Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
sh4.elf

Overview

General Information

Sample name:sh4.elf
Analysis ID:1575989
MD5:866c52bc44c007685c49f5f7c51e05ca
SHA1:83bb15de9ff6d7501897689e97907fe80f329604
SHA256:3c0c87bbc1a908ee2d698bf59722fc050b29aa5dcc9312a7c33c04910ad2f067
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Mirai
Contains symbols with names commonly found in malware
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample contains strings that are user agent strings indicative of HTTP manipulation
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1575989
Start date and time:2024-12-16 13:08:29 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:sh4.elf
Detection:MAL
Classification:mal100.spre.troj.linELF@0/0@0/0
  • VT rate limit hit for: sh4.elf
Command:/tmp/sh4.elf
PID:6262
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6225, Parent: 4331)
  • rm (PID: 6225, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.25mzlEEvpZ /tmp/tmp.DDq2YkcMbt /tmp/tmp.scdstBQjf3
  • dash New Fork (PID: 6226, Parent: 4331)
  • cat (PID: 6226, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.25mzlEEvpZ
  • dash New Fork (PID: 6227, Parent: 4331)
  • head (PID: 6227, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6228, Parent: 4331)
  • tr (PID: 6228, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6229, Parent: 4331)
  • cut (PID: 6229, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6230, Parent: 4331)
  • cat (PID: 6230, Parent: 4331, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.25mzlEEvpZ
  • dash New Fork (PID: 6231, Parent: 4331)
  • head (PID: 6231, Parent: 4331, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6232, Parent: 4331)
  • tr (PID: 6232, Parent: 4331, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6233, Parent: 4331)
  • cut (PID: 6233, Parent: 4331, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6234, Parent: 4331)
  • rm (PID: 6234, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.25mzlEEvpZ /tmp/tmp.DDq2YkcMbt /tmp/tmp.scdstBQjf3
  • sh4.elf (PID: 6262, Parent: 6157, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/sh4.elf
    • sh4.elf New Fork (PID: 6264, Parent: 6262)
      • sh4.elf New Fork (PID: 6266, Parent: 6264)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
sh4.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    sh4.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      sh4.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xdd38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdd4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdd60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdd74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdd88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdd9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xddb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xddc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xddd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xddec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xde8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdea0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdeb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdec8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      SourceRuleDescriptionAuthorStrings
      6262.1.00007f70ec400000.00007f70ec410000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6262.1.00007f70ec400000.00007f70ec410000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0xdd38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdd4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdd60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdd74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdd88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdd9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xddb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xddc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xddd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xddec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xde8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdea0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdeb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xdec8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        6264.1.00007f70ec400000.00007f70ec410000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          6264.1.00007f70ec400000.00007f70ec410000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xdd38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdd4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdd60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdd74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdd88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdd9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xddb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xddc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xddd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xddec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xde8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdea0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdeb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdec8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          Process Memory Space: sh4.elf PID: 6262JoeSecurity_Mirai_8Yara detected MiraiJoe Security
            Click to see the 3 entries
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-12-16T13:09:18.671976+010028465261A Network Trojan was detected192.168.2.2340762150.241.88.13225565TCP
            2024-12-16T13:09:20.989883+010028465261A Network Trojan was detected192.168.2.2340764150.241.88.13225565TCP
            2024-12-16T13:09:23.346054+010028465261A Network Trojan was detected192.168.2.2340766150.241.88.13225565TCP
            2024-12-16T13:09:25.930736+010028465261A Network Trojan was detected192.168.2.2340768150.241.88.13225565TCP
            2024-12-16T13:09:28.273429+010028465261A Network Trojan was detected192.168.2.2340770150.241.88.13225565TCP
            2024-12-16T13:09:30.600123+010028465261A Network Trojan was detected192.168.2.2340772150.241.88.13225565TCP
            2024-12-16T13:09:32.984956+010028465261A Network Trojan was detected192.168.2.2340774150.241.88.13225565TCP
            2024-12-16T13:09:35.321711+010028465261A Network Trojan was detected192.168.2.2340776150.241.88.13225565TCP
            2024-12-16T13:09:37.661942+010028465261A Network Trojan was detected192.168.2.2340778150.241.88.13225565TCP
            2024-12-16T13:09:40.009051+010028465261A Network Trojan was detected192.168.2.2340780150.241.88.13225565TCP
            2024-12-16T13:09:42.396763+010028465261A Network Trojan was detected192.168.2.2340782150.241.88.13225565TCP
            2024-12-16T13:09:44.723149+010028465261A Network Trojan was detected192.168.2.2340784150.241.88.13225565TCP
            2024-12-16T13:09:47.051419+010028465261A Network Trojan was detected192.168.2.2340786150.241.88.13225565TCP
            2024-12-16T13:09:49.444987+010028465261A Network Trojan was detected192.168.2.2340788150.241.88.13225565TCP
            2024-12-16T13:09:51.818646+010028465261A Network Trojan was detected192.168.2.2340790150.241.88.13225565TCP
            2024-12-16T13:09:54.164192+010028465261A Network Trojan was detected192.168.2.2340792150.241.88.13225565TCP
            2024-12-16T13:09:56.490071+010028465261A Network Trojan was detected192.168.2.2340794150.241.88.13225565TCP
            2024-12-16T13:09:58.821929+010028465261A Network Trojan was detected192.168.2.2340796150.241.88.13225565TCP
            2024-12-16T13:10:01.209721+010028465261A Network Trojan was detected192.168.2.2340798150.241.88.13225565TCP
            2024-12-16T13:10:03.540102+010028465261A Network Trojan was detected192.168.2.2340800150.241.88.13225565TCP
            2024-12-16T13:10:05.914624+010028465261A Network Trojan was detected192.168.2.2340802150.241.88.13225565TCP
            2024-12-16T13:10:08.258636+010028465261A Network Trojan was detected192.168.2.2340804150.241.88.13225565TCP
            2024-12-16T13:10:11.202089+010028465261A Network Trojan was detected192.168.2.2340806150.241.88.13225565TCP
            2024-12-16T13:10:13.584603+010028465261A Network Trojan was detected192.168.2.2340808150.241.88.13225565TCP
            2024-12-16T13:10:16.004322+010028465261A Network Trojan was detected192.168.2.2340810150.241.88.13225565TCP
            2024-12-16T13:10:18.381606+010028465261A Network Trojan was detected192.168.2.2340812150.241.88.13225565TCP
            2024-12-16T13:10:20.711400+010028465261A Network Trojan was detected192.168.2.2340814150.241.88.13225565TCP
            2024-12-16T13:10:23.087152+010028465261A Network Trojan was detected192.168.2.2340816150.241.88.13225565TCP
            2024-12-16T13:10:25.410316+010028465261A Network Trojan was detected192.168.2.2340818150.241.88.13225565TCP
            2024-12-16T13:10:27.740599+010028465261A Network Trojan was detected192.168.2.2340820150.241.88.13225565TCP
            2024-12-16T13:10:30.082800+010028465261A Network Trojan was detected192.168.2.2340822150.241.88.13225565TCP
            2024-12-16T13:10:32.414294+010028465261A Network Trojan was detected192.168.2.2340824150.241.88.13225565TCP
            2024-12-16T13:10:34.743959+010028465261A Network Trojan was detected192.168.2.2340826150.241.88.13225565TCP
            2024-12-16T13:10:37.086757+010028465261A Network Trojan was detected192.168.2.2340828150.241.88.13225565TCP
            2024-12-16T13:10:39.460161+010028465261A Network Trojan was detected192.168.2.2340830150.241.88.13225565TCP
            2024-12-16T13:10:41.786389+010028465261A Network Trojan was detected192.168.2.2340832150.241.88.13225565TCP
            2024-12-16T13:10:44.114438+010028465261A Network Trojan was detected192.168.2.2340834150.241.88.13225565TCP
            2024-12-16T13:10:46.443282+010028465261A Network Trojan was detected192.168.2.2340836150.241.88.13225565TCP
            2024-12-16T13:10:48.771491+010028465261A Network Trojan was detected192.168.2.2340838150.241.88.13225565TCP
            2024-12-16T13:10:51.102683+010028465261A Network Trojan was detected192.168.2.2340840150.241.88.13225565TCP
            2024-12-16T13:10:53.427842+010028465261A Network Trojan was detected192.168.2.2340842150.241.88.13225565TCP
            2024-12-16T13:10:55.758306+010028465261A Network Trojan was detected192.168.2.2340844150.241.88.13225565TCP
            2024-12-16T13:10:58.087852+010028465261A Network Trojan was detected192.168.2.2340846150.241.88.13225565TCP
            2024-12-16T13:11:00.414039+010028465261A Network Trojan was detected192.168.2.2340848150.241.88.13225565TCP
            2024-12-16T13:11:02.771624+010028465261A Network Trojan was detected192.168.2.2340850150.241.88.13225565TCP
            2024-12-16T13:11:05.150016+010028465261A Network Trojan was detected192.168.2.2340852150.241.88.13225565TCP
            2024-12-16T13:11:07.525163+010028465261A Network Trojan was detected192.168.2.2340854150.241.88.13225565TCP
            2024-12-16T13:11:09.849922+010028465261A Network Trojan was detected192.168.2.2340856150.241.88.13225565TCP
            2024-12-16T13:11:12.182637+010028465261A Network Trojan was detected192.168.2.2340858150.241.88.13225565TCP
            2024-12-16T13:11:14.538622+010028465261A Network Trojan was detected192.168.2.2340860150.241.88.13225565TCP
            2024-12-16T13:11:16.871041+010028465261A Network Trojan was detected192.168.2.2340862150.241.88.13225565TCP
            2024-12-16T13:11:19.257724+010028465261A Network Trojan was detected192.168.2.2340864150.241.88.13225565TCP
            2024-12-16T13:11:21.633848+010028465261A Network Trojan was detected192.168.2.2340866150.241.88.13225565TCP
            2024-12-16T13:11:23.960194+010028465261A Network Trojan was detected192.168.2.2340868150.241.88.13225565TCP
            2024-12-16T13:11:26.290801+010028465261A Network Trojan was detected192.168.2.2340870150.241.88.13225565TCP
            2024-12-16T13:11:28.615583+010028465261A Network Trojan was detected192.168.2.2340872150.241.88.13225565TCP
            2024-12-16T13:11:30.943668+010028465261A Network Trojan was detected192.168.2.2340874150.241.88.13225565TCP
            2024-12-16T13:11:33.320753+010028465261A Network Trojan was detected192.168.2.2340876150.241.88.13225565TCP
            2024-12-16T13:11:35.650754+010028465261A Network Trojan was detected192.168.2.2340878150.241.88.13225565TCP
            2024-12-16T13:11:37.974812+010028465261A Network Trojan was detected192.168.2.2340880150.241.88.13225565TCP
            2024-12-16T13:11:40.302688+010028465261A Network Trojan was detected192.168.2.2340882150.241.88.13225565TCP
            2024-12-16T13:11:42.680017+010028465261A Network Trojan was detected192.168.2.2340884150.241.88.13225565TCP
            2024-12-16T13:11:45.008955+010028465261A Network Trojan was detected192.168.2.2340886150.241.88.13225565TCP
            2024-12-16T13:11:47.337385+010028465261A Network Trojan was detected192.168.2.2340888150.241.88.13225565TCP
            2024-12-16T13:11:49.668720+010028465261A Network Trojan was detected192.168.2.2340890150.241.88.13225565TCP
            2024-12-16T13:11:51.998419+010028465261A Network Trojan was detected192.168.2.2340892150.241.88.13225565TCP
            2024-12-16T13:11:54.355590+010028465261A Network Trojan was detected192.168.2.2340894150.241.88.13225565TCP
            2024-12-16T13:11:56.678643+010028465261A Network Trojan was detected192.168.2.2340896150.241.88.13225565TCP
            2024-12-16T13:11:59.005909+010028465261A Network Trojan was detected192.168.2.2340898150.241.88.13225565TCP
            2024-12-16T13:12:01.337841+010028465261A Network Trojan was detected192.168.2.2340900150.241.88.13225565TCP
            2024-12-16T13:12:03.891693+010028465261A Network Trojan was detected192.168.2.2340902150.241.88.13225565TCP
            2024-12-16T13:12:06.228448+010028465261A Network Trojan was detected192.168.2.2340904150.241.88.13225565TCP
            2024-12-16T13:12:08.553795+010028465261A Network Trojan was detected192.168.2.2340906150.241.88.13225565TCP
            2024-12-16T13:12:10.919357+010028465261A Network Trojan was detected192.168.2.2340908150.241.88.13225565TCP
            2024-12-16T13:12:13.241470+010028465261A Network Trojan was detected192.168.2.2340910150.241.88.13225565TCP
            2024-12-16T13:12:15.648624+010028465261A Network Trojan was detected192.168.2.2340912150.241.88.13225565TCP
            2024-12-16T13:12:17.993880+010028465261A Network Trojan was detected192.168.2.2340914150.241.88.13225565TCP
            2024-12-16T13:12:20.319368+010028465261A Network Trojan was detected192.168.2.2340916150.241.88.13225565TCP
            2024-12-16T13:12:22.651320+010028465261A Network Trojan was detected192.168.2.2340918150.241.88.13225565TCP
            2024-12-16T13:12:25.023903+010028465261A Network Trojan was detected192.168.2.2340920150.241.88.13225565TCP
            2024-12-16T13:12:27.400202+010028465261A Network Trojan was detected192.168.2.2340922150.241.88.13225565TCP
            2024-12-16T13:12:29.774623+010028465261A Network Trojan was detected192.168.2.2340924150.241.88.13225565TCP
            2024-12-16T13:12:32.104882+010028465261A Network Trojan was detected192.168.2.2340926150.241.88.13225565TCP
            2024-12-16T13:12:34.460723+010028465261A Network Trojan was detected192.168.2.2340928150.241.88.13225565TCP
            2024-12-16T13:12:36.788256+010028465261A Network Trojan was detected192.168.2.2340930150.241.88.13225565TCP
            2024-12-16T13:12:39.116866+010028465261A Network Trojan was detected192.168.2.2340932150.241.88.13225565TCP
            2024-12-16T13:12:41.499684+010028465261A Network Trojan was detected192.168.2.2340934150.241.88.13225565TCP
            2024-12-16T13:12:43.837014+010028465261A Network Trojan was detected192.168.2.2340936150.241.88.13225565TCP
            2024-12-16T13:12:46.214814+010028465261A Network Trojan was detected192.168.2.2340938150.241.88.13225565TCP
            2024-12-16T13:12:48.575123+010028465261A Network Trojan was detected192.168.2.2340940150.241.88.13225565TCP
            2024-12-16T13:12:51.062329+010028465261A Network Trojan was detected192.168.2.2340942150.241.88.13225565TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: sh4.elfAvira: detected
            Source: sh4.elfMalware Configuration Extractor: Gafgyt {"C2 url": "150.241.88.132:25565"}
            Source: sh4.elfReversingLabs: Detection: 65%

            Spreading

            barindex
            Source: /tmp/sh4.elf (PID: 6262)Opens: /proc/net/routeJump to behavior

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40772 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40764 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40770 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40792 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40768 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40762 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40800 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40790 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40788 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40804 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40776 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40778 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40808 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40782 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40780 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40822 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40796 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40812 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40818 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40786 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40806 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40832 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40828 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40826 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40798 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40836 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40824 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40830 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40766 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40814 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40784 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40834 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40802 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40774 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40794 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40810 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40816 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40840 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40844 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40848 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40850 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40838 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40852 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40874 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40862 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40880 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40876 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40842 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40868 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40872 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40878 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40896 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40890 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40846 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40892 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40884 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40856 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40854 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40870 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40860 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40864 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40900 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40882 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40894 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40858 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40920 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40906 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40888 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40922 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40934 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40902 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40910 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40918 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40928 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40904 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40932 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40940 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40908 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40866 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40936 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40942 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40898 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40926 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40916 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40930 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40938 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40924 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40914 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40912 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40820 -> 150.241.88.132:25565
            Source: Network trafficSuricata IDS: 2846526 - Severity 1 - ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin : 192.168.2.23:40886 -> 150.241.88.132:25565
            Source: global trafficTCP traffic: 192.168.2.23:40762 -> 150.241.88.132:25565
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownTCP traffic detected without corresponding DNS query: 150.241.88.132
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

            System Summary

            barindex
            Source: sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6262.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6264.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: sh4.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: Process Memory Space: sh4.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6262.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6264.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: sh4.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: Process Memory Space: sh4.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: classification engineClassification label: mal100.spre.troj.linELF@0/0@0/0
            Source: sh4.elfELF static info symbol of initial sample: /home/firmware/build/temp-sh4/gcc-core/gcc/config/sh/lib1funcs.asm
            Source: sh4.elfELF static info symbol of initial sample: /home/firmware/build/temp-sh4/gcc-core/gcc/config/sh/lib1funcs.asm
            Source: sh4.elfELF static info symbol of initial sample: libc/string/sh/sh4/memcpy.S
            Source: sh4.elfELF static info symbol of initial sample: libc/sysdeps/linux/sh/crt1.S
            Source: sh4.elfELF static info symbol of initial sample: libc/sysdeps/linux/sh/crti.S
