Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.x86_64.elf

Overview

General Information

Sample name:Space.x86_64.elf
Analysis ID:1580591
MD5:2a970c08a36bf8f55635f35c36450c39
SHA1:19178136051ca912cb63f3b660aaff2ad1a0acf2
SHA256:24e0c293e85e159f78622bfd49323ffeeae27d8714a4763599eca3d9f0db3979
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "rm" command used to delete files or directories
Sample contains only a LOAD segment without any section mappings
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1580591
Start date and time:2024-12-25 11:29:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 8s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.x86_64.elf
Detection:MAL
Classification:mal64.evad.linELF@0/0@0/0
Command:/tmp/Space.x86_64.elf
PID:6264
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6275, Parent: 4331)
  • rm (PID: 6275, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.tFqBW9n4JQ /tmp/tmp.4cRzMqmGbF /tmp/tmp.nu7u3pCc3Y
  • dash New Fork (PID: 6276, Parent: 4331)
  • rm (PID: 6276, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.tFqBW9n4JQ /tmp/tmp.4cRzMqmGbF /tmp/tmp.nu7u3pCc3Y
  • cleanup
SourceRuleDescriptionAuthorStrings
6266.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6266.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x49b2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
6270.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6270.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Mirai_564b8edaunknownunknown
  • 0x49b2:$a: 83 FE 01 76 12 0F B7 07 83 EE 02 48 83 C7 02 48 01 C1 83 FE 01
6264.1.0000000000400000.0000000000413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xfeb8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfecc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfee0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfef4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xff94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffa8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xffe4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xfff8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1000c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10020:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10034:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10048:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 7 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.x86_64.elfVirustotal: Detection: 36%Perma Link
Source: Space.x86_64.elfReversingLabs: Detection: 50%
Source: Space.x86_64.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:42346 -> 154.216.20.216:3778
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: unknownTCP traffic detected without corresponding DNS query: 154.216.20.216
Source: Space.x86_64.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 39256
Source: unknownNetwork traffic detected: HTTP traffic on port 39256 -> 443

System Summary

barindex
Source: 6266.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6266.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 6270.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6270.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 6264.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6264.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: 6265.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6265.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 6266, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.x86_64.elf PID: 6270, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x400000
Source: 6266.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6266.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 6270.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6270.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 6264.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6264.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: 6265.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6265.1.0000000000400000.0000000000413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 6266, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.x86_64.elf PID: 6270, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1582/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/3088/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1579/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1699/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1335/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1698/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1334/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1576/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/2302/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/910/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/912/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/2307/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/918/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1594/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1349/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1344/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1465/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1586/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1463/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/801/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1900/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/491/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1599/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1477/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/379/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1476/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/6249/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/6248/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/2208/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/35/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/6264/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/6267/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1809/statusJump to behavior
