46f531000.000055d46f5e1000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
    Source: Space.ppc.elf, 5475.1.000055d46f531000.000055d46f602000.rw-.sdmp, Space.ppc.elf, 5479.1.000055d46f531000.000055d46f5e1000.rw-.sdmp, Space.ppc.elf, 5489.1.000055d46f531000.000055d46f602000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
    Source: Space.ppc.elf, 5475.1.000055d46f531000.000055d46f602000.rw-.sdmp, Space.ppc.elf, 5477.1.000055d46f531000.000055d46f5e1000.rw-.sdmp, Space.ppc.elf, 5479.1.000055d46f531000.000055d46f5e1000.rw-.sdmp, Space.ppc.elf, 5489.1.000055d46f531000.000055d46f602000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
    Source: Space.ppc.elf, 5475.1.00007fff42332000.00007fff42353000.rw-.sdmp, Space.ppc.elf, 5477.1.00007fff42332000.00007fff42353000.rw-.sdmp, Space.ppc.elf, 5479.1.00007fff42332000.00007fff42353000.rw-.sdmp, Space.ppc.elf, 5489.1.00007fff42332000.00007fff42353000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
    Source: Space.ppc.elf, 5475.1.00007fff42332000.00007fff42353000.rw-.sdmp, Space.ppc.elf, 5477.1.00007fff42332000.00007fff42353000.rw-.sdmp, Space.ppc.elf, 5479.1.00007fff42332000.00007fff42353000.rw-.sdmp, Space.ppc.elf, 5489.1.00007fff42332000.00007fff42353000.rw-.sdmpBinary or memory string: xx86_64/usr/bin/qemu-ppc/tmp/Space.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.ppc.elf

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5475, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5477, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5479, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5489, type: MEMORYSTR

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5475, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5477, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5479, type: MEMORYSTR
    Source: Yara matchFile source: Process Memory Space: Space.ppc.elf PID: 5489, type: MEMORYSTR
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
    Obfuscated Files or Information
    1
    OS Credential Dumping
    11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    File Deletion
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1575724 Sample: Space.ppc.elf Startdate: 16/12/2024 Architecture: LINUX Score: 76 24 89.169.4.44, 3778, 46686, 46688 INF-NET-ASRU Russian Federation 2->24 26 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->26 28 54.217.10.153, 34592, 443 AMAZON-02US United States 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Antivirus / Scanner detection for submitted sample 2->32 34 Multi AV Scanner detection for submitted file 2->34 36 2 other signatures 2->36 8 Space.ppc.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 Space.ppc.elf 8->14         started        16 Space.ppc.elf 8->16         started        18 Space.ppc.elf 8->18         started        process6 20 Space.ppc.elf 14->20         started        22 Space.ppc.elf 14->22         started       

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    Space.ppc.elf49%VirustotalBrowse
    Space.ppc.elf47%ReversingLabsLinux.Trojan.Mirai
    Space.ppc.elf100%AviraEXP/ELF.Agent.F.118
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netSpace.ppc.elffalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      54.217.10.153
      unknownUnited States
      16509AMAZON-02USfalse
      185.125.190.26
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      89.169.4.44
      unknownRussian Federation
      31514INF-NET-ASRUfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      54.217.10.153.5r3fqt67ew531has4231.mpsl.elfGet hashmaliciousGafgyt, Mirai, Moobot, OkiruBrowse
        m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
          i686.elfGet hashmaliciousMirai, GafgytBrowse
            loligang.arm5.elfGet hashmaliciousMiraiBrowse
              vqsjh4.elfGet hashmaliciousMiraiBrowse
                x-3.2-.ISIS.elfGet hashmaliciousGafgytBrowse
                  m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                    shindeVx86.elfGet hashmaliciousUnknownBrowse
                      linux_mips.elfGet hashmaliciousChaosBrowse
                        assailant.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                          185.125.190.26main_mpsl.elfGet hashmaliciousMiraiBrowse
                            main_ppc.elfGet hashmaliciousMiraiBrowse
                              hidakibest.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                  rebirth.m68.elfGet hashmaliciousGafgytBrowse
                                    rebirth.spc.elfGet hashmaliciousGafgytBrowse
                                      rebirth.arm4.elfGet hashmaliciousGafgytBrowse
                                        boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                          a-r.m-4.Logicnet.elfGet hashmaliciousGafgyt, MiraiBrowse
                                            elitebotnet.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                                              89.169.4.44Space.arm7.elfGet hashmaliciousMiraiBrowse
                                                Space.i686.elfGet hashmaliciousMiraiBrowse
                                                  Space.m68k.elfGet hashmaliciousMiraiBrowse
                                                    Space.spc.elfGet hashmaliciousMiraiBrowse
                                                      Space.x86_64.elfGet hashmaliciousMiraiBrowse
                                                        Space.mips.elfGet hashmaliciousMiraiBrowse