            Source: sh4.elfELF static info symbol of initial sample: libc/sysdeps/linux/sh/crtn.S
            Source: /usr/bin/dash (PID: 6225)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.25mzlEEvpZ /tmp/tmp.DDq2YkcMbt /tmp/tmp.scdstBQjf3Jump to behavior
            Source: /usr/bin/dash (PID: 6234)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.25mzlEEvpZ /tmp/tmp.DDq2YkcMbt /tmp/tmp.scdstBQjf3Jump to behavior
            Source: /tmp/sh4.elf (PID: 6262)Queries kernel information via 'uname': Jump to behavior
            Source: sh4.elf, 6262.1.00007ffd8f49a000.00007ffd8f4bb000.rw-.sdmp, sh4.elf, 6264.1.00007ffd8f49a000.00007ffd8f4bb000.rw-.sdmpBinary or memory string: Mxs)x86_64/usr/bin/qemu-sh4/tmp/sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sh4.elf
            Source: sh4.elf, 6262.1.00007ffd8f49a000.00007ffd8f4bb000.rw-.sdmp, sh4.elf, 6264.1.00007ffd8f49a000.00007ffd8f4bb000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
            Source: sh4.elf, 6262.1.0000557b81d94000.0000557b81df7000.rw-.sdmp, sh4.elf, 6264.1.0000557b81d94000.0000557b81df7000.rw-.sdmpBinary or memory string: {U5!/etc/qemu-binfmt/sh4
            Source: sh4.elf, 6262.1.0000557b81d94000.0000557b81df7000.rw-.sdmp, sh4.elf, 6264.1.0000557b81d94000.0000557b81df7000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: sh4.elf, type: SAMPLE
            Source: Yara matchFile source: sh4.elf, type: SAMPLE
            Source: Yara matchFile source: 6262.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6264.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: sh4.elf PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: sh4.elf PID: 6264, type: MEMORYSTR
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.71 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: sh4.elf, type: SAMPLE
            Source: Yara matchFile source: sh4.elf, type: SAMPLE
            Source: Yara matchFile source: 6262.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6264.1.00007f70ec400000.00007f70ec410000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: sh4.elf PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: sh4.elf PID: 6264, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
            File Deletion
            OS Credential Dumping11
            Security Software Discovery
            Remote ServicesData from Local System1
            Data Obfuscation
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
            Remote System Discovery
            Remote Desktop ProtocolData from Removable Media1
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
            Non-Standard Port
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
            Application Layer Protocol
            Traffic DuplicationData Destruction
            {"C2 url": "150.241.88.132:25565"}
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1575989 Sample: sh4.elf Startdate: 16/12/2024 Architecture: LINUX Score: 100 21 150.241.88.132, 25565, 40762, 40764 TECNALIAES Spain 2->21 23 109.202.202.202, 80 INIT7CH Switzerland 2->23 25 2 other IPs or domains 2->25 27 Suricata IDS alerts for network traffic 2->27 29 Found malware configuration 2->29 31 Malicious sample detected (through community Yara rule) 2->31 33 5 other signatures 2->33 8 dash rm sh4.elf 2->8         started        11 dash rm 2->11         started        13 dash cut 2->13         started        15 7 other processes 2->15 signatures3 process4 signatures5 35 Opens /proc/net/* files useful for finding connected devices and routers 8->35 17 sh4.elf 8->17         started        process6 process7 19 sh4.elf 17->19         started       
            SourceDetectionScannerLabelLink
            sh4.elf66%ReversingLabsLinux.Exploit.Mirai
            sh4.elf100%AviraEXP/ELF.Mirai.Z.A
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            No contacted domains info
            NameMaliciousAntivirus DetectionReputation
            150.241.88.132:25565true
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              109.202.202.202
              unknownSwitzerland
              13030INIT7CHfalse
              91.189.91.43
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              91.189.91.42
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              150.241.88.132
              unknownSpain
              207714TECNALIAEStrue
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
              91.189.91.43uTfdXFqWcq.elfGet hashmaliciousConnectBackBrowse
                V8iybGX0WW.elfGet hashmaliciousUnknownBrowse
                  boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                    boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                      main_arm7.elfGet hashmaliciousMiraiBrowse
                        main_mips.elfGet hashmaliciousMiraiBrowse
                          darm7.elfGet hashmaliciousUnknownBrowse
                            main_x86_64.elfGet hashmaliciousMiraiBrowse
                              main_arm5.elfGet hashmaliciousMiraiBrowse
                                main_mpsl.elfGet hashmaliciousMiraiBrowse
                                  91.189.91.42uTfdXFqWcq.elfGet hashmaliciousConnectBackBrowse
                                    V8iybGX0WW.elfGet hashmaliciousUnknownBrowse
                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                        boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                          main_arm7.elfGet hashmaliciousMiraiBrowse
                                            main_mips.elfGet hashmaliciousMiraiBrowse
                                              darm7.elfGet hashmaliciousUnknownBrowse
                                                main_x86_64.elfGet hashmaliciousMiraiBrowse
                                                  main_mips.elfGet hashmaliciousMiraiBrowse
                                                    main_arm5.elfGet hashmaliciousMiraiBrowse
                                                      150.241.88.132powerpc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                          armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                            mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                              armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                  armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                    armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      No context
                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                      CANONICAL-ASGBuTfdXFqWcq.elfGet hashmaliciousConnectBackBrowse
                                                                      • 91.189.91.42
                                                                      V8iybGX0WW.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_arm7.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      darm7.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      main_x86_64.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      CANONICAL-ASGBuTfdXFqWcq.elfGet hashmaliciousConnectBackBrowse
                                                                      • 91.189.91.42
                                                                      V8iybGX0WW.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_arm7.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      darm7.elfGet hashmaliciousUnknownBrowse
                                                                      • 91.189.91.42
                                                                      main_x86_64.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      main_arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 91.189.91.42
                                                                      TECNALIAESx86_64.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.95.250
                                                                      powerpc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.88.132
                                                                      armv7l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.95.250
                                                                      m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.88.132
                                                                      armv6l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.88.132
                                                                      mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.88.132
                                                                      armv4l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.88.132
                                                                      i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.88.132
                                                                      armv5l.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                                      • 150.241.88.132
                                                                      file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                      • 150.241.91.218
                                                                      INIT7CHuTfdXFqWcq.elfGet hashmaliciousConnectBackBrowse
                                                                      • 109.202.202.202
                                                                      V8iybGX0WW.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      main_arm7.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      main_mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      darm7.elfGet hashmaliciousUnknownBrowse
                                                                      • 109.202.202.202
                                                                      main_x86_64.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      main_mips.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      main_arm5.elfGet hashmaliciousMiraiBrowse
                                                                      • 109.202.202.202
                                                                      No context
                                                                      No context
                                                                      No created / dropped files found
                                                                      File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, not stripped
                                                                      Entropy (8bit):6.618373560893373
                                                                      TrID:
                                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                      File name:sh4.elf
                                                                      File size:88'733 bytes
                                                                      MD5:866c52bc44c007685c49f5f7c51e05ca
                                                                      SHA1:83bb15de9ff6d7501897689e97907fe80f329604
                                                                      SHA256:3c0c87bbc1a908ee2d698bf59722fc050b29aa5dcc9312a7c33c04910ad2f067
                                                                      SHA512:2cd86d31968a9cb542d66a192b6c28a4644c8c0be83a5d04d10ed9eabfdc0a18853bc76b7f1efd3dabf6ac269a35887a867a14d73f27de8d84b612069bd61d8d
                                                                      SSDEEP:1536:ClNtAyOXSU3rUk954CKmg0KfjyJCSujEaX9LmkxVqOEeofzee:gbOXSU3rUkmmbJ594LmkxVqODofzee
                                                                      TLSH:98832B43E9A19FB7C0866AB565AB5E300B13E9912B4F1A4A313CA7F4434F4CD790EF64
                                                                      File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................A...A......g..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                                                      ELF header

                                                                      Class:ELF32
                                                                      Data:2's complement, little endian
                                                                      Version:1 (current)
                                                                      Machine:<unknown>
                                                                      Version Number:0x1
                                                                      Type:EXEC (Executable file)
                                                                      OS/ABI:UNIX - System V
                                                                      ABI Version:0
                                                                      Entry Point Address:0x4001a0
                                                                      Flags:0x9
                                                                      ELF Header Size:52
                                                                      Program Header Offset:52
                                                                      Program Header Size:32
                                                                      Number of Program Headers:3
                                                                      Section Header Offset:69296
                                                                      Section Header Size:40
                                                                      Number of Section Headers:15
                                                                      Header String Table Index:12
                                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                      NULL0x00x00x00x00x0000
                                                                      .initPROGBITS0x4000940x940x300x00x6AX004
                                                                      .textPROGBITS0x4000e00xe00xd5200x00x6AX0032
                                                                      .finiPROGBITS0x40d6000xd6000x240x00x6AX004
                                                                      .rodataPROGBITS0x40d6240xd6240x26700x00x2A004
                                                                      .eh_framePROGBITS0x40fc940xfc940x40x00x2A004
                                                                      .ctorsPROGBITS0x4100000x100000x80x00x3WA004
                                                                      .dtorsPROGBITS0x4100080x100080x80x00x3WA004
                                                                      .jcrPROGBITS0x4100100x100100x40x00x3WA004
                                                                      .dataPROGBITS0x4100140x100140x3980x00x3WA004
                                                                      .bssNOBITS0x4103ac0x103ac0x635c0x00x3WA004
                                                                      .commentPROGBITS0x00x103ac0xa9e0x00x0001
                                                                      .shstrtabSTRTAB0x00x10e4a0x660x00x0001
                                                                      .symtabSYMTAB0x00x111080x29e00x100x0142494
                                                                      .strtabSTRTAB0x00x13ae80x1fb50x00x0001
                                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                      LOAD0x00x4000000x4000000xfc980xfc986.92020x5R E0x10000.init .text .fini .rodata .eh_frame
                                                                      LOAD0x100000x4100000x4100000x3ac0x67082.74920x6RW 0x10000.ctors .dtors .jcr .data .bss
                                                                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                      NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                      .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                      .symtab0x4000940SECTION<unknown>DEFAULT1
                                                                      .symtab0x4000e00SECTION<unknown>DEFAULT2
                                                                      .symtab0x40d6000SECTION<unknown>DEFAULT3
                                                                      .symtab0x40d6240SECTION<unknown>DEFAULT4
                                                                      .symtab0x40fc940SECTION<unknown>DEFAULT5
                                                                      .symtab0x4100000SECTION<unknown>DEFAULT6
                                                                      .symtab0x4100080SECTION<unknown>DEFAULT7
                                                                      .symtab0x4100100SECTION<unknown>DEFAULT8
                                                                      .symtab0x4100140SECTION<unknown>DEFAULT9
                                                                      .symtab0x4103ac0SECTION<unknown>DEFAULT10
                                                                      .symtab0x00SECTION<unknown>DEFAULT11
                                                                      .symtab0x00SECTION<unknown>DEFAULT12
                                                                      .symtab0x00SECTION<unknown>DEFAULT13
                                                                      .symtab0x00SECTION<unknown>DEFAULT14
                                                                      /home/firmware/build/temp-sh4/gcc-core/gcc/config/sh/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      /home/firmware/build/temp-sh4/gcc-core/gcc/config/sh/lib1funcs.asm.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      L1.symtab0x406b1c0NOTYPE<unknown>DEFAULT2
                                                                      L_abort.symtab0x4001d00NOTYPE<unknown>DEFAULT2
                                                                      L_fini.symtab0x4001c80NOTYPE<unknown>DEFAULT2
                                                                      L_init.symtab0x4001c40NOTYPE<unknown>DEFAULT2
                                                                      L_main.symtab0x4001c00NOTYPE<unknown>DEFAULT2
                                                                      L_uClibc_main.symtab0x4001cc0NOTYPE<unknown>DEFAULT2
                                                                      Q.symtab0x4103e016384OBJECT<unknown>DEFAULT10
                                                                      Sakura_Bot.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      SendSTD.symtab0x403020344FUNC<unknown>DEFAULT2
                                                                      SendSTDHEX.symtab0x4026b0372FUNC<unknown>DEFAULT2
                                                                      SendSTD_HEX.symtab0x4032e0420FUNC<unknown>DEFAULT2
                                                                      SendUDP.symtab0x401cf41040FUNC<unknown>DEFAULT2
                                                                      _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                      _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __CTOR_END__.symtab0x4100040OBJECT<unknown>DEFAULT6
                                                                      __CTOR_LIST__.symtab0x4100000OBJECT<unknown>DEFAULT6
                                                                      __C_ctype_b.symtab0x41004c4OBJECT<unknown>DEFAULT9
                                                                      __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __C_ctype_b_data.symtab0x40e63c768OBJECT<unknown>DEFAULT4
                                                                      __C_ctype_tolower.symtab0x4103a44OBJECT<unknown>DEFAULT9
                                                                      __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __C_ctype_tolower_data.symtab0x40ed22768OBJECT<unknown>DEFAULT4
                                                                      __C_ctype_toupper.symtab0x4100544OBJECT<unknown>DEFAULT9
                                                                      __C_ctype_toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __C_ctype_toupper_data.symtab0x40e93c768OBJECT<unknown>DEFAULT4
                                                                      __DTOR_END__.symtab0x41000c0OBJECT<unknown>DEFAULT7
                                                                      __DTOR_LIST__.symtab0x4100080OBJECT<unknown>DEFAULT7
                                                                      __EH_FRAME_BEGIN__.symtab0x40fc940OBJECT<unknown>DEFAULT5
                                                                      __FRAME_END__.symtab0x40fc940OBJECT<unknown>DEFAULT5
                                                                      __GI___C_ctype_b.symtab0x41004c4OBJECT<unknown>HIDDEN9
                                                                      __GI___C_ctype_b_data.symtab0x40e63c768OBJECT<unknown>HIDDEN4
                                                                      __GI___C_ctype_tolower.symtab0x4103a44OBJECT<unknown>HIDDEN9
                                                                      __GI___C_ctype_tolower_data.symtab0x40ed22768OBJECT<unknown>HIDDEN4
                                                                      __GI___C_ctype_toupper.symtab0x4100544OBJECT<unknown>HIDDEN9
                                                                      __GI___C_ctype_toupper_data.symtab0x40e93c768OBJECT<unknown>HIDDEN4
                                                                      __GI___ctype_b.symtab0x4100504OBJECT<unknown>HIDDEN9
                                                                      __GI___ctype_tolower.symtab0x4103a84OBJECT<unknown>HIDDEN9
                                                                      __GI___ctype_toupper.symtab0x4100584OBJECT<unknown>HIDDEN9
                                                                      __GI___errno_location.symtab0x4070a020FUNC<unknown>HIDDEN2
                                                                      __GI___fgetc_unlocked.symtab0x40c378216FUNC<unknown>HIDDEN2
                                                                      __GI___glibc_strerror_r.symtab0x40c5d832FUNC<unknown>HIDDEN2
                                                                      __GI___h_errno_location.symtab0x408eec20FUNC<unknown>HIDDEN2
                                                                      __GI___libc_fcntl.symtab0x406b24172FUNC<unknown>HIDDEN2
                                                                      __GI___libc_fcntl64.symtab0x406bd0152FUNC<unknown>HIDDEN2
                                                                      __GI___libc_open.symtab0x406e7c160FUNC<unknown>HIDDEN2
                                                                      __GI___uClibc_fini.symtab0x4089c8104FUNC<unknown>HIDDEN2
                                                                      __GI___uClibc_init.symtab0x408a9480FUNC<unknown>HIDDEN2
                                                                      __GI___xpg_strerror_r.symtab0x40c5f8200FUNC<unknown>HIDDEN2
                                                                      __GI__exit.symtab0x406c6848FUNC<unknown>HIDDEN2
                                                                      __GI_abort.symtab0x4080c0244FUNC<unknown>HIDDEN2
                                                                      __GI_atoi.symtab0x40862424FUNC<unknown>HIDDEN2