Source: /tmp/Space.x86_64.elf (PID: 6264)File opened: /proc/1494/statusJump to behavior
Source: /usr/bin/dash (PID: 6275)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.tFqBW9n4JQ /tmp/tmp.4cRzMqmGbF /tmp/tmp.nu7u3pCc3YJump to behavior
Source: /usr/bin/dash (PID: 6276)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.tFqBW9n4JQ /tmp/tmp.4cRzMqmGbF /tmp/tmp.nu7u3pCc3YJump to behavior
Source: Space.x86_64.elfSubmission file: segment LOAD with 7.9616 entropy (max. 8.0)
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
System Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1580591 Sample: Space.x86_64.elf Startdate: 25/12/2024 Architecture: LINUX Score: 64 24 154.216.20.216, 3778, 42346, 42348 SKHT-ASShenzhenKatherineHengTechnologyInformationCo Seychelles 2->24 26 109.202.202.202, 80 INIT7CH Switzerland 2->26 28 2 other IPs or domains 2->28 30 Malicious sample detected (through community Yara rule) 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Machine Learning detection for sample 2->34 36 Sample is packed with UPX 2->36 8 Space.x86_64.elf 2->8         started        10 dash rm 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 Space.x86_64.elf 8->14         started        16 Space.x86_64.elf 8->16         started        18 Space.x86_64.elf 8->18         started        process6 20 Space.x86_64.elf 14->20         started        22 Space.x86_64.elf 14->22         started       
SourceDetectionScannerLabelLink
Space.x86_64.elf37%VirustotalBrowse
Space.x86_64.elf50%ReversingLabsLinux.Backdoor.Mirai
Space.x86_64.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.x86_64.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    154.216.20.216
    unknownSeychelles
    135357SKHT-ASShenzhenKatherineHengTechnologyInformationCofalse
    34.249.145.219
    unknownUnited States
    16509AMAZON-02USfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    154.216.20.216Space.arm.elfGet hashmaliciousMiraiBrowse
      Space.mips.elfGet hashmaliciousUnknownBrowse
        Space.mpsl.elfGet hashmaliciousUnknownBrowse
          Space.m68k.elfGet hashmaliciousMiraiBrowse
            Space.i686.elfGet hashmaliciousUnknownBrowse
              34.249.145.219zerm68k.elfGet hashmaliciousUnknownBrowse
                hidakibest.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                  hidakibest.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                    main_mips.elfGet hashmaliciousMiraiBrowse
                      powerpc.elfGet hashmaliciousMiraiBrowse
                        main_arm6.elfGet hashmaliciousMiraiBrowse
                          main_x86.elfGet hashmaliciousMiraiBrowse
                            main_m68k.elfGet hashmaliciousMiraiBrowse
                              Space.mips.elfGet hashmaliciousMiraiBrowse
                                hmips.elfGet hashmaliciousUnknownBrowse
                                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                                  91.189.91.42Space.arc.elfGet hashmaliciousMiraiBrowse
                                    Space.arm5.elfGet hashmaliciousUnknownBrowse
                                      byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                        armv4eb.elfGet hashmaliciousUnknownBrowse
                                          armv5l.elfGet hashmaliciousUnknownBrowse
                                            armv4eb.elfGet hashmaliciousUnknownBrowse
                                              sshd.elfGet hashmaliciousUnknownBrowse
                                                armv4eb.elfGet hashmaliciousMiraiBrowse
                                                  most-arm7.elfGet hashmaliciousMiraiBrowse
                                                    arm5.elfGet hashmaliciousUnknownBrowse
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      CANONICAL-ASGBSpace.arc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      Space.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      Space.arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 91.189.91.42
                                                      armv4eb.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      armv5l.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      armv4eb.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      sshd.elfGet hashmaliciousUnknownBrowse
                                                      • 91.189.91.42
                                                      loligang.arm5.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      armv4eb.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      SKHT-ASShenzhenKatherineHengTechnologyInformationCoSpace.arm.elfGet hashmaliciousMiraiBrowse
                                                      • 154.216.20.216