                                                          Space.x86.elfGet hashmaliciousMiraiBrowse
                                                            Space.arm.elfGet hashmaliciousMiraiBrowse
                                                              Space.sh4.elfGet hashmaliciousMiraiBrowse
                                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                                  No context
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  INF-NET-ASRUSpace.arm7.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.i686.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.spc.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.x86_64.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.x86.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.arm.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  Space.sh4.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.4.44
                                                                  jade.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 89.169.156.74
                                                                  CANONICAL-ASGBSpace.i686.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  Space.mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  Space.arm.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  m68k.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  x86.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  bin.sh.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  .i.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  mpsl.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  spc.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  m68k.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  AMAZON-02USSpace.mips.elfGet hashmaliciousMiraiBrowse
                                                                  • 34.249.145.219
                                                                  lmao.exeGet hashmaliciousQuasarBrowse
                                                                  • 52.8.11.142
                                                                  executablelol.exeGet hashmaliciousQuasarBrowse
                                                                  • 52.9.128.160
                                                                  negarque.exeGet hashmaliciousQuasarBrowse
                                                                  • 50.18.181.119
                                                                  enai2.exeGet hashmaliciousNjratBrowse
                                                                  • 3.69.115.178
                                                                  fern_wifi_recon%2.34.exeGet hashmaliciousMetasploitBrowse
                                                                  • 3.6.115.64
                                                                  Krishna33.exeGet hashmaliciousAsyncRATBrowse
                                                                  • 13.215.170.190
                                                                  aaa (3).exeGet hashmaliciousAsyncRATBrowse
                                                                  • 3.68.171.119
                                                                  anne.exeGet hashmaliciousAsyncRATBrowse
                                                                  • 52.14.18.129
                                                                  CrSpoofer.exeGet hashmaliciousAsyncRATBrowse
                                                                  • 18.153.198.123
                                                                  No context
                                                                  No context
                                                                  No created / dropped files found
                                                                  File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (GNU/Linux), statically linked, no section header
                                                                  Entropy (8bit):7.954542194785649
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                  File name:Space.ppc.elf
                                                                  File size:35'156 bytes
                                                                  MD5:0474965d631bc9d0de2ce54e45ec2113
                                                                  SHA1:34f123a32b4f02f10f1ef11a3bae307ff7c96d27
                                                                  SHA256:61dc9e6eb18e4882d8bebf6e046f8fc2d8ea1da0117416ea9dbbedd0cc86c73b
                                                                  SHA512:0a397b19905ce372a23a590821c2864833b18db7309d03dee8fcd086729e934728bef727339a75ec8f6af3a89690536205744d5857ff80ce191271f803349226
                                                                  SSDEEP:768:yl3cWFWEdCEv4Fr1WmPc+ClLIT6Ot34uVcqgw09u:ylsW86Mr1WmU+ClL+b4u+qgw09u
                                                                  TLSH:9CF2E1A4F4444EC8DA67ADF059266FA0B3BB1E4F77FEEA15508ACE1131058273183DC9
                                                                  File Content Preview:.ELF......................vp...4.........4. ...(.......................X...X..............I...I...I.................dt.Q................................UPX!..........%...%........V.......?.E.h4...@b..............d...[.Q.........4+j..``*:.D.k.'.I.I..w]....