                                                                      __GI_atol.symtab0x40862424FUNC<unknown>HIDDEN2
                                                                      __GI_chdir.symtab0x406cd056FUNC<unknown>HIDDEN2
                                                                      __GI_close.symtab0x406d0856FUNC<unknown>HIDDEN2
                                                                      __GI_connect.symtab0x407af040FUNC<unknown>HIDDEN2
                                                                      __GI_errno.symtab0x41460c4OBJECT<unknown>HIDDEN10
                                                                      __GI_exit.symtab0x408794112FUNC<unknown>HIDDEN2
                                                                      __GI_fclose.symtab0x40a078272FUNC<unknown>HIDDEN2
                                                                      __GI_fcntl.symtab0x406b24172FUNC<unknown>HIDDEN2
                                                                      __GI_fcntl64.symtab0x406bd0152FUNC<unknown>HIDDEN2
                                                                      __GI_fflush_unlocked.symtab0x40a660320FUNC<unknown>HIDDEN2
                                                                      __GI_fgetc_unlocked.symtab0x40c378216FUNC<unknown>HIDDEN2
                                                                      __GI_fgets.symtab0x40a508120FUNC<unknown>HIDDEN2
                                                                      __GI_fgets_unlocked.symtab0x40a7a0128FUNC<unknown>HIDDEN2
                                                                      __GI_fopen.symtab0x40a18824FUNC<unknown>HIDDEN2
                                                                      __GI_fork.symtab0x406d4056FUNC<unknown>HIDDEN2
                                                                      __GI_fputs_unlocked.symtab0x40c45068FUNC<unknown>HIDDEN2
                                                                      __GI_fseek.symtab0x40d35428FUNC<unknown>HIDDEN2
                                                                      __GI_fseeko64.symtab0x40d370232FUNC<unknown>HIDDEN2
                                                                      __GI_fwrite_unlocked.symtab0x40c494156FUNC<unknown>HIDDEN2
                                                                      __GI_getc_unlocked.symtab0x40c378216FUNC<unknown>HIDDEN2
                                                                      __GI_getegid.symtab0x408d4856FUNC<unknown>HIDDEN2
                                                                      __GI_geteuid.symtab0x408d8056FUNC<unknown>HIDDEN2
                                                                      __GI_getgid.symtab0x408db856FUNC<unknown>HIDDEN2
                                                                      __GI_gethostbyname.symtab0x4077fc72FUNC<unknown>HIDDEN2
                                                                      __GI_gethostbyname_r.symtab0x407844684FUNC<unknown>HIDDEN2
                                                                      __GI_getpid.symtab0x406d7856FUNC<unknown>HIDDEN2
                                                                      __GI_getsockname.symtab0x407b1840FUNC<unknown>HIDDEN2
                                                                      __GI_getuid.symtab0x408df056FUNC<unknown>HIDDEN2
                                                                      __GI_h_errno.symtab0x4146104OBJECT<unknown>HIDDEN10
                                                                      __GI_inet_addr.symtab0x4077d044FUNC<unknown>HIDDEN2
                                                                      __GI_inet_aton.symtab0x409508204FUNC<unknown>HIDDEN2
                                                                      __GI_inet_ntoa.symtab0x4077b824FUNC<unknown>HIDDEN2
                                                                      __GI_inet_ntoa_r.symtab0x407740120FUNC<unknown>HIDDEN2
                                                                      __GI_inet_ntop.symtab0x40add8492FUNC<unknown>HIDDEN2
                                                                      __GI_inet_pton.symtab0x40ab04408FUNC<unknown>HIDDEN2
                                                                      __GI_initstate_r.symtab0x408574176FUNC<unknown>HIDDEN2
                                                                      __GI_ioctl.symtab0x406db0148FUNC<unknown>HIDDEN2
                                                                      __GI_isatty.symtab0x40a9d036FUNC<unknown>HIDDEN2
                                                                      __GI_kill.symtab0x406e4456FUNC<unknown>HIDDEN2
                                                                      __GI_lseek64.symtab0x40d54096FUNC<unknown>HIDDEN2
                                                                      __GI_memchr.symtab0x40d1bc204FUNC<unknown>HIDDEN2
                                                                      __GI_memcpy.symtab0x407140636FUNC<unknown>HIDDEN2
                                                                      __GI_memmove.symtab0x409004978FUNC<unknown>HIDDEN2
                                                                      __GI_mempcpy.symtab0x40c53036FUNC<unknown>HIDDEN2
                                                                      __GI_memrchr.symtab0x40d288204FUNC<unknown>HIDDEN2
                                                                      __GI_memset.symtab0x4073c0124FUNC<unknown>HIDDEN2
                                                                      __GI_nanosleep.symtab0x408e2856FUNC<unknown>HIDDEN2
                                                                      __GI_open.symtab0x406e7c160FUNC<unknown>HIDDEN2
                                                                      __GI_poll.symtab0x40a04056FUNC<unknown>HIDDEN2
                                                                      __GI_raise.symtab0x409ea440FUNC<unknown>HIDDEN2
                                                                      __GI_random.symtab0x4081c8100FUNC<unknown>HIDDEN2
                                                                      __GI_random_r.symtab0x408448104FUNC<unknown>HIDDEN2
                                                                      __GI_rawmemchr.symtab0x40a820152FUNC<unknown>HIDDEN2
                                                                      __GI_read.symtab0x406f3456FUNC<unknown>HIDDEN2
                                                                      __GI_recv.symtab0x407b6c40FUNC<unknown>HIDDEN2
                                                                      __GI_sbrk.symtab0x408cb888FUNC<unknown>HIDDEN2
                                                                      __GI_select.symtab0x406f6c52FUNC<unknown>HIDDEN2
                                                                      __GI_send.symtab0x407b9440FUNC<unknown>HIDDEN2
                                                                      __GI_sendto.symtab0x407bbc48FUNC<unknown>HIDDEN2
                                                                      __GI_setsid.symtab0x406fa056FUNC<unknown>HIDDEN2
                                                                      __GI_setsockopt.symtab0x407bec44FUNC<unknown>HIDDEN2
                                                                      __GI_setstate_r.symtab0x408370216FUNC<unknown>HIDDEN2
                                                                      __GI_sigaction.symtab0x409ecc160FUNC<unknown>HIDDEN2
                                                                      __GI_signal.symtab0x407c40184FUNC<unknown>HIDDEN2
                                                                      __GI_sigprocmask.symtab0x408e6084FUNC<unknown>HIDDEN2
                                                                      __GI_sleep.symtab0x408804376FUNC<unknown>HIDDEN2
                                                                      __GI_socket.symtab0x407c1840FUNC<unknown>HIDDEN2
                                                                      __GI_sprintf.symtab0x40b554132FUNC<unknown>HIDDEN2
                                                                      __GI_srandom_r.symtab0x4084b0196FUNC<unknown>HIDDEN2
                                                                      __GI_strcasecmp.symtab0x40c6c064FUNC<unknown>HIDDEN2
                                                                      __GI_strchr.symtab0x40743c192FUNC<unknown>HIDDEN2
                                                                      __GI_strcmp.symtab0x4074fc34FUNC<unknown>HIDDEN2
                                                                      __GI_strcoll.symtab0x4074fc34FUNC<unknown>HIDDEN2
                                                                      __GI_strcpy.symtab0x40751e30FUNC<unknown>HIDDEN2
                                                                      __GI_strdup.symtab0x40a98476FUNC<unknown>HIDDEN2
                                                                      __GI_strlen.symtab0x40753c136FUNC<unknown>HIDDEN2
                                                                      __GI_strncat.symtab0x40a8b8154FUNC<unknown>HIDDEN2
                                                                      __GI_strncpy.symtab0x4093d8142FUNC<unknown>HIDDEN2
                                                                      __GI_strnlen.symtab0x40c554132FUNC<unknown>HIDDEN2
                                                                      __GI_strpbrk.symtab0x4094e040FUNC<unknown>HIDDEN2
                                                                      __GI_strspn.symtab0x40a95248FUNC<unknown>HIDDEN2
                                                                      __GI_strstr.symtab0x4075c4192FUNC<unknown>HIDDEN2
                                                                      __GI_strtok.symtab0x40769c24FUNC<unknown>HIDDEN2
                                                                      __GI_strtok_r.symtab0x409468120FUNC<unknown>HIDDEN2
                                                                      __GI_strtol.symtab0x40863c20FUNC<unknown>HIDDEN2
                                                                      __GI_tcgetattr.symtab0x40a9f4116FUNC<unknown>HIDDEN2
                                                                      __GI_time.symtab0x406fd856FUNC<unknown>HIDDEN2
                                                                      __GI_tolower.symtab0x40b52c40FUNC<unknown>HIDDEN2
                                                                      __GI_toupper.symtab0x40707840FUNC<unknown>HIDDEN2
                                                                      __GI_vsnprintf.symtab0x40b5d8168FUNC<unknown>HIDDEN2
                                                                      __GI_wait4.symtab0x408eb456FUNC<unknown>HIDDEN2
                                                                      __GI_waitpid.symtab0x40701020FUNC<unknown>HIDDEN2
                                                                      __GI_wcrtomb.symtab0x40c8b468FUNC<unknown>HIDDEN2
                                                                      __GI_wcsnrtombs.symtab0x40c918112FUNC<unknown>HIDDEN2
                                                                      __GI_wcsrtombs.symtab0x40c8f832FUNC<unknown>HIDDEN2
                                                                      __GI_write.symtab0x40702456FUNC<unknown>HIDDEN2
                                                                      __JCR_END__.symtab0x4100100OBJECT<unknown>DEFAULT8
                                                                      __JCR_LIST__.symtab0x4100100OBJECT<unknown>DEFAULT8
                                                                      __app_fini.symtab0x4146004OBJECT<unknown>HIDDEN10
                                                                      __atexit_lock.symtab0x41023024OBJECT<unknown>DEFAULT9
                                                                      __bsd_signal.symtab0x407c40184FUNC<unknown>HIDDEN2
                                                                      __bss_start.symtab0x4103ac0NOTYPE<unknown>DEFAULTSHN_ABS
                                                                      __check_one_fd.symtab0x408a4a74FUNC<unknown>DEFAULT2
                                                                      __ctype_b.symtab0x4100504OBJECT<unknown>DEFAULT9
                                                                      __ctype_tolower.symtab0x4103a84OBJECT<unknown>DEFAULT9
                                                                      __ctype_toupper.symtab0x4100584OBJECT<unknown>DEFAULT9
                                                                      __curbrk.symtab0x4146304OBJECT<unknown>HIDDEN10
                                                                      __data_start.symtab0x4100140NOTYPE<unknown>DEFAULT9
                                                                      __decode_answer.symtab0x40b1a0228FUNC<unknown>HIDDEN2
                                                                      __decode_dotted.symtab0x40c7ac200FUNC<unknown>HIDDEN2
                                                                      __decode_header.symtab0x40b084148FUNC<unknown>HIDDEN2
                                                                      __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                      __dns_lookup.symtab0x4095d41604FUNC<unknown>HIDDEN2
                                                                      __do_global_ctors_aux.symtab0x40d5c00FUNC<unknown>DEFAULT2
                                                                      __do_global_dtors_aux.symtab0x4000e00FUNC<unknown>DEFAULT2
                                                                      __dso_handle.symtab0x4100140OBJECT<unknown>HIDDEN9
                                                                      __encode_dotted.symtab0x40c700172FUNC<unknown>HIDDEN2
                                                                      __encode_header.symtab0x40afc4192FUNC<unknown>HIDDEN2
                                                                      __encode_question.symtab0x40b118104FUNC<unknown>HIDDEN2
                                                                      __environ.symtab0x4145f84OBJECT<unknown>DEFAULT10
                                                                      __errno_location.symtab0x4070a020FUNC<unknown>DEFAULT2
                                                                      __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __exit_cleanup.symtab0x4145f04OBJECT<unknown>HIDDEN10
                                                                      __fgetc_unlocked.symtab0x40c378216FUNC<unknown>DEFAULT2
                                                                      __fini_array_end.symtab0x4100000NOTYPE<unknown>HIDDENSHN_ABS
                                                                      __fini_array_start.symtab0x4100000NOTYPE<unknown>HIDDENSHN_ABS
                                                                      __get_hosts_byname_r.symtab0x409e7052FUNC<unknown>HIDDEN2
                                                                      __glibc_strerror_r.symtab0x40c5d832FUNC<unknown>DEFAULT2
                                                                      __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __h_errno_location.symtab0x408eec20FUNC<unknown>DEFAULT2
                                                                      __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __heap_alloc.symtab0x407f7098FUNC<unknown>DEFAULT2
                                                                      __heap_free.symtab0x408010176FUNC<unknown>DEFAULT2
                                                                      __heap_link_free_area.symtab0x407fd434FUNC<unknown>DEFAULT2
                                                                      __heap_link_free_area_after.symtab0x407ff626FUNC<unknown>DEFAULT2
                                                                      __init_array_end.symtab0x4100000NOTYPE<unknown>HIDDENSHN_ABS
                                                                      __init_array_start.symtab0x4100000NOTYPE<unknown>HIDDENSHN_ABS
                                                                      __init_brk.symtab0x409fc468FUNC<unknown>HIDDEN2
                                                                      __init_brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __length_dotted.symtab0x40c87464FUNC<unknown>HIDDEN2
                                                                      __length_question.symtab0x40b18032FUNC<unknown>HIDDEN2
                                                                      __libc_close.symtab0x406d0856FUNC<unknown>DEFAULT2
                                                                      __libc_connect.symtab0x407af040FUNC<unknown>DEFAULT2
                                                                      __libc_creat.symtab0x406f1c24FUNC<unknown>DEFAULT2
                                                                      __libc_fcntl.symtab0x406b24172FUNC<unknown>DEFAULT2
                                                                      __libc_fcntl64.symtab0x406bd0152FUNC<unknown>DEFAULT2
                                                                      __libc_fork.symtab0x406d4056FUNC<unknown>DEFAULT2
                                                                      __libc_getpid.symtab0x406d7856FUNC<unknown>DEFAULT2
                                                                      __libc_lseek64.symtab0x40d54096FUNC<unknown>DEFAULT2
                                                                      __libc_nanosleep.symtab0x408e2856FUNC<unknown>DEFAULT2
                                                                      __libc_open.symtab0x406e7c160FUNC<unknown>DEFAULT2
                                                                      __libc_poll.symtab0x40a04056FUNC<unknown>DEFAULT2
                                                                      __libc_read.symtab0x406f3456FUNC<unknown>DEFAULT2
                                                                      __libc_recv.symtab0x407b6c40FUNC<unknown>DEFAULT2
                                                                      __libc_select.symtab0x406f6c52FUNC<unknown>DEFAULT2
                                                                      __libc_send.symtab0x407b9440FUNC<unknown>DEFAULT2
                                                                      __libc_sendto.symtab0x407bbc48FUNC<unknown>DEFAULT2
                                                                      __libc_sigaction.symtab0x409ecc160FUNC<unknown>DEFAULT2
                                                                      __libc_stack_end.symtab0x4145f44OBJECT<unknown>DEFAULT10
                                                                      __libc_waitpid.symtab0x40701020FUNC<unknown>DEFAULT2
                                                                      __libc_write.symtab0x40702456FUNC<unknown>DEFAULT2
                                                                      __malloc_heap.symtab0x41005c4OBJECT<unknown>DEFAULT9
                                                                      __malloc_heap_lock.symtab0x4145d424OBJECT<unknown>DEFAULT10
                                                                      __malloc_sbrk_lock.symtab0x4166c424OBJECT<unknown>DEFAULT10
                                                                      __nameserver.symtab0x4166ec12OBJECT<unknown>HIDDEN10
                                                                      __nameservers.symtab0x4166f84OBJECT<unknown>HIDDEN10
                                                                      __open_etc_hosts.symtab0x40b28468FUNC<unknown>HIDDEN2
                                                                      __open_nameservers.symtab0x409c18600FUNC<unknown>HIDDEN2
                                                                      __pagesize.symtab0x4145fc4OBJECT<unknown>DEFAULT10
                                                                      __preinit_array_end.symtab0x4100000NOTYPE<unknown>HIDDENSHN_ABS
                                                                      __preinit_array_start.symtab0x4100000NOTYPE<unknown>HIDDENSHN_ABS
                                                                      __pthread_initialize_minimal.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                      __pthread_mutex_init.symtab0x408a3014FUNC<unknown>DEFAULT2
                                                                      __pthread_mutex_lock.symtab0x408a3014FUNC<unknown>DEFAULT2
                                                                      __pthread_mutex_trylock.symtab0x408a3014FUNC<unknown>DEFAULT2
                                                                      __pthread_mutex_unlock.symtab0x408a3014FUNC<unknown>DEFAULT2
                                                                      __pthread_return_0.symtab0x408a3014FUNC<unknown>DEFAULT2
                                                                      __pthread_return_void.symtab0x408a3e12FUNC<unknown>DEFAULT2
                                                                      __raise.symtab0x409ea440FUNC<unknown>HIDDEN2
                                                                      __read_etc_hosts_r.symtab0x40b2c8612FUNC<unknown>HIDDEN2
                                                                      __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                      __resolv_lock.symtab0x41025024OBJECT<unknown>DEFAULT9
                                                                      __rtld_fini.symtab0x4146044OBJECT<unknown>HIDDEN10
                                                                      __sdivsi3_i4.symtab0x40d5a014FUNC<unknown>HIDDEN2
                                                                      __searchdomain.symtab0x4166dc16OBJECT<unknown>HIDDEN10
                                                                      __searchdomains.symtab0x4166fc4OBJECT<unknown>HIDDEN10
                                                                      __sigaddset.symtab0x407d2440FUNC<unknown>DEFAULT2
                                                                      __sigdelset.symtab0x407d4c42FUNC<unknown>DEFAULT2
                                                                      __sigismember.symtab0x407cf844FUNC<unknown>DEFAULT2
                                                                      __socketcall.symtab0x408d1056FUNC<unknown>HIDDEN2
                                                                      __socketcall.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __stdin.symtab0x4102744OBJECT<unknown>DEFAULT9
                                                                      __stdio_READ.symtab0x40c98880FUNC<unknown>HIDDEN2
                                                                      __stdio_WRITE.symtab0x40b680148FUNC<unknown>HIDDEN2
                                                                      __stdio_adjust_position.symtab0x40d458180FUNC<unknown>HIDDEN2
                                                                      __stdio_fwrite.symtab0x40c9d8264FUNC<unknown>HIDDEN2
                                                                      __stdio_init_mutex.symtab0x40a42428FUNC<unknown>HIDDEN2
                                                                      __stdio_mutex_initializer.3812.symtab0x40ecc024OBJECT<unknown>DEFAULT4