                                                      Space.mips.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.20.216
                                                      Space.mpsl.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.20.216
                                                      Space.m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 154.216.20.216
                                                      Space.i686.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.20.216
                                                      byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 154.216.19.138
                                                      zerarm7.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.16.250
                                                      nabm68k.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.16.244
                                                      nabarm.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.16.244
                                                      zerppc.elfGet hashmaliciousUnknownBrowse
                                                      • 154.216.16.250
                                                      INIT7CHSpace.arc.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      Space.arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      byte.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 109.202.202.202
                                                      armv4eb.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      armv5l.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      armv4eb.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      sshd.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      armv4eb.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      most-arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      arm5.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      AMAZON-02USbyte.x86.elfGet hashmaliciousMirai, OkiruBrowse
                                                      • 54.171.230.55
                                                      armv4l.elfGet hashmaliciousUnknownBrowse
                                                      • 52.221.127.63
                                                      armv4eb.elfGet hashmaliciousUnknownBrowse
                                                      • 54.171.230.55
                                                      telnet.x86.elfGet hashmaliciousUnknownBrowse
                                                      • 54.154.23.188
                                                      https://email.equifaxbreachsettlement.com/c/eJwUys9qtDAQAPCnSY6STLL_DjnIp4GFr-3iLrX0EuLMiMLqWo1r-_al9x-5yDrGo2SnD8YednvYK9m5lhEPSJpaYtPgDk-NUUQKCS3r2MjegQKrAbSy1oLKWmC1UycbkU9asxZW8dfat_G7mTlit3BKdx54TBk-Bnl3XUrTIkwuwAvw27Zlw8808xR7Qh4Tz39OgJ-ZmAdhPOODWJiihuP7y__al5_1Vc5uoPhMfRyFVeuCGdMqkyv9R7hUb6HKb3m4VOUlPxfhX14VoThfb-Favhby6eA3AAD__0qSUF8Get hashmaliciousUnknownBrowse
                                                      • 18.221.139.220
                                                      http://assets.website-files.com/65efffe8d4e10d26910f0543/65f65633ab8b2f021b357c18_64146967722.pdfGet hashmaliciousUnknownBrowse
                                                      • 52.211.121.244
                                                      armv5l.elfGet hashmaliciousMiraiBrowse
                                                      • 52.11.1.37
                                                      armv6l.elfGet hashmaliciousMiraiBrowse
                                                      • 13.210.214.39
                                                      loligang.mpsl.elfGet hashmaliciousMiraiBrowse
                                                      • 65.1.40.160
                                                      loligang.arm.elfGet hashmaliciousMiraiBrowse
                                                      • 13.243.198.228
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
                                                      Entropy (8bit):7.959533434504921
                                                      TrID:
                                                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                      File name:Space.x86_64.elf
                                                      File size:37'540 bytes
                                                      MD5:2a970c08a36bf8f55635f35c36450c39
                                                      SHA1:19178136051ca912cb63f3b660aaff2ad1a0acf2
                                                      SHA256:24e0c293e85e159f78622bfd49323ffeeae27d8714a4763599eca3d9f0db3979
                                                      SHA512:671d7a2cce48f7d3716d53b7c4bd365aeba2972101935aa2b5d5f637a7b888caf0e138db9c52c2a0a4e7359eb9909c04563110bc9db9110c8b649c9b9d63039f
                                                      SSDEEP:768:F+4qtvWUAASje6lhaVG5CHb4diYjLMWf5CcWHdbL5fPr8J75Wx0S:A9tvWrASje4wVGigJmFL578J7AD
                                                      TLSH:AAF2E092D56AD53CD9336E7000D65A28DB32E0B08443976B0FED67EF5EAEA043D0E780
                                                      File Content Preview:.ELF..............>.....`.@.....@...................@.8...@.......................@.......@....................... ......................Ka......Ka.............................Q.td.....................................................I..UPX!D.......8:..8:.