                                                                  ELF header

                                                                  Class:ELF32
                                                                  Data:2's complement, big endian
                                                                  Version:1 (current)
                                                                  Machine:PowerPC
                                                                  Version Number:0x1
                                                                  Type:EXEC (Executable file)
                                                                  OS/ABI:UNIX - Linux
                                                                  ABI Version:0
                                                                  Entry Point Address:0x107670
                                                                  Flags:0x0
                                                                  ELF Header Size:52
                                                                  Program Header Offset:52
                                                                  Program Header Size:32
                                                                  Number of Program Headers:3
                                                                  Section Header Offset:0
                                                                  Section Header Size:40
                                                                  Number of Section Headers:0
                                                                  Header String Table Index:0
                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  LOAD0x00x1000000x1000000x88580x88587.95730x5R E0x10000
                                                                  LOAD0x499c0x1002499c0x1002499c0x00x00.00000x6RW 0x10000
                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Dec 16, 2024 09:05:33.142932892 CET466863778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:33.262759924 CET37784668689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:33.262821913 CET466863778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:33.278409958 CET466863778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:33.399822950 CET37784668689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:33.399873972 CET466863778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:33.519629002 CET37784668689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:34.615344048 CET37784668689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:34.615895987 CET466863778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:34.615896940 CET466863778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:34.616811037 CET466883778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:34.736608028 CET37784668889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:34.736782074 CET466883778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:34.739846945 CET466883778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:34.859600067 CET37784668889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:34.859749079 CET466883778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:34.979572058 CET37784668889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:36.058126926 CET37784668889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:36.058324099 CET466883778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:36.058362007 CET466883778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:36.059129000 CET466903778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:36.182694912 CET37784669089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:36.182898045 CET466903778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:36.183809996 CET466903778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:36.303898096 CET37784669089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:36.304147959 CET466903778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:36.423921108 CET37784669089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:37.510375023 CET37784669089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:37.510945082 CET466903778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:37.510945082 CET466903778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:37.511529922 CET466923778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:37.631438017 CET37784669289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:37.631740093 CET466923778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:37.632581949 CET466923778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:37.752314091 CET37784669289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:37.752476931 CET466923778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:37.872265100 CET37784669289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:38.793620110 CET466943778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:38.913311958 CET37784669489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:38.913425922 CET466943778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:38.947087049 CET466943778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:38.957457066 CET37784669289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:38.957634926 CET466923778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:38.957634926 CET466923778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:38.958714008 CET466963778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:39.066761971 CET37784669489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:39.066839933 CET466943778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:39.078622103 CET37784669689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:39.078675985 CET466963778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:39.103488922 CET466963778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:39.186556101 CET37784669489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:39.223275900 CET37784669689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:39.223412037 CET466963778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:39.343192101 CET37784669689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.236685038 CET37784669489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.236964941 CET466943778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.237061977 CET466943778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.238039970 CET466983778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.357857943 CET37784669889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.358099937 CET466983778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.359376907 CET466983778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.407896042 CET37784669689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.408029079 CET466963778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.408080101 CET466963778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.410013914 CET467003778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.479065895 CET37784669889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.479203939 CET466983778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.529779911 CET37784670089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.530536890 CET467003778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.533528090 CET467003778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.598870039 CET37784669889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.653228998 CET37784670089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:40.653454065 CET467003778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:40.773216963 CET37784670089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:41.690650940 CET37784669889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:41.690767050 CET466983778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.690807104 CET466983778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.691380978 CET467023778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.811821938 CET37784670289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:41.812035084 CET467023778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.812813997 CET467023778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.855402946 CET37784670089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:41.855494022 CET467003778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.855684042 CET467003778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.856190920 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.933651924 CET37784670289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:41.933845997 CET467023778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:41.975900888 CET37784670489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:41.976089001 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:42.053555012 CET37784670289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:42.624696970 CET46540443192.168.2.14185.125.190.26