                                                                      __stdio_rfill.symtab0x40cae048FUNC<unknown>HIDDEN2
                                                                      __stdio_seek.symtab0x40d50c52FUNC<unknown>HIDDEN2
                                                                      __stdio_trans2r_o.symtab0x40cb10120FUNC<unknown>HIDDEN2
                                                                      __stdio_trans2w_o.symtab0x40cb88176FUNC<unknown>HIDDEN2
                                                                      __stdio_wcommit.symtab0x40a4d452FUNC<unknown>HIDDEN2
                                                                      __stdout.symtab0x4102784OBJECT<unknown>DEFAULT9
                                                                      __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __syscall_fcntl64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __syscall_rt_sigaction.symtab0x40a00856FUNC<unknown>HIDDEN2
                                                                      __syscall_rt_sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __uClibc_fini.symtab0x4089c8104FUNC<unknown>DEFAULT2
                                                                      __uClibc_init.symtab0x408a9480FUNC<unknown>DEFAULT2
                                                                      __uClibc_main.symtab0x408ae4468FUNC<unknown>DEFAULT2
                                                                      __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      __uclibc_progname.symtab0x4102484OBJECT<unknown>HIDDEN9
                                                                      __udivsi3_i4.symtab0x406af448FUNC<unknown>HIDDEN2
                                                                      __xpg_strerror_r.symtab0x40c5f8200FUNC<unknown>DEFAULT2
                                                                      __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _brk.symtab0x409f8c56FUNC<unknown>HIDDEN2
                                                                      _charpad.symtab0x40b71480FUNC<unknown>DEFAULT2
                                                                      _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _dl_aux_init.symtab0x409f6c32FUNC<unknown>DEFAULT2
                                                                      _dl_phdr.symtab0x4167004OBJECT<unknown>DEFAULT10
                                                                      _dl_phnum.symtab0x4167044OBJECT<unknown>DEFAULT10
                                                                      _edata.symtab0x4103ac0NOTYPE<unknown>DEFAULTSHN_ABS
                                                                      _end.symtab0x4167080NOTYPE<unknown>DEFAULTSHN_ABS
                                                                      _errno.symtab0x41460c4OBJECT<unknown>DEFAULT10
                                                                      _exit.symtab0x406c6848FUNC<unknown>DEFAULT2
                                                                      _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _fini.symtab0x40d60012FUNC<unknown>HIDDEN3
                                                                      _fixed_buffers.symtab0x41463c8192OBJECT<unknown>DEFAULT10
                                                                      _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _fp_out_narrow.symtab0x40b764124FUNC<unknown>DEFAULT2
                                                                      _fpmaxtostr.symtab0x40cccc1264FUNC<unknown>HIDDEN2
                                                                      _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _h_errno.symtab0x4146104OBJECT<unknown>DEFAULT10
                                                                      _init.symtab0x40009412FUNC<unknown>HIDDEN1
                                                                      _load_inttype.symtab0x40cc3892FUNC<unknown>HIDDEN2
                                                                      _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _ppfs_init.symtab0x40bd24120FUNC<unknown>HIDDEN2
                                                                      _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _ppfs_parsespec.symtab0x40bff0902FUNC<unknown>HIDDEN2
                                                                      _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _ppfs_prepargs.symtab0x40bd9c72FUNC<unknown>HIDDEN2
                                                                      _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _ppfs_setargs.symtab0x40bde4464FUNC<unknown>HIDDEN2
                                                                      _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _promoted_size.symtab0x40bfb460FUNC<unknown>DEFAULT2
                                                                      _pthread_cleanup_pop_restore.symtab0x408a3e12FUNC<unknown>DEFAULT2
                                                                      _pthread_cleanup_push_defer.symtab0x408a3e12FUNC<unknown>DEFAULT2
                                                                      _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _sigintr.symtab0x416644128OBJECT<unknown>HIDDEN10
                                                                      _start.symtab0x4001a030FUNC<unknown>DEFAULT2
                                                                      _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _stdio_fopen.symtab0x40a1a0536FUNC<unknown>HIDDEN2
                                                                      _stdio_init.symtab0x40a3b8108FUNC<unknown>HIDDEN2
                                                                      _stdio_openlist.symtab0x41027c4OBJECT<unknown>DEFAULT9
                                                                      _stdio_openlist_add_lock.symtab0x41028024OBJECT<unknown>DEFAULT9
                                                                      _stdio_openlist_dec_use.symtab0x40a580224FUNC<unknown>DEFAULT2
                                                                      _stdio_openlist_del_count.symtab0x4146384OBJECT<unknown>DEFAULT10
                                                                      _stdio_openlist_del_lock.symtab0x41029824OBJECT<unknown>DEFAULT9
                                                                      _stdio_openlist_use_count.symtab0x4146344OBJECT<unknown>DEFAULT10
                                                                      _stdio_streams.symtab0x4102b4240OBJECT<unknown>DEFAULT9
                                                                      _stdio_term.symtab0x40a440148FUNC<unknown>HIDDEN2
                                                                      _stdio_user_locking.symtab0x4102b04OBJECT<unknown>DEFAULT9
                                                                      _stdlib_strto_l.symtab0x408650324FUNC<unknown>HIDDEN2
                                                                      _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _store_inttype.symtab0x40cc9456FUNC<unknown>HIDDEN2
                                                                      _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _string_syserrmsgs.symtab0x40f0dc2906OBJECT<unknown>HIDDEN4
                                                                      _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _uintmaxtostr.symtab0x408f00260FUNC<unknown>HIDDEN2
                                                                      _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _vfprintf_internal.symtab0x40b7e01348FUNC<unknown>HIDDEN2
                                                                      _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      abort.symtab0x4080c0244FUNC<unknown>DEFAULT2
                                                                      abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      access.symtab0x406c9856FUNC<unknown>DEFAULT2
                                                                      access.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      astd.symtab0x4043b8368FUNC<unknown>DEFAULT2
                                                                      atcp.symtab0x403e101448FUNC<unknown>DEFAULT2
                                                                      atoi.symtab0x40862424FUNC<unknown>DEFAULT2
                                                                      atol.symtab0x40862424FUNC<unknown>DEFAULT2
                                                                      atol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      audp.symtab0x4038d41340FUNC<unknown>DEFAULT2
                                                                      bcopy.symtab0x40768424FUNC<unknown>DEFAULT2
                                                                      bcopy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      been_there_done_that.symtab0x4145ec4OBJECT<unknown>DEFAULT10
                                                                      been_there_done_that.2753.symtab0x4146084OBJECT<unknown>DEFAULT10
                                                                      bsd_signal.symtab0x407c40184FUNC<unknown>DEFAULT2
                                                                      buf.2577.symtab0x4143e416OBJECT<unknown>DEFAULT10
                                                                      buf.4814.symtab0x4143f4460OBJECT<unknown>DEFAULT10
                                                                      c.symtab0x4100444OBJECT<unknown>DEFAULT9
                                                                      chdir.symtab0x406cd056FUNC<unknown>DEFAULT2
                                                                      chdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      close.symtab0x406d0856FUNC<unknown>DEFAULT2
                                                                      close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      commServer.symtab0x4100204OBJECT<unknown>DEFAULT9
                                                                      completed.2217.symtab0x4103ac1OBJECT<unknown>DEFAULT10
                                                                      connect.symtab0x407af040FUNC<unknown>DEFAULT2
                                                                      connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      connectTimeout.symtab0x4015e0772FUNC<unknown>DEFAULT2
                                                                      creat.symtab0x406f1c24FUNC<unknown>DEFAULT2
                                                                      crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      csum.symtab0x401a18232FUNC<unknown>DEFAULT2
                                                                      currentServer.symtab0x4100404OBJECT<unknown>DEFAULT9
                                                                      data_start.symtab0x41001c0NOTYPE<unknown>DEFAULT9
                                                                      decodea.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      environ.symtab0x4145f84OBJECT<unknown>DEFAULT10
                                                                      errno.symtab0x41460c4OBJECT<unknown>DEFAULT10
                                                                      errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      exit.symtab0x408794112FUNC<unknown>DEFAULT2
                                                                      exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      exp10_table.symtab0x40fc4c72OBJECT<unknown>DEFAULT4
                                                                      fclose.symtab0x40a078272FUNC<unknown>DEFAULT2
                                                                      fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fcntl.symtab0x406b24172FUNC<unknown>DEFAULT2
                                                                      fcntl64.symtab0x406bd0152FUNC<unknown>DEFAULT2
                                                                      fdgets.symtab0x4003f4200FUNC<unknown>DEFAULT2
                                                                      fflush_unlocked.symtab0x40a660320FUNC<unknown>DEFAULT2
                                                                      fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fgetc_unlocked.symtab0x40c378216FUNC<unknown>DEFAULT2
                                                                      fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fgets.symtab0x40a508120FUNC<unknown>DEFAULT2
                                                                      fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fgets_unlocked.symtab0x40a7a0128FUNC<unknown>DEFAULT2
                                                                      fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fmt.symtab0x40fc3820OBJECT<unknown>DEFAULT4
                                                                      fopen.symtab0x40a18824FUNC<unknown>DEFAULT2
                                                                      fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fork.symtab0x406d4056FUNC<unknown>DEFAULT2
                                                                      fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fputs_unlocked.symtab0x40c45068FUNC<unknown>DEFAULT2
                                                                      fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      frame_dummy.symtab0x4001400FUNC<unknown>DEFAULT2
                                                                      free.symtab0x407e80240FUNC<unknown>DEFAULT2
                                                                      free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fseek.symtab0x40d35428FUNC<unknown>DEFAULT2
                                                                      fseeko.symtab0x40d35428FUNC<unknown>DEFAULT2
                                                                      fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      fseeko64.symtab0x40d370232FUNC<unknown>DEFAULT2
                                                                      fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      ftcp.symtab0x4021041452FUNC<unknown>DEFAULT2
                                                                      fwrite_unlocked.symtab0x40c494156FUNC<unknown>DEFAULT2
                                                                      fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      getArch.symtab0x40452820FUNC<unknown>DEFAULT2
                                                                      getHost.symtab0x40118884FUNC<unknown>DEFAULT2
                                                                      getOurIP.symtab0x4004bc680FUNC<unknown>DEFAULT2
                                                                      getPortz.symtab0x40453c152FUNC<unknown>DEFAULT2
                                                                      getRandomIP.symtab0x40039892FUNC<unknown>DEFAULT2
                                                                      get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      getc_unlocked.symtab0x40c378216FUNC<unknown>DEFAULT2
                                                                      getegid.symtab0x408d4856FUNC<unknown>DEFAULT2
                                                                      getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      geteuid.symtab0x408d8056FUNC<unknown>DEFAULT2
                                                                      geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      getgid.symtab0x408db856FUNC<unknown>DEFAULT2
                                                                      getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      gethostbyname.symtab0x4077fc72FUNC<unknown>DEFAULT2
                                                                      gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      gethostbyname_r.symtab0x407844684FUNC<unknown>DEFAULT2
                                                                      gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      getpid.symtab0x406d7856FUNC<unknown>DEFAULT2
                                                                      getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      getsockname.symtab0x407b1840FUNC<unknown>DEFAULT2
                                                                      getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      getsockopt.symtab0x407b4044FUNC<unknown>DEFAULT2
                                                                      getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      getuid.symtab0x408df056FUNC<unknown>DEFAULT2
                                                                      getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      gotIP.symtab0x4103cc4OBJECT<unknown>DEFAULT10
                                                                      h.4813.symtab0x4145c020OBJECT<unknown>DEFAULT10
                                                                      h_errno.symtab0x4146104OBJECT<unknown>DEFAULT10
                                                                      heap_alloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      heap_free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      htonl.symtab0x4076fa46FUNC<unknown>DEFAULT2
                                                                      htons.symtab0x40772822FUNC<unknown>DEFAULT2
                                                                      i.4082.symtab0x4100484OBJECT<unknown>DEFAULT9
                                                                      index.symtab0x40743c192FUNC<unknown>DEFAULT2
                                                                      inet_addr.symtab0x4077d044FUNC<unknown>DEFAULT2
                                                                      inet_aton.symtab0x409508204FUNC<unknown>DEFAULT2
                                                                      inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      inet_ntoa.symtab0x4077b824FUNC<unknown>DEFAULT2
                                                                      inet_ntoa.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      inet_ntoa_r.symtab0x407740120FUNC<unknown>DEFAULT2
                                                                      inet_ntop.symtab0x40add8492FUNC<unknown>DEFAULT2
                                                                      inet_ntop4.symtab0x40ac9c316FUNC<unknown>DEFAULT2
                                                                      inet_pton.symtab0x40ab04408FUNC<unknown>DEFAULT2
                                                                      inet_pton4.symtab0x40aa68156FUNC<unknown>DEFAULT2
                                                                      initConnection.symtab0x4062ac340FUNC<unknown>DEFAULT2
                                                                      init_rand.symtab0x4001d4180FUNC<unknown>DEFAULT2
                                                                      initial_fa.symtab0x410060260OBJECT<unknown>DEFAULT9
                                                                      initstate.symtab0x408298120FUNC<unknown>DEFAULT2
                                                                      initstate_r.symtab0x408574176FUNC<unknown>DEFAULT2
                                                                      ioctl.symtab0x406db0148FUNC<unknown>DEFAULT2
                                                                      ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      isatty.symtab0x40a9d036FUNC<unknown>DEFAULT2
                                                                      isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      isspace.symtab0x40705c28FUNC<unknown>DEFAULT2
                                                                      isspace.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      kill.symtab0x406e4456FUNC<unknown>DEFAULT2
                                                                      kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      lengthd.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      lengthq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      libc/string/sh/sh4/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      libc/sysdeps/linux/sh/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      libc/sysdeps/linux/sh/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      libc/sysdeps/linux/sh/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      listFork.symtab0x4018e4308FUNC<unknown>DEFAULT2
                                                                      llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      lseek64.symtab0x40d54096FUNC<unknown>DEFAULT2
                                                                      macAddress.symtab0x4103d86OBJECT<unknown>DEFAULT10
                                                                      main.symtab0x4064001780FUNC<unknown>DEFAULT2
                                                                      mainCommSock.symtab0x4103c84OBJECT<unknown>DEFAULT10
                                                                      makeIPPacket.symtab0x401c14224FUNC<unknown>DEFAULT2
                                                                      makeRandomStr.symtab0x4011dc156FUNC<unknown>DEFAULT2
                                                                      makevsepacket.symtab0x402944248FUNC<unknown>DEFAULT2
                                                                      malloc.symtab0x407d78264FUNC<unknown>DEFAULT2
                                                                      malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      memchr.symtab0x40d1bc204FUNC<unknown>DEFAULT2
                                                                      memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      memcpy.symtab0x407140636FUNC<unknown>DEFAULT2
                                                                      memmove.symtab0x409004978FUNC<unknown>DEFAULT2
                                                                      memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      mempcpy.symtab0x40c53036FUNC<unknown>DEFAULT2
                                                                      mempcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      memrchr.symtab0x40d288204FUNC<unknown>DEFAULT2
                                                                      memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      memset.symtab0x4073c0124FUNC<unknown>DEFAULT2
                                                                      memset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      mylock.symtab0x41016424OBJECT<unknown>DEFAULT9
                                                                      mylock.symtab0x41017c24OBJECT<unknown>DEFAULT9
                                                                      mylock.symtab0x41461424OBJECT<unknown>DEFAULT10
                                                                      nanosleep.symtab0x408e2856FUNC<unknown>DEFAULT2
                                                                      nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      next_start.1030.symtab0x4143e04OBJECT<unknown>DEFAULT10