                                                      ELF header

                                                      Class:ELF64
                                                      Data:2's complement, little endian
                                                      Version:1 (current)
                                                      Machine:Advanced Micro Devices X86-64
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:UNIX - System V
                                                      ABI Version:0
                                                      Entry Point Address:0x408060
                                                      Flags:0x0
                                                      ELF Header Size:64
                                                      Program Header Offset:64
                                                      Program Header Size:56
                                                      Number of Program Headers:3
                                                      Section Header Offset:0
                                                      Section Header Size:64
                                                      Number of Section Headers:0
                                                      Header String Table Index:0
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x4000000x4000000x919c0x919c7.96160x5R E0x200000
                                                      LOAD0xb000x614b000x614b000x00x00.00000x6RW 0x1000
                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Dec 25, 2024 11:30:24.040837049 CET423463778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:24.160486937 CET377842346154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:24.160562038 CET423463778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:24.161516905 CET423463778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:24.281089067 CET377842346154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:24.281164885 CET423463778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:24.400752068 CET377842346154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:24.496294975 CET43928443192.168.2.2391.189.91.42
                                                      Dec 25, 2024 11:30:25.464489937 CET377842346154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:25.464705944 CET423463778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:25.464797020 CET423463778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:25.465480089 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:25.584989071 CET377842348154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:25.585144997 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:25.586061001 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:25.705569983 CET377842348154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:25.705764055 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:25.825335979 CET377842348154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:29.521990061 CET423503778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:29.642677069 CET377842350154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:29.642865896 CET423503778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:29.643774033 CET423503778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:29.763299942 CET377842350154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:29.763488054 CET423503778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:29.887033939 CET377842350154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:30.939862013 CET377842350154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:30.940033913 CET423503778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:30.940033913 CET423503778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:30.940732002 CET423523778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:31.060421944 CET377842352154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:31.060789108 CET423523778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:31.061482906 CET423523778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:31.180996895 CET377842352154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:31.181304932 CET423523778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:31.300987005 CET377842352154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:32.362301111 CET377842352154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:32.362483978 CET423523778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:32.362526894 CET423523778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:32.363146067 CET423543778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:32.482640982 CET377842354154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:32.482779980 CET423543778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:32.483660936 CET423543778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:32.603243113 CET377842354154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:32.603404045 CET423543778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:32.722985983 CET377842354154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:33.781807899 CET377842354154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:33.781953096 CET423543778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:33.781953096 CET423543778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:33.782444954 CET423563778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:33.902055025 CET377842356154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:33.902148008 CET423563778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:33.902879953 CET423563778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:34.022521973 CET377842356154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:34.022618055 CET423563778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:34.142558098 CET377842356154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:35.202779055 CET377842356154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:35.202950954 CET423563778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:35.202950954 CET423563778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:35.203794956 CET423583778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:35.323383093 CET377842358154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:35.323823929 CET423583778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:35.330480099 CET423583778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:35.450045109 CET377842358154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:35.450175047 CET423583778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:35.569729090 CET377842358154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:35.591155052 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:35.710748911 CET377842348154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:36.010787010 CET377842348154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:36.011100054 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:36.623693943 CET377842358154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:36.623991013 CET423583778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:36.624038935 CET423583778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:36.624655008 CET423603778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:36.744273901 CET377842360154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:36.744518042 CET423603778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:36.745629072 CET423603778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:36.865164995 CET377842360154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:36.865443945 CET423603778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:36.985033989 CET377842360154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:37.584378004 CET4433925634.249.145.219192.168.2.23
                                                      Dec 25, 2024 11:30:37.584609985 CET39256443192.168.2.2334.249.145.219
                                                      Dec 25, 2024 11:30:37.704086065 CET4433925634.249.145.219192.168.2.23
                                                      Dec 25, 2024 11:30:38.043951988 CET377842360154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:38.044197083 CET423603778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:38.044251919 CET423603778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:38.045038939 CET423623778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:38.164625883 CET377842362154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:38.164747000 CET423623778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:38.165656090 CET423623778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:38.286762953 CET377842362154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:38.286873102 CET423623778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:38.406671047 CET377842362154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:39.468871117 CET377842362154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:39.469012022 CET423623778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:39.469012022 CET423623778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:39.469583035 CET423643778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:39.589133978 CET377842364154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:39.589251041 CET423643778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:39.590040922 CET423643778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:39.709693909 CET377842364154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:39.709898949 CET423643778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:39.829592943 CET377842364154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:40.878249884 CET4251680192.168.2.23109.202.202.202