                                                                  Dec 16, 2024 09:05:42.880644083 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.000519037 CET37784670489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:43.000693083 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.001827955 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.121701002 CET37784670489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:43.121968985 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.135632992 CET37784670289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:43.135930061 CET467023778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.135930061 CET467023778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.136508942 CET467063778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.241985083 CET37784670489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:43.256225109 CET37784670689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:43.256377935 CET467063778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.257540941 CET467063778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.377346039 CET37784670689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:43.377604008 CET467063778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:43.497451067 CET37784670689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.324348927 CET37784670489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.324525118 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.324599981 CET467043778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.325218916 CET467083778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.444957018 CET37784670889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.445332050 CET467083778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.446433067 CET467083778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.566196918 CET37784670889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.566385031 CET467083778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.579453945 CET37784670689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.579618931 CET467063778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.579677105 CET467063778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.580262899 CET467103778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.686808109 CET37784670889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.700030088 CET37784671089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.700206041 CET467103778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.701167107 CET467103778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.820933104 CET37784671089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:44.821149111 CET467103778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:44.940865040 CET37784671089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:45.772449970 CET37784670889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:45.772618055 CET467083778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:45.772650957 CET467083778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:45.773269892 CET467123778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:45.892993927 CET37784671289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:45.893142939 CET467123778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:45.894239902 CET467123778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.013964891 CET37784671289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:46.014108896 CET467123778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.051664114 CET37784671089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:46.051779985 CET467103778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.051816940 CET467103778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.052386999 CET467143778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.133884907 CET37784671289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:46.172074080 CET37784671489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:46.172200918 CET467143778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.172972918 CET467143778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.292655945 CET37784671489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:46.293040037 CET467143778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:46.412826061 CET37784671489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.215148926 CET37784671289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.215426922 CET467123778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.215490103 CET467123778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.216363907 CET467163778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.336215973 CET37784671689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.336375952 CET467163778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.337879896 CET467163778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.457657099 CET37784671689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.457824945 CET467163778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.501347065 CET37784671489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.501568079 CET467143778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.501616955 CET467143778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.502290010 CET467183778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.577662945 CET37784671689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.622128963 CET37784671889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.622359037 CET467183778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.623542070 CET467183778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.743310928 CET37784671889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:47.743479967 CET467183778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:47.863238096 CET37784671889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:48.662691116 CET37784671689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:48.662874937 CET467163778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.662906885 CET467163778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.663727999 CET467203778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.784584045 CET37784672089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:48.784759045 CET467203778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.786771059 CET467203778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.906596899 CET37784672089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:48.906754017 CET467203778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.942202091 CET37784671889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:48.942372084 CET467183778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.942372084 CET467183778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:48.943068027 CET467223778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:49.026732922 CET37784672089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:49.062920094 CET37784672289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:49.063174963 CET467223778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:49.064677954 CET467223778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:49.184427977 CET37784672289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:49.184685946 CET467223778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:49.306235075 CET37784672289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.125211000 CET37784672089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.125368118 CET467203778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.125591993 CET467203778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.126669884 CET467243778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.246917009 CET37784672489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.247078896 CET467243778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.248440027 CET467243778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.368236065 CET37784672489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.368561029 CET467243778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.389411926 CET37784672289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.389534950 CET467223778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.389611006 CET467223778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.390261889 CET467263778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.489979029 CET37784672489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.511255026 CET37784672689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.511435986 CET467263778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.513115883 CET467263778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.633322954 CET37784672689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:50.633510113 CET467263778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:50.755260944 CET37784672689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:51.573396921 CET37784672489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:51.573594093 CET467243778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.573627949 CET467243778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.574332952 CET467283778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.694114923 CET37784672889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:51.694355965 CET467283778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.695691109 CET467283778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.818147898 CET37784672889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:51.818550110 CET467283778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.836740017 CET37784672689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:51.837012053 CET467263778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.837137938 CET467263778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.838042974 CET467303778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.938504934 CET37784672889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:51.958684921 CET37784673089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:51.958998919 CET467303778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:51.960149050 CET467303778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:52.080909967 CET37784673089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:52.081175089 CET467303778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:52.200891972 