                                                                      ntohl.symtab0x4076b448FUNC<unknown>DEFAULT2
                                                                      ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      ntohs.symtab0x4076e422FUNC<unknown>DEFAULT2
                                                                      ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      numpids.symtab0x4103d08OBJECT<unknown>DEFAULT10
                                                                      object.2270.symtab0x4103b024OBJECT<unknown>DEFAULT10
                                                                      open.symtab0x406e7c160FUNC<unknown>DEFAULT2
                                                                      open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      opennameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      ourIP.symtab0x41663c4OBJECT<unknown>DEFAULT10
                                                                      p.2215.symtab0x4100180OBJECT<unknown>DEFAULT9
                                                                      pids.symtab0x4166404OBJECT<unknown>DEFAULT10
                                                                      poll.symtab0x40a04056FUNC<unknown>DEFAULT2
                                                                      poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      prefix.4023.symtab0x40f03412OBJECT<unknown>DEFAULT4
                                                                      print.symtab0x400bf01072FUNC<unknown>DEFAULT2
                                                                      printchar.symtab0x400898104FUNC<unknown>DEFAULT2
                                                                      printi.symtab0x400a58408FUNC<unknown>DEFAULT2
                                                                      prints.symtab0x400900344FUNC<unknown>DEFAULT2
                                                                      processCmd.symtab0x4045d47384FUNC<unknown>DEFAULT2
                                                                      qual_chars.4029.symtab0x40f04820OBJECT<unknown>DEFAULT4
                                                                      raise.symtab0x409ea440FUNC<unknown>DEFAULT2
                                                                      raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      rand.symtab0x4081b420FUNC<unknown>DEFAULT2
                                                                      rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      rand_cmwc.symtab0x400288272FUNC<unknown>DEFAULT2
                                                                      random.symtab0x4081c8100FUNC<unknown>DEFAULT2
                                                                      random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      random_poly_info.symtab0x40ec3c40OBJECT<unknown>DEFAULT4
                                                                      random_r.symtab0x408448104FUNC<unknown>DEFAULT2
                                                                      random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      randtbl.symtab0x4101b0128OBJECT<unknown>DEFAULT9
                                                                      rawmemchr.symtab0x40a820152FUNC<unknown>DEFAULT2
                                                                      rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      read.symtab0x406f3456FUNC<unknown>DEFAULT2
                                                                      read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      read_etc_hosts_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      recv.symtab0x407b6c40FUNC<unknown>DEFAULT2
                                                                      recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      recvLine.symtab0x401278872FUNC<unknown>DEFAULT2
                                                                      rtcp.symtab0x4034841104FUNC<unknown>DEFAULT2
                                                                      sbrk.symtab0x408cb888FUNC<unknown>DEFAULT2
                                                                      sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      select.symtab0x406f6c52FUNC<unknown>DEFAULT2
                                                                      select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      send.symtab0x407b9440FUNC<unknown>DEFAULT2
                                                                      send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      sendto.symtab0x407bbc48FUNC<unknown>DEFAULT2
                                                                      sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      setsid.symtab0x406fa056FUNC<unknown>DEFAULT2
                                                                      setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      setsockopt.symtab0x407bec44FUNC<unknown>DEFAULT2
                                                                      setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      setstate.symtab0x40822c108FUNC<unknown>DEFAULT2
                                                                      setstate_r.symtab0x408370216FUNC<unknown>DEFAULT2
                                                                      sigaction.symtab0x409ecc160FUNC<unknown>DEFAULT2
                                                                      sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      signal.symtab0x407c40184FUNC<unknown>DEFAULT2
                                                                      signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      sigprocmask.symtab0x408e6084FUNC<unknown>DEFAULT2
                                                                      sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      sleep.symtab0x408804376FUNC<unknown>DEFAULT2
                                                                      sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      socket.symtab0x407c1840FUNC<unknown>DEFAULT2
                                                                      socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      socket_connect.symtab0x402824288FUNC<unknown>DEFAULT2
                                                                      sockprintf.symtab0x401020360FUNC<unknown>DEFAULT2
                                                                      spec_and_mask.4028.symtab0x40f05c16OBJECT<unknown>DEFAULT4
                                                                      spec_base.4022.symtab0x40f0407OBJECT<unknown>DEFAULT4
                                                                      spec_chars.4025.symtab0x40f08821OBJECT<unknown>DEFAULT4
                                                                      spec_flags.4024.symtab0x40f0a08OBJECT<unknown>DEFAULT4
                                                                      spec_or_mask.4027.symtab0x40f06c16OBJECT<unknown>DEFAULT4
                                                                      spec_ranges.4026.symtab0x40f07c9OBJECT<unknown>DEFAULT4
                                                                      sprintf.symtab0x40b554132FUNC<unknown>DEFAULT2
                                                                      sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      srand.symtab0x40831096FUNC<unknown>DEFAULT2
                                                                      srandom.symtab0x40831096FUNC<unknown>DEFAULT2
                                                                      srandom_r.symtab0x4084b0196FUNC<unknown>DEFAULT2
                                                                      static_id.symtab0x41024c2OBJECT<unknown>DEFAULT9
                                                                      static_ns.symtab0x41462c4OBJECT<unknown>DEFAULT10
                                                                      stderr.symtab0x4102704OBJECT<unknown>DEFAULT9
                                                                      stdhexflood.symtab0x403178360FUNC<unknown>DEFAULT2
                                                                      stdin.symtab0x4102684OBJECT<unknown>DEFAULT9
                                                                      stdout.symtab0x41026c4OBJECT<unknown>DEFAULT9
                                                                      strcasecmp.symtab0x40c6c064FUNC<unknown>DEFAULT2
                                                                      strcasecmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strchr.symtab0x40743c192FUNC<unknown>DEFAULT2
                                                                      strchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strcmp.symtab0x4074fc34FUNC<unknown>DEFAULT2
                                                                      strcmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strcoll.symtab0x4074fc34FUNC<unknown>DEFAULT2
                                                                      strcpy.symtab0x40751e30FUNC<unknown>DEFAULT2
                                                                      strcpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strdup.symtab0x40a98476FUNC<unknown>DEFAULT2
                                                                      strdup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strerror_r.symtab0x40c5f8200FUNC<unknown>DEFAULT2
                                                                      strlen.symtab0x40753c136FUNC<unknown>DEFAULT2
                                                                      strlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strncat.symtab0x40a8b8154FUNC<unknown>DEFAULT2
                                                                      strncat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strncpy.symtab0x4093d8142FUNC<unknown>DEFAULT2
                                                                      strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strnlen.symtab0x40c554132FUNC<unknown>DEFAULT2
                                                                      strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strpbrk.symtab0x4094e040FUNC<unknown>DEFAULT2
                                                                      strpbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strspn.symtab0x40a95248FUNC<unknown>DEFAULT2
                                                                      strspn.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strstr.symtab0x4075c4192FUNC<unknown>DEFAULT2
                                                                      strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strtok.symtab0x40769c24FUNC<unknown>DEFAULT2
                                                                      strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strtok_r.symtab0x409468120FUNC<unknown>DEFAULT2
                                                                      strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      strtol.symtab0x40863c20FUNC<unknown>DEFAULT2
                                                                      strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      tcgetattr.symtab0x40a9f4116FUNC<unknown>DEFAULT2
                                                                      tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      tcpcsum.symtab0x401b00276FUNC<unknown>DEFAULT2
                                                                      time.symtab0x406fd856FUNC<unknown>DEFAULT2
                                                                      time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      tolower.symtab0x40b52c40FUNC<unknown>DEFAULT2
                                                                      tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      toupper.symtab0x40707840FUNC<unknown>DEFAULT2
                                                                      toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      trim.symtab0x400764308FUNC<unknown>DEFAULT2
                                                                      trivial.symtab0x406b180NOTYPE<unknown>DEFAULT2
                                                                      type_codes.symtab0x40f0a824OBJECT<unknown>DEFAULT4
                                                                      type_sizes.symtab0x40f0c012OBJECT<unknown>DEFAULT4
                                                                      unknown.1072.symtab0x40f0cc14OBJECT<unknown>DEFAULT4
                                                                      unsafe_state.symtab0x41019428OBJECT<unknown>DEFAULT9
                                                                      useragents.symtab0x41002428OBJECT<unknown>DEFAULT9
                                                                      usleep.symtab0x40897c76FUNC<unknown>DEFAULT2
                                                                      usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      vseattack.symtab0x402a3c1508FUNC<unknown>DEFAULT2
                                                                      vsnprintf.symtab0x40b5d8168FUNC<unknown>DEFAULT2
                                                                      vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      wait4.symtab0x408eb456FUNC<unknown>DEFAULT2
                                                                      wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      waitpid.symtab0x40701020FUNC<unknown>DEFAULT2
                                                                      waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      wcrtomb.symtab0x40c8b468FUNC<unknown>DEFAULT2
                                                                      wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      wcsnrtombs.symtab0x40c918112FUNC<unknown>DEFAULT2
                                                                      wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      wcsrtombs.symtab0x40c8f832FUNC<unknown>DEFAULT2
                                                                      wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      write.symtab0x40702456FUNC<unknown>DEFAULT2
                                                                      write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                                                      xdigits.3026.symtab0x40ecec17OBJECT<unknown>DEFAULT4
                                                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                      2024-12-16T13:09:18.671976+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340762150.241.88.13225565TCP
                                                                      2024-12-16T13:09:20.989883+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340764150.241.88.13225565TCP
                                                                      2024-12-16T13:09:23.346054+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340766150.241.88.13225565TCP
                                                                      2024-12-16T13:09:25.930736+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340768150.241.88.13225565TCP
                                                                      2024-12-16T13:09:28.273429+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340770150.241.88.13225565TCP
                                                                      2024-12-16T13:09:30.600123+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340772150.241.88.13225565TCP
                                                                      2024-12-16T13:09:32.984956+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340774150.241.88.13225565TCP
                                                                      2024-12-16T13:09:35.321711+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340776150.241.88.13225565TCP
                                                                      2024-12-16T13:09:37.661942+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340778150.241.88.13225565TCP
                                                                      2024-12-16T13:09:40.009051+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340780150.241.88.13225565TCP
                                                                      2024-12-16T13:09:42.396763+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340782150.241.88.13225565TCP
                                                                      2024-12-16T13:09:44.723149+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340784150.241.88.13225565TCP
                                                                      2024-12-16T13:09:47.051419+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340786150.241.88.13225565TCP
                                                                      2024-12-16T13:09:49.444987+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340788150.241.88.13225565TCP
                                                                      2024-12-16T13:09:51.818646+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340790150.241.88.13225565TCP
                                                                      2024-12-16T13:09:54.164192+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340792150.241.88.13225565TCP
                                                                      2024-12-16T13:09:56.490071+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340794150.241.88.13225565TCP
                                                                      2024-12-16T13:09:58.821929+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340796150.241.88.13225565TCP
                                                                      2024-12-16T13:10:01.209721+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340798150.241.88.13225565TCP
                                                                      2024-12-16T13:10:03.540102+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340800150.241.88.13225565TCP
                                                                      2024-12-16T13:10:05.914624+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340802150.241.88.13225565TCP
                                                                      2024-12-16T13:10:08.258636+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340804150.241.88.13225565TCP
                                                                      2024-12-16T13:10:11.202089+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340806150.241.88.13225565TCP
                                                                      2024-12-16T13:10:13.584603+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340808150.241.88.13225565TCP
                                                                      2024-12-16T13:10:16.004322+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340810150.241.88.13225565TCP
                                                                      2024-12-16T13:10:18.381606+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340812150.241.88.13225565TCP
                                                                      2024-12-16T13:10:20.711400+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340814150.241.88.13225565TCP
                                                                      2024-12-16T13:10:23.087152+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340816150.241.88.13225565TCP
                                                                      2024-12-16T13:10:25.410316+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340818150.241.88.13225565TCP
                                                                      2024-12-16T13:10:27.740599+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340820150.241.88.13225565TCP
                                                                      2024-12-16T13:10:30.082800+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340822150.241.88.13225565TCP
                                                                      2024-12-16T13:10:32.414294+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340824150.241.88.13225565TCP
                                                                      2024-12-16T13:10:34.743959+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340826150.241.88.13225565TCP
                                                                      2024-12-16T13:10:37.086757+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340828150.241.88.13225565TCP
                                                                      2024-12-16T13:10:39.460161+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340830150.241.88.13225565TCP
                                                                      2024-12-16T13:10:41.786389+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340832150.241.88.13225565TCP
                                                                      2024-12-16T13:10:44.114438+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340834150.241.88.13225565TCP
                                                                      2024-12-16T13:10:46.443282+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340836150.241.88.13225565TCP
                                                                      2024-12-16T13:10:48.771491+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340838150.241.88.13225565TCP
                                                                      2024-12-16T13:10:51.102683+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340840150.241.88.13225565TCP
                                                                      2024-12-16T13:10:53.427842+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340842150.241.88.13225565TCP
                                                                      2024-12-16T13:10:55.758306+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340844150.241.88.13225565TCP
                                                                      2024-12-16T13:10:58.087852+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340846150.241.88.13225565TCP
                                                                      2024-12-16T13:11:00.414039+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340848150.241.88.13225565TCP
                                                                      2024-12-16T13:11:02.771624+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340850150.241.88.13225565TCP
                                                                      2024-12-16T13:11:05.150016+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340852150.241.88.13225565TCP
                                                                      2024-12-16T13:11:07.525163+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340854150.241.88.13225565TCP
                                                                      2024-12-16T13:11:09.849922+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340856150.241.88.13225565TCP
                                                                      2024-12-16T13:11:12.182637+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340858150.241.88.13225565TCP
                                                                      2024-12-16T13:11:14.538622+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340860150.241.88.13225565TCP