                                                      Dec 25, 2024 11:30:40.887511969 CET377842364154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:40.887697935 CET423643778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:40.887762070 CET423643778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:40.888525009 CET423663778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:41.008200884 CET377842366154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:41.008344889 CET423663778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:41.009763956 CET423663778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:41.129302025 CET377842366154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:41.129435062 CET423663778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:41.249138117 CET377842366154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:42.307476044 CET377842366154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:42.307615995 CET423663778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:42.307655096 CET423663778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:42.308296919 CET423683778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:42.427798033 CET377842368154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:42.427889109 CET423683778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:42.428834915 CET423683778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:42.548434973 CET377842368154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:42.548521996 CET423683778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:42.668184042 CET377842368154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:43.727334976 CET377842368154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:43.727488041 CET423683778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:43.727488041 CET423683778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:43.728044987 CET423703778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:43.848186970 CET377842370154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:43.848294020 CET423703778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:43.849153042 CET423703778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:43.968657017 CET377842370154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:43.968769073 CET423703778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:44.088675976 CET377842370154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:44.973649979 CET43928443192.168.2.2391.189.91.42
                                                      Dec 25, 2024 11:30:45.145608902 CET377842370154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:45.145740032 CET423703778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:45.145776033 CET423703778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:45.146426916 CET423723778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:45.266455889 CET377842372154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:45.266565084 CET423723778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:45.267416000 CET423723778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:45.387058973 CET377842372154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:45.387212038 CET423723778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:45.506992102 CET377842372154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:46.566716909 CET377842372154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:46.566939116 CET423723778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:46.566939116 CET423723778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:46.567542076 CET423743778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:46.687232971 CET377842374154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:46.687530041 CET423743778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:46.688925982 CET423743778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:46.808517933 CET377842374154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:46.808665037 CET423743778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:46.928306103 CET377842374154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:47.988661051 CET377842374154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:47.988796949 CET423743778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:47.988796949 CET423743778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:47.989435911 CET423763778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:48.108971119 CET377842376154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:48.109097958 CET423763778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:48.110419989 CET423763778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:48.230027914 CET377842376154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:48.230199099 CET423763778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:48.349957943 CET377842376154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:49.407880068 CET377842376154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:49.408065081 CET423763778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:49.408139944 CET423763778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:49.408911943 CET423783778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:49.528359890 CET377842378154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:49.528589010 CET423783778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:49.529867887 CET423783778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:49.649346113 CET377842378154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:49.649482012 CET423783778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:49.769011021 CET377842378154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:50.827512980 CET377842378154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:50.827917099 CET423783778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:50.827980042 CET423783778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:50.828754902 CET423803778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:50.948396921 CET377842380154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:50.948659897 CET423803778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:50.950022936 CET423803778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:51.069617033 CET377842380154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:51.069845915 CET423803778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:51.189631939 CET377842380154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:52.245413065 CET377842380154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:52.245628119 CET423803778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:52.245709896 CET423803778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:52.246495962 CET423823778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:52.366074085 CET377842382154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:52.366189957 CET423823778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:52.367428064 CET423823778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:52.487025976 CET377842382154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:52.487185001 CET423823778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:52.606771946 CET377842382154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:53.664758921 CET377842382154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:53.665025949 CET423823778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:53.665112019 CET423823778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:53.665770054 CET423843778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:53.785401106 CET377842384154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:53.785649061 CET423843778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:53.786828995 CET423843778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:53.906502008 CET377842384154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:53.906765938 CET423843778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:54.026354074 CET377842384154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:55.085246086 CET377842384154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:55.085465908 CET423843778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:55.085465908 CET423843778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:55.086189032 CET423863778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:55.205687046 CET377842386154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:55.205957890 CET423863778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:55.207223892 CET423863778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:55.326874971 CET377842386154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:55.327003956 CET423863778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:55.446955919 CET377842386154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:56.504337072 CET377842386154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:56.504460096 CET423863778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:56.504668951 CET423863778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:56.505369902 CET423883778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:56.624948025 CET377842388154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:56.625030041 CET423883778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:56.625668049 CET423883778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:56.745228052 CET377842388154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:56.745358944 CET423883778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:56.864976883 CET377842388154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:57.924429893 