CET37784673089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.016834974 CET37784672889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.017021894 CET467283778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.017112970 CET467283778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.017946959 CET467323778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.137741089 CET37784673289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.137916088 CET467323778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.139367104 CET467323778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.259150982 CET37784673289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.259274006 CET467323778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.285209894 CET37784673089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.285352945 CET467303778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.285387039 CET467303778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.286015034 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.379044056 CET37784673289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.405745983 CET37784673489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.406095982 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.407114983 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.527482986 CET37784673489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:53.527661085 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:53.647402048 CET37784673489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:54.458534956 CET37784673289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:54.458697081 CET467323778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:54.458794117 CET467323778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:54.459686041 CET467363778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:54.579705000 CET37784673689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:54.579857111 CET467363778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:54.581243038 CET467363778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:54.701241016 CET37784673689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:54.701385021 CET467363778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:54.821377039 CET37784673689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:55.931735992 CET37784673689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:55.931921959 CET467363778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:55.932008028 CET467363778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:55.932868958 CET467383778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:56.052625895 CET37784673889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:56.052800894 CET467383778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:56.053889990 CET467383778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:56.173736095 CET37784673889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:56.173898935 CET467383778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:56.293757915 CET37784673889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:57.377635956 CET37784673889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:57.377875090 CET467383778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:57.378053904 CET467383778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:57.378889084 CET467403778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:57.498553991 CET37784674089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:57.498792887 CET467403778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:57.500422955 CET467403778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:57.620253086 CET37784674089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:57.620388031 CET467403778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:57.740469933 CET37784674089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:58.823951006 CET37784674089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:58.824070930 CET467403778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:58.824110985 CET467403778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:58.824965000 CET467423778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:58.944746017 CET37784674289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:58.944957972 CET467423778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:58.946191072 CET467423778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:59.065918922 CET37784674289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:05:59.066081047 CET467423778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:05:59.185902119 CET37784674289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:00.268850088 CET37784674289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:00.269164085 CET467423778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:00.269223928 CET467423778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:00.270415068 CET467443778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:00.390165091 CET37784674489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:00.390330076 CET467443778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:00.392112970 CET467443778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:00.511960030 CET37784674489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:00.512093067 CET467443778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:00.631947994 CET37784674489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:01.728091955 CET37784674489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:01.728411913 CET467443778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:01.728452921 CET467443778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:01.729492903 CET467463778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:01.849319935 CET37784674689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:01.849673986 CET467463778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:01.851089954 CET467463778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:01.884938002 CET34592443192.168.2.1454.217.10.153
                                                                  Dec 16, 2024 09:06:01.970808983 CET37784674689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:01.970880032 CET467463778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:02.005331039 CET4433459254.217.10.153192.168.2.14
                                                                  Dec 16, 2024 09:06:02.005454063 CET34592443192.168.2.1454.217.10.153
                                                                  Dec 16, 2024 09:06:02.090593100 CET37784674689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:03.175473928 CET37784674689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:03.175622940 CET467463778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:03.175780058 CET467463778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:03.176595926 CET467483778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:03.296478033 CET37784674889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:03.296648979 CET467483778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:03.298151970 CET467483778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:03.415730953 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:03.417929888 CET37784674889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:03.418068886 CET467483778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:03.535928011 CET37784673489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:03.538109064 CET37784674889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:03.849592924 CET37784673489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:03.849909067 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:04.621963978 CET37784674889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:04.622288942 CET467483778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:04.622395039 CET467483778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:04.624136925 CET467503778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:04.744048119 CET37784675089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:04.744229078 CET467503778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:04.746124983 CET467503778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:04.865837097 CET37784675089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:04.865987062 CET467503778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:04.985853910 CET37784675089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:06.097299099 CET37784675089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:06.097456932 CET467503778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:06.097568035 CET467503778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:06.098342896 CET467523778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:06.218740940 CET37784675289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:06.219058037 CET467523778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:06.220125914 CET467523778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:06.339833975 CET37784675289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:06.340002060 CET467523778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:06.459896088 CET37784675289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:07.543461084 CET37784675289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:07.543740034 CET467523778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:07.543740988 CET467523778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:07.544570923 CET467543778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:07.664313078 CET37784675489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:07.664443970 CET467543778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:07.665694952 