                                                                      2024-12-16T13:11:16.871041+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340862150.241.88.13225565TCP
                                                                      2024-12-16T13:11:19.257724+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340864150.241.88.13225565TCP
                                                                      2024-12-16T13:11:21.633848+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340866150.241.88.13225565TCP
                                                                      2024-12-16T13:11:23.960194+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340868150.241.88.13225565TCP
                                                                      2024-12-16T13:11:26.290801+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340870150.241.88.13225565TCP
                                                                      2024-12-16T13:11:28.615583+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340872150.241.88.13225565TCP
                                                                      2024-12-16T13:11:30.943668+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340874150.241.88.13225565TCP
                                                                      2024-12-16T13:11:33.320753+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340876150.241.88.13225565TCP
                                                                      2024-12-16T13:11:35.650754+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340878150.241.88.13225565TCP
                                                                      2024-12-16T13:11:37.974812+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340880150.241.88.13225565TCP
                                                                      2024-12-16T13:11:40.302688+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340882150.241.88.13225565TCP
                                                                      2024-12-16T13:11:42.680017+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340884150.241.88.13225565TCP
                                                                      2024-12-16T13:11:45.008955+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340886150.241.88.13225565TCP
                                                                      2024-12-16T13:11:47.337385+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340888150.241.88.13225565TCP
                                                                      2024-12-16T13:11:49.668720+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340890150.241.88.13225565TCP
                                                                      2024-12-16T13:11:51.998419+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340892150.241.88.13225565TCP
                                                                      2024-12-16T13:11:54.355590+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340894150.241.88.13225565TCP
                                                                      2024-12-16T13:11:56.678643+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340896150.241.88.13225565TCP
                                                                      2024-12-16T13:11:59.005909+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340898150.241.88.13225565TCP
                                                                      2024-12-16T13:12:01.337841+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340900150.241.88.13225565TCP
                                                                      2024-12-16T13:12:03.891693+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340902150.241.88.13225565TCP
                                                                      2024-12-16T13:12:06.228448+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340904150.241.88.13225565TCP
                                                                      2024-12-16T13:12:08.553795+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340906150.241.88.13225565TCP
                                                                      2024-12-16T13:12:10.919357+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340908150.241.88.13225565TCP
                                                                      2024-12-16T13:12:13.241470+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340910150.241.88.13225565TCP
                                                                      2024-12-16T13:12:15.648624+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340912150.241.88.13225565TCP
                                                                      2024-12-16T13:12:17.993880+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340914150.241.88.13225565TCP
                                                                      2024-12-16T13:12:20.319368+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340916150.241.88.13225565TCP
                                                                      2024-12-16T13:12:22.651320+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340918150.241.88.13225565TCP
                                                                      2024-12-16T13:12:25.023903+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340920150.241.88.13225565TCP
                                                                      2024-12-16T13:12:27.400202+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340922150.241.88.13225565TCP
                                                                      2024-12-16T13:12:29.774623+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340924150.241.88.13225565TCP
                                                                      2024-12-16T13:12:32.104882+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340926150.241.88.13225565TCP
                                                                      2024-12-16T13:12:34.460723+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340928150.241.88.13225565TCP
                                                                      2024-12-16T13:12:36.788256+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340930150.241.88.13225565TCP
                                                                      2024-12-16T13:12:39.116866+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340932150.241.88.13225565TCP
                                                                      2024-12-16T13:12:41.499684+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340934150.241.88.13225565TCP
                                                                      2024-12-16T13:12:43.837014+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340936150.241.88.13225565TCP
                                                                      2024-12-16T13:12:46.214814+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340938150.241.88.13225565TCP
                                                                      2024-12-16T13:12:48.575123+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340940150.241.88.13225565TCP
                                                                      2024-12-16T13:12:51.062329+01002846526ETPRO MALWARE ELF/BASHLITE Variant CnC Checkin1192.168.2.2340942150.241.88.13225565TCP
                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                      Dec 16, 2024 13:09:16.615055084 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 13:09:18.545960903 CET4076225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:18.665632010 CET2556540762150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:18.665729046 CET4076225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:18.671976089 CET4076225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:18.792207003 CET2556540762150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:20.867384911 CET2556540762150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:20.869390965 CET4076225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:20.869905949 CET4076425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:20.989639044 CET2556540762150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:20.989681005 CET2556540764150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:20.989784956 CET4076425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:20.989882946 CET4076425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:21.109898090 CET2556540764150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:22.246225119 CET42836443192.168.2.2391.189.91.43
                                                                      Dec 16, 2024 13:09:23.014134884 CET4251680192.168.2.23109.202.202.202
                                                                      Dec 16, 2024 13:09:23.221112967 CET2556540764150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:23.221553087 CET4076425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:23.222115040 CET4076625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:23.345429897 CET2556540764150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:23.345885992 CET2556540766150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:23.345995903 CET4076625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:23.346054077 CET4076625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:23.466305017 CET2556540766150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:25.809485912 CET2556540766150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:25.809616089 CET4076625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:25.810416937 CET4076825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:25.930058956 CET2556540766150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:25.930493116 CET2556540768150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:25.930572987 CET4076825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:25.930736065 CET4076825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:26.051023006 CET2556540768150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:28.151885986 CET2556540768150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:28.152205944 CET4076825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:28.153142929 CET4077025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:28.272027969 CET2556540768150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:28.273159027 CET2556540770150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:28.273308039 CET4077025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:28.273428917 CET4077025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:28.393524885 CET2556540770150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:30.477699041 CET2556540770150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:30.478383064 CET4077025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:30.479172945 CET4077225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:30.598844051 CET2556540770150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:30.599860907 CET2556540772150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:30.600037098 CET4077225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:30.600122929 CET4077225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:30.719857931 CET2556540772150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:32.863522053 CET2556540772150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:32.863907099 CET4077225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:32.864922047 CET4077425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:32.983869076 CET2556540772150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:32.984680891 CET2556540774150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:32.984956026 CET4077425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:32.984956026 CET4077425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:33.104885101 CET2556540774150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:35.199917078 CET2556540774150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:35.200494051 CET4077425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:35.200525999 CET4077425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:35.201370001 CET4077625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:35.320496082 CET2556540774150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:35.321252108 CET2556540776150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:35.321400881 CET4077625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:35.321711063 CET4077625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:35.442085981 CET2556540776150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:37.348295927 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 13:09:37.540514946 CET2556540776150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:37.540965080 CET4077625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:37.541868925 CET4077825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:37.660855055 CET2556540776150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:37.661654949 CET2556540778150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:37.661847115 CET4077825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:37.661942005 CET4077825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:37.781861067 CET2556540778150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:39.887065887 CET2556540778150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:39.887299061 CET4077825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:39.887748003 CET4078025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:40.008840084 CET2556540778150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:40.008861065 CET2556540780150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:40.009021997 CET4078025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:40.009051085 CET4078025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:40.128937006 CET2556540780150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:42.275419950 CET2556540780150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:42.275692940 CET4078025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:42.276506901 CET4078225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:42.395567894 CET2556540780150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:42.396311045 CET2556540782150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:42.396423101 CET4078225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:42.396763086 CET4078225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:42.516539097 CET2556540782150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:44.601705074 CET2556540782150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:44.602010965 CET4078225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:44.602904081 CET4078425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:44.721745014 CET2556540782150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:44.722640038 CET2556540784150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:44.723023891 CET4078425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:44.723149061 CET4078425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:44.844770908 CET2556540784150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:46.930026054 CET2556540784150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:46.930430889 CET4078425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:46.931298018 CET4078625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:47.050226927 CET2556540784150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:47.051052094 CET2556540786150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:47.051246881 CET4078625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:47.051419020 CET4078625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:47.171232939 CET2556540786150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:49.322369099 CET2556540786150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:49.322638988 CET4078625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:49.323519945 CET4078825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:49.443227053 CET2556540786150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:49.444761992 CET2556540788150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:49.444873095 CET4078825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:49.444987059 CET4078825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:49.564811945 CET2556540788150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:49.634535074 CET42836443192.168.2.2391.189.91.43
                                                                      Dec 16, 2024 13:09:51.697247028 CET2556540788150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:51.697622061 CET4078825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:51.698672056 CET4079025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:51.817483902 CET2556540788150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:51.818500042 CET2556540790150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:51.818599939 CET4079025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:51.818645954 CET4079025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:51.938613892 CET2556540790150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:53.729852915 CET4251680192.168.2.23109.202.202.202
                                                                      Dec 16, 2024 13:09:54.043090105 CET2556540790150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:54.043307066 CET4079025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:54.044186115 CET4079225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:54.163489103 CET2556540790150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:54.164004087 CET2556540792150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:54.164114952 CET4079225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:54.164191961 CET4079225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:54.284070969 CET2556540792150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:56.368446112 CET2556540792150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:56.368690968 CET4079225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:56.369990110 CET4079425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:56.489149094 CET2556540792150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:56.489784956 CET2556540794150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:56.489917040 CET4079425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:56.490071058 CET4079425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:56.611834049 CET2556540794150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:58.699383020 CET2556540794150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:58.699626923 CET4079425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:58.701009035 CET4079625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:58.820178986 CET2556540794150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:58.821719885 CET2556540796150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:09:58.821856976 CET4079625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:58.821928978 CET4079625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:09:58.941721916 CET2556540796150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:01.088378906 CET2556540796150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:01.088721037 CET4079625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:01.089446068 CET4079825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:01.208494902 CET2556540796150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:01.209402084 CET2556540798150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:01.209536076 CET4079825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:01.209721088 CET4079825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:01.330305099 CET2556540798150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:03.418272972 CET2556540798150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:03.418708086 CET4079825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:03.419821978 CET4080025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:03.538822889 CET2556540798150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:03.539755106 CET2556540800150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:03.539889097 CET4080025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:03.540102005 CET4080025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:03.662766933 CET2556540800150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:05.793117046 CET2556540800150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:05.793517113 CET4080025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:05.794517994 CET4080225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:05.913338900 CET2556540800150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:05.914381981 CET2556540802150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:05.914526939 CET4080225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:05.914623976 CET4080225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:06.034393072 CET2556540802150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:08.136987925 CET2556540802150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:08.137398005 CET4080225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:08.138495922 CET4080425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:08.257287025 CET2556540802150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:08.258337975 CET2556540804150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:08.258446932 CET4080425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:08.258635998 CET4080425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:08.378335953 CET2556540804150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:10.993973017 CET2556540804150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:10.994414091 CET4080425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:10.995052099 CET4080625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:11.201523066 CET2556540804150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:11.201581955 CET2556540806150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:11.201931953 CET4080625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:11.202089071 CET4080625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:11.327303886 CET2556540806150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:13.462968111 CET2556540806150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:13.463395119 CET4080625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:13.464586973 CET4080825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:13.583301067 CET2556540806150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:13.584315062 CET2556540808150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:13.584449053 CET4080825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:13.584603071 CET4080825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:13.705414057 CET2556540808150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:15.883425951 CET2556540808150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:15.883613110 CET4080825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:15.884275913 CET4081025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:16.003573895 CET2556540808150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:16.004200935 CET2556540810150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:16.004268885 CET4081025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:16.004322052 CET4081025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:16.124339104 CET2556540810150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:18.260219097 CET2556540810150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:18.260484934 CET4081025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:18.261434078 CET4081225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:18.302439928 CET43928443192.168.2.2391.189.91.42
                                                                      Dec 16, 2024 13:10:18.380286932 CET2556540810150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:18.381450891 CET2556540812150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:18.381541014 CET4081225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:18.381606102 CET4081225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:18.501539946 CET2556540812150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:20.590570927 CET2556540812150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:20.590774059 CET4081225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:20.591500044 CET4081425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:20.710683107 CET2556540812150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:20.711208105 CET2556540814150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:20.711353064 CET4081425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:20.711400032 CET4081425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:20.831630945 CET2556540814150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:22.963363886 CET2556540814150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:22.965477943 CET4081425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:22.967001915 CET4081625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:23.085407019 CET2556540814150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:23.086846113 CET2556540816150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:23.087009907 CET4081625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:23.087152004 CET4081625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:23.206933022 CET2556540816150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:25.289604902 CET2556540816150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:25.289880991 CET4081625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:25.290415049 CET4081825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:25.409676075 CET2556540816150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:25.410083055 CET2556540818150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:25.410212040 CET4081825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:25.410315990 CET4081825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:25.530015945 CET2556540818150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:27.618227005 CET2556540818150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:27.618870020 CET4081825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:27.619493008 CET4082025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:27.740084887 CET2556540818150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:27.740135908 CET2556540820150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:27.740420103 CET4082025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:27.740598917 CET4082025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:27.860318899 CET2556540820150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:29.961678028 CET2556540820150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:29.961965084 CET4082025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:29.962685108 CET4082225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:30.081891060 CET2556540820150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:30.082357883 CET2556540822150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:30.082470894 CET4082225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:30.082799911 CET4082225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:30.202815056 CET2556540822150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:32.293425083 CET2556540822150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:32.293664932 CET4082225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:32.294329882 CET4082425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:32.413543940 CET2556540822150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:32.414093018 CET2556540824150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:32.414226055 CET4082425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:32.414294004 CET4082425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:32.534049034 CET2556540824150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:34.621581078 CET2556540824150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:34.621917009 CET4082425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:34.622359991 CET4082625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:34.743544102 CET2556540824150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:34.743565083 CET2556540826150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:34.743717909 CET4082625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:34.743958950 CET4082625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:34.863764048 CET2556540826150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:36.965899944 CET2556540826150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:36.966228962 CET4082625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:36.966733932 CET4082825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:37.086018085 CET2556540826150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:37.086522102 CET2556540828150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:37.086674929 CET4082825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:37.086756945 CET4082825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:37.206768036 CET2556540828150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:39.338412046 CET2556540828150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:39.338960886 CET4082825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:39.339726925 CET4083025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:39.458904028 CET2556540828150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:39.459574938 CET2556540830150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:39.459836960 CET4083025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:39.460160971 CET4083025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:39.579957008 CET2556540830150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:41.665429115 CET2556540830150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:41.665751934 CET4083025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:41.666323900 CET4083225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:41.785727024 CET2556540830150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:41.786117077 CET2556540832150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:41.786259890 CET4083225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:41.786389112 CET4083225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:41.906122923 CET2556540832150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:43.993504047 CET2556540832150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:43.993751049 CET4083225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:43.994501114 CET4083425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:44.113787889 CET2556540832150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:44.114202976 CET2556540834150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:44.114319086 CET4083425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:44.114438057 CET4083425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:44.235037088 CET2556540834150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:46.321533918 CET2556540834150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:46.322125912 CET4083425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:46.323061943 CET4083625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:46.442025900 CET2556540834150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:46.442955017 CET2556540836150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:46.443085909 CET4083625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:46.443281889 CET4083625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:46.563038111 CET2556540836150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:48.650093079 CET2556540836150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:48.650527954 CET4083625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:48.651263952 CET4083825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:48.770526886 CET2556540836150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:48.771214962 CET2556540838150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:48.771399975 CET4083825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:48.771491051 CET4083825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:48.891382933 CET2556540838150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:50.981724024 CET2556540838150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:50.981920958 CET4083825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:50.981971025 CET4083825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:50.982687950 CET4084025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:51.101887941 CET2556540838150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:51.102428913 CET2556540840150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:51.102546930 CET4084025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:51.102683067 CET4084025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:51.222369909 CET2556540840150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:53.306767941 CET2556540840150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:53.306999922 CET4084025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:53.307478905 CET4084225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:53.427143097 CET2556540840150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:53.427519083 CET2556540842150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:53.427632093 CET4084225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:53.427841902 CET4084225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:53.547981977 CET2556540842150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:55.637459993 CET2556540842150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:55.637667894 CET4084225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:55.638209105 CET4084425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:55.757443905 CET2556540842150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:55.758121014 CET2556540844150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:55.758254051 CET4084425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:55.758306026 CET4084425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:55.878910065 CET2556540844150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:57.966258049 CET2556540844150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:57.966655016 CET4084425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:57.967597008 CET4084625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:58.086519003 CET2556540844150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:58.087389946 CET2556540846150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:10:58.087532997 CET4084625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:58.087852001 CET4084625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:10:58.208328962 CET2556540846150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:00.291263103 CET2556540846150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:00.291707993 CET4084625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:00.292361975 CET4084825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:00.413249969 CET2556540846150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:00.413763046 CET2556540848150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:00.413969994 CET4084825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:00.414038897 CET4084825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:00.533873081 CET2556540848150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:02.650230885 CET2556540848150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:02.650482893 CET4084825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:02.651524067 CET4085025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:02.770747900 CET2556540848150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:02.771323919 CET2556540850150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:02.771508932 CET4085025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:02.771624088 CET4085025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:02.891746998 CET2556540850150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:05.028696060 CET2556540850150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:05.029238939 CET4085025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:05.029992104 CET4085225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:05.149154902 CET2556540850150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:05.149713993 CET2556540852150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:05.149848938 CET4085225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:05.150016069 CET4085225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:05.269850969 CET2556540852150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:07.402621031 CET2556540852150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:07.403110981 CET4085225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:07.403913021 CET4085425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:07.524072886 CET2556540852150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:07.524804115 CET2556540854150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:07.524950027 CET4085425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:07.525162935 CET4085425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:07.645100117 CET2556540854150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:09.727895975 CET2556540854150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:09.728235006 CET4085425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:09.728918076 CET4085625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:09.848263979 CET2556540854150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:09.849584103 CET2556540856150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:09.849788904 CET4085625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:09.849921942 CET4085625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:09.969589949 CET2556540856150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:12.058628082 CET2556540856150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:12.058893919 CET4085625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:12.059585094 CET4085825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:12.182347059 CET2556540856150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:12.182396889 CET2556540858150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:12.182595968 CET4085825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:12.182636976 CET4085825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:12.302696943 CET2556540858150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:14.415765047 CET2556540858150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:14.415985107 CET4085825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:14.416461945 CET4086025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:14.538024902 CET2556540858150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:14.538352013 CET2556540860150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:14.538480997 CET4086025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:14.538621902 CET4086025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:14.658329964 CET2556540860150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:16.749670982 CET2556540860150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:16.749936104 CET4086025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:16.750667095 CET4086225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:16.869956970 CET2556540860150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:16.870701075 CET2556540862150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:16.870835066 CET4086225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:16.871041059 CET4086225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:16.990880966 CET2556540862150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:19.136598110 CET2556540862150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:19.136949062 CET4086225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:19.137655973 CET4086425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:19.257153988 CET2556540862150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:19.257479906 CET2556540864150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:19.257646084 CET4086425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:19.257724047 CET4086425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:19.378535986 CET2556540864150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:21.512249947 CET2556540864150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:21.512629986 CET4086425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:21.513700962 CET4086625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:21.632487059 CET2556540864150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:21.633560896 CET2556540866150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:21.633641958 CET4086625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:21.633847952 CET4086625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:21.753567934 CET2556540866150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:23.838447094 CET2556540866150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:23.838743925 CET4086625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:23.839550018 CET4086825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:23.959817886 CET2556540866150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:23.959840059 CET2556540868150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:23.960000992 CET4086825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:23.960194111 CET4086825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:24.080852985 CET2556540868150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:26.166692972 CET2556540868150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:26.167146921 CET4086825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:26.168405056 CET4087025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:26.287348032 CET2556540868150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:26.290467978 CET2556540870150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:26.290621996 CET4087025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:26.290801048 CET4087025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:26.410604000 CET2556540870150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:28.494381905 CET2556540870150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:28.494811058 CET4087025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:28.495536089 CET4087225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:28.614800930 CET2556540870150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:28.615288973 CET2556540872150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:28.615425110 CET4087225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:28.615582943 CET4087225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:28.735371113 CET2556540872150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:30.822686911 CET2556540872150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:30.823101997 CET4087225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:30.823683023 CET4087425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:30.942929029 CET2556540872150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:30.943355083 CET2556540874150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:30.943499088 CET4087425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:30.943667889 CET4087425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:31.063406944 CET2556540874150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:33.199249983 CET2556540874150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:33.199637890 CET4087425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:33.200591087 CET4087625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:33.319567919 CET2556540874150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:33.320457935 CET2556540876150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:33.320590973 CET4087625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:33.320753098 CET4087625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:33.443401098 CET2556540876150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:35.529659986 CET2556540876150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:35.529876947 CET4087625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:35.530839920 CET4087825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:35.650122881 CET2556540876150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:35.650595903 CET2556540878150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:35.650674105 CET4087825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:35.650753975 CET4087825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:35.771513939 CET2556540878150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:37.853486061 CET2556540878150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:37.853805065 CET4087825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:37.854621887 CET4088025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:37.973819971 CET2556540878150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:37.974430084 CET2556540880150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:37.974711895 CET4088025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:37.974812031 CET4088025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:38.094594955 CET2556540880150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:40.181677103 CET2556540880150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:40.181929111 CET4088025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:40.182529926 CET4088225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:40.301991940 CET2556540880150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:40.302407026 CET2556540882150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:40.302521944 CET4088225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:40.302687883 CET4088225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:40.422633886 CET2556540882150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:42.558861017 CET2556540882150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:42.559273958 CET4088225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:42.559979916 CET4088425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:42.679233074 CET2556540882150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:42.679814100 CET2556540884150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:42.679907084 CET4088425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:42.680016994 