CET467543778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:07.785454035 CET37784675489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:07.785576105 CET467543778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:07.905294895 CET37784675489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:08.989517927 CET37784675489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:08.989742994 CET467543778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:08.989743948 CET467543778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:08.990132093 CET467563778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:09.110152960 CET37784675689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:09.110296011 CET467563778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:09.112552881 CET467563778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:09.232402086 CET37784675689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:09.232630968 CET467563778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:09.352477074 CET37784675689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:10.473251104 CET37784675689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:10.473377943 CET467563778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:10.473423958 CET467563778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:10.474476099 CET467583778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:10.602860928 CET37784675889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:10.602994919 CET467583778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:10.604387999 CET467583778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:10.724248886 CET37784675889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:10.724376917 CET467583778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:10.844093084 CET37784675889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:11.940114975 CET37784675889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:11.940256119 CET467583778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:11.940296888 CET467583778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:11.940912008 CET467603778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:12.060730934 CET37784676089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:12.060859919 CET467603778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:12.061669111 CET467603778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:12.181580067 CET37784676089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:12.181751966 CET467603778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:12.301583052 CET37784676089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:12.575201988 CET46540443192.168.2.14185.125.190.26
                                                                  Dec 16, 2024 09:06:13.383563042 CET37784676089.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:13.383774042 CET467603778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:13.383821964 CET467603778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:13.384601116 CET467623778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:13.504484892 CET37784676289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:13.504601955 CET467623778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:13.506223917 CET467623778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:13.625988007 CET37784676289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:13.626106977 CET467623778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:13.745891094 CET37784676289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:14.825449944 CET37784676289.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:14.825683117 CET467623778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:14.825684071 CET467623778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:14.826268911 CET467643778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:14.945990086 CET37784676489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:14.946186066 CET467643778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:14.947935104 CET467643778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:15.067619085 CET37784676489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:15.067823887 CET467643778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:15.187582016 CET37784676489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:16.294756889 CET37784676489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:16.295101881 CET467643778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:16.295257092 CET467643778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:16.295922995 CET467663778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:16.419496059 CET37784676689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:16.419694901 CET467663778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:16.421334982 CET467663778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:16.541022062 CET37784676689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:16.541160107 CET467663778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:16.661031008 CET37784676689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:17.741638899 CET37784676689.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:17.741908073 CET467663778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:17.741981030 CET467663778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:17.742791891 CET467683778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:18.057143927 CET37784676889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:18.057254076 CET467683778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:18.058156967 CET467683778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:18.216778040 CET37784676889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:18.216952085 CET467683778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:18.338392019 CET37784676889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:28.067926884 CET467683778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:06:28.187882900 CET37784676889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:28.501996040 CET37784676889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:06:28.502139091 CET467683778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:07:03.895232916 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:07:04.015263081 CET37784673489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:07:04.329457998 CET37784673489.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:07:04.329622984 CET467343778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:07:28.559453964 CET467683778192.168.2.1489.169.4.44
                                                                  Dec 16, 2024 09:07:28.679327011 CET37784676889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:07:28.995151043 CET37784676889.169.4.44192.168.2.14
                                                                  Dec 16, 2024 09:07:28.995284081 CET467683778192.168.2.1489.169.4.44

                                                                  System Behavior

                                                                  Start time (UTC):08:05:31
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/tmp/Space.ppc.elf
                                                                  Arguments:/tmp/Space.ppc.elf
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):08:05:31
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/tmp/Space.ppc.elf
                                                                  Arguments:-
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):08:05:31
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/tmp/Space.ppc.elf
                                                                  Arguments:-
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):08:05:31
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/tmp/Space.ppc.elf
                                                                  Arguments:-
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):08:05:37
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/tmp/Space.ppc.elf
                                                                  Arguments:-
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):08:05:37
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/tmp/Space.ppc.elf
                                                                  Arguments:-
                                                                  File size:5388968 bytes
                                                                  MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                  Start time (UTC):08:06:00
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):08:06:00
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.xziUcqrt4D /tmp/tmp.Gwq6tq1fbX /tmp/tmp.2XW13rOwNj
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                  Start time (UTC):08:06:00
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/usr/bin/dash
                                                                  Arguments:-
                                                                  File size:129816 bytes
                                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                  Start time (UTC):08:06:00
                                                                  Start date (UTC):16/12/2024
                                                                  Path:/usr/bin/rm
                                                                  Arguments:rm -f /tmp/tmp.xziUcqrt4D /tmp/tmp.Gwq6tq1fbX /tmp/tmp.2XW13rOwNj
                                                                  File size:72056 bytes
                                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b