CET4088425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:42.799787045 CET2556540884150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:44.888324976 CET2556540884150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:44.888520956 CET4088425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:44.889070034 CET4088625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:45.008389950 CET2556540884150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:45.008754015 CET2556540886150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:45.008847952 CET4088625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:45.008955002 CET4088625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:45.128976107 CET2556540886150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:47.216658115 CET2556540886150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:47.216897964 CET4088625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:47.217437029 CET4088825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:47.336658955 CET2556540886150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:47.337194920 CET2556540888150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:47.337275028 CET4088825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:47.337384939 CET4088825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:47.457195044 CET2556540888150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:49.547636986 CET2556540888150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:49.547992945 CET4088825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:49.548664093 CET4089025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:49.667953014 CET2556540888150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:49.668534994 CET2556540890150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:49.668663025 CET4089025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:49.668720007 CET4089025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:49.791858912 CET2556540890150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:51.877440929 CET2556540890150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:51.877631903 CET4089025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:51.878385067 CET4089225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:51.997529030 CET2556540890150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:51.998183966 CET2556540892150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:51.998296976 CET4089225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:51.998419046 CET4089225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:52.118331909 CET2556540892150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:54.233602047 CET2556540892150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:54.233916998 CET4089225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:54.235397100 CET4089425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:54.354038954 CET2556540892150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:54.355300903 CET2556540894150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:54.355417967 CET4089425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:54.355590105 CET4089425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:54.475446939 CET2556540894150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:56.556977987 CET2556540894150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:56.557300091 CET4089425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:56.558319092 CET4089625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:56.677257061 CET2556540894150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:56.678206921 CET2556540896150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:56.678443909 CET4089625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:56.678642988 CET4089625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:56.798470974 CET2556540896150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:58.885235071 CET2556540896150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:58.885396004 CET4089625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:58.885943890 CET4089825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:59.005408049 CET2556540896150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:59.005769968 CET2556540898150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:11:59.005851984 CET4089825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:59.005908966 CET4089825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:11:59.125998020 CET2556540898150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:01.217088938 CET2556540898150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:01.217201948 CET4089825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:01.217911005 CET4090025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:01.337110043 CET2556540898150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:01.337713003 CET2556540900150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:01.337769985 CET4090025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:01.337841034 CET4090025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:01.457819939 CET2556540900150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:03.544755936 CET2556540900150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:03.545008898 CET4090025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:03.546106100 CET4090225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:03.891426086 CET2556540900150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:03.891485929 CET2556540902150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:03.891585112 CET4090225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:03.891693115 CET4090225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:04.011527061 CET2556540902150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:06.107804060 CET2556540902150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:06.108032942 CET4090225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:06.108549118 CET4090425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:06.227874994 CET2556540902150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:06.228254080 CET2556540904150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:06.228338003 CET4090425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:06.228447914 CET4090425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:06.348999023 CET2556540904150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:08.432825089 CET2556540904150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:08.433082104 CET4090425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:08.433764935 CET4090625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:08.553230047 CET2556540904150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:08.553515911 CET2556540906150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:08.553582907 CET4090625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:08.553795099 CET4090625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:08.673640966 CET2556540906150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:10.798532963 CET2556540906150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:10.798743963 CET4090625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:10.799428940 CET4090825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:10.918492079 CET2556540906150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:10.919171095 CET2556540908150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:10.919249058 CET4090825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:10.919357061 CET4090825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:11.039222002 CET2556540908150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:13.119987011 CET2556540908150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:13.120260954 CET4090825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:13.121478081 CET4091025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:13.240129948 CET2556540908150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:13.241225004 CET2556540910150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:13.241353035 CET4091025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:13.241470098 CET4091025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:13.361212015 CET2556540910150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:15.527744055 CET2556540910150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:15.528146029 CET4091025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:15.528664112 CET4091225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:15.647902966 CET2556540910150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:15.648367882 CET2556540912150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:15.648509026 CET4091225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:15.648623943 CET4091225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:15.768400908 CET2556540912150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:17.873025894 CET2556540912150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:17.873275995 CET4091225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:17.873889923 CET4091425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:17.993171930 CET2556540912150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:17.993607998 CET2556540914150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:17.993707895 CET4091425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:17.993880033 CET4091425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:18.115849018 CET2556540914150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:20.198513985 CET2556540914150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:20.198837996 CET4091425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:20.199433088 CET4091625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:20.318763971 CET2556540914150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:20.319173098 CET2556540916150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:20.319273949 CET4091625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:20.319367886 CET4091625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:20.439201117 CET2556540916150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:22.529911995 CET2556540916150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:22.530324936 CET4091625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:22.531259060 CET4091825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:22.650757074 CET2556540916150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:22.651021004 CET2556540918150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:22.651140928 CET4091825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:22.651319981 CET4091825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:22.771440029 CET2556540918150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:24.903084993 CET2556540918150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:24.903247118 CET4091825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:24.903914928 CET4092025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:25.023080111 CET2556540918150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:25.023597002 CET2556540920150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:25.023721933 CET4092025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:25.023902893 CET4092025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:25.143522978 CET2556540920150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:27.278661966 CET2556540920150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:27.279020071 CET4092025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:27.279686928 CET4092225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:27.399101973 CET2556540920150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:27.399841070 CET2556540922150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:27.400058031 CET4092225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:27.400202036 CET4092225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:27.520122051 CET2556540922150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:29.653250933 CET2556540922150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:29.653472900 CET4092225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:29.654205084 CET4092425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:29.773610115 CET2556540922150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:29.774457932 CET2556540924150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:29.774533033 CET4092425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:29.774622917 CET4092425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:29.894392967 CET2556540924150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:31.983707905 CET2556540924150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:31.983876944 CET4092425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:31.983939886 CET4092425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:31.984791040 CET4092625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:32.103940964 CET2556540924150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:32.104688883 CET2556540926150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:32.104809046 CET4092625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:32.104882002 CET4092625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:32.224750042 CET2556540926150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:34.338943005 CET2556540926150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:34.339346886 CET4092625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:34.340101004 CET4092825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:34.459939957 CET2556540926150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:34.460443974 CET2556540928150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:34.460722923 CET4092825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:34.460722923 CET4092825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:34.580553055 CET2556540928150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:36.667267084 CET2556540928150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:36.667530060 CET4092825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:36.668212891 CET4093025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:36.787452936 CET2556540928150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:36.787971973 CET2556540930150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:36.788120985 CET4093025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:36.788255930 CET4093025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:36.908098936 CET2556540930150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:38.995418072 CET2556540930150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:38.995776892 CET4093025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:38.996725082 CET4093225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:39.115860939 CET2556540930150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:39.116553068 CET2556540932150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:39.116652966 CET4093225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:39.116866112 CET4093225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:39.237325907 CET2556540932150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:41.372629881 CET2556540932150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:41.372873068 CET4093225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:41.377198935 CET4093425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:41.493628979 CET2556540932150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:41.499423981 CET2556540934150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:41.499555111 CET4093425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:41.499684095 CET4093425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:41.619391918 CET2556540934150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:43.714370966 CET2556540934150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:43.714719057 CET4093425565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:43.715641975 CET4093625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:43.835870981 CET2556540934150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:43.836787939 CET2556540936150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:43.836915016 CET4093625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:43.837013960 CET4093625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:43.956995010 CET2556540936150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:46.093803883 CET2556540936150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:46.094207048 CET4093625565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:46.094676971 CET4093825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:46.214164019 CET2556540936150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:46.214487076 CET2556540938150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:46.214813948 CET4093825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:46.214813948 CET4093825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:46.335757017 CET2556540938150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:48.453428984 CET2556540938150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:48.453939915 CET4093825565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:48.454773903 CET4094025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:48.573712111 CET2556540938150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:48.574785948 CET2556540940150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:48.574877977 CET4094025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:48.575123072 CET4094025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:48.696094990 CET2556540940150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:50.941428900 CET2556540940150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:50.941606998 CET4094025565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:50.942276955 CET4094225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:51.061537981 CET2556540940150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:51.062088013 CET2556540942150.241.88.132192.168.2.23
                                                                      Dec 16, 2024 13:12:51.062213898 CET4094225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:51.062329054 CET4094225565192.168.2.23150.241.88.132
                                                                      Dec 16, 2024 13:12:51.183980942 CET2556540942150.241.88.132192.168.2.23

                                                                      System Behavior

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/rm
                                                                      Arguments:rm -f /tmp/tmp.25mzlEEvpZ /tmp/tmp.DDq2YkcMbt /tmp/tmp.scdstBQjf3
                                                                      File size:72056 bytes
                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/cat
                                                                      Arguments:cat /tmp/tmp.25mzlEEvpZ
                                                                      File size:43416 bytes
                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/head
                                                                      Arguments:head -n 10
                                                                      File size:47480 bytes
                                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/tr
                                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                      File size:51544 bytes
                                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:09
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/cut
                                                                      Arguments:cut -c -80
                                                                      File size:47480 bytes
                                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/cat
                                                                      Arguments:cat /tmp/tmp.25mzlEEvpZ
                                                                      File size:43416 bytes
                                                                      MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/head
                                                                      Arguments:head -n 10
                                                                      File size:47480 bytes
                                                                      MD5 hash:fd96a67145172477dd57131396fc9608

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/tr
                                                                      Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                                      File size:51544 bytes
                                                                      MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/cut
                                                                      Arguments:cut -c -80
                                                                      File size:47480 bytes
                                                                      MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/dash
                                                                      Arguments:-
                                                                      File size:129816 bytes
                                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                      Start time (UTC):12:09:10
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/usr/bin/rm
                                                                      Arguments:rm -f /tmp/tmp.25mzlEEvpZ /tmp/tmp.DDq2YkcMbt /tmp/tmp.scdstBQjf3
                                                                      File size:72056 bytes
                                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                      Start time (UTC):12:09:17
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/sh4.elf
                                                                      Arguments:/tmp/sh4.elf
                                                                      File size:4139976 bytes
                                                                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                                      Start time (UTC):12:09:17
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/sh4.elf
                                                                      Arguments:-
                                                                      File size:4139976 bytes
                                                                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                                                      Start time (UTC):12:09:17
                                                                      Start date (UTC):16/12/2024
                                                                      Path:/tmp/sh4.elf
                                                                      Arguments:-
                                                                      File size:4139976 bytes
                                                                      MD5 hash:8943e5f8f8c280467b4472c15ae93ba9