CET377842388154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:57.924560070 CET423883778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:57.924598932 CET423883778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:57.925306082 CET423903778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:58.045228004 CET377842390154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:58.045382977 CET423903778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:58.046478987 CET423903778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:58.166032076 CET377842390154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:58.166167021 CET423903778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:58.285792112 CET377842390154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:59.345125914 CET377842390154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:59.345437050 CET423903778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:59.345490932 CET423903778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:59.346277952 CET423923778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:59.465871096 CET377842392154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:59.466146946 CET423923778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:59.467422962 CET423923778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:59.587086916 CET377842392154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:30:59.587168932 CET423923778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:30:59.706768990 CET377842392154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:00.771250010 CET377842392154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:00.771485090 CET423923778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:00.771655083 CET423923778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:00.772399902 CET423943778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:00.893651009 CET377842394154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:00.893913984 CET423943778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:00.895132065 CET423943778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:01.014823914 CET377842394154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:01.015065908 CET423943778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:01.134710073 CET377842394154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:02.195899010 CET377842394154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:02.196058035 CET423943778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:02.196124077 CET423943778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:02.196899891 CET423963778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:02.316400051 CET377842396154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:02.316634893 CET423963778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:02.317967892 CET423963778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:02.437586069 CET377842396154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:02.437786102 CET423963778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:02.557378054 CET377842396154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:03.618896961 CET377842396154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:03.619127035 CET423963778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:03.619277954 CET423963778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:03.620086908 CET423983778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:03.739626884 CET377842398154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:03.739732027 CET423983778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:03.740885973 CET423983778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:03.860941887 CET377842398154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:03.861057043 CET423983778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:03.980710983 CET377842398154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:05.041728020 CET377842398154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:05.041924953 CET423983778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:05.041966915 CET423983778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:05.042550087 CET424003778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:05.162482023 CET377842400154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:05.162606955 CET424003778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:05.163604021 CET424003778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:05.283360958 CET377842400154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:05.283555984 CET424003778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:05.403177977 CET377842400154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:06.469300032 CET377842400154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:06.469598055 CET424003778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:06.469599009 CET424003778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:06.470225096 CET424023778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:06.589798927 CET377842402154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:06.589955091 CET424023778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:06.591356993 CET424023778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:06.710913897 CET377842402154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:06.711072922 CET424023778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:06.831162930 CET377842402154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:07.890108109 CET377842402154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:07.890471935 CET424023778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:07.890551090 CET424023778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:07.891369104 CET424043778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:08.011010885 CET377842404154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:08.011221886 CET424043778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:08.012964964 CET424043778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:08.132867098 CET377842404154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:08.133143902 CET424043778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:08.252860069 CET377842404154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:09.310256004 CET377842404154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:09.310486078 CET424043778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:09.310537100 CET424043778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:09.311371088 CET424063778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:09.430978060 CET377842406154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:09.431243896 CET424063778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:09.432667017 CET424063778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:09.552187920 CET377842406154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:09.552350998 CET424063778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:09.672018051 CET377842406154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:10.729996920 CET377842406154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:10.730273008 CET424063778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:10.730324984 CET424063778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:10.731261015 CET424083778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:10.851340055 CET377842408154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:10.851665020 CET424083778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:10.853111982 CET424083778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:10.972713947 CET377842408154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:10.972956896 CET424083778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:11.092581034 CET377842408154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:12.152542114 CET377842408154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:12.152704954 CET424083778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:12.152704954 CET424083778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:12.153549910 CET424103778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:12.273111105 CET377842410154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:12.273370981 CET424103778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:12.274945974 CET424103778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:12.394413948 CET377842410154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:12.394673109 CET424103778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:12.514570951 CET377842410154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:13.571947098 CET377842410154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:13.572473049 CET424103778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:13.572473049 CET424103778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:13.573846102 CET424123778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:13.693948984 CET377842412154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:13.694195032 CET424123778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:13.696137905 CET424123778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:13.815628052 CET377842412154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:13.815891981 CET424123778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:13.935731888 CET377842412154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:14.991895914 CET377842412154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:14.992075920 CET424123778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:14.992120028 CET424123778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:14.992923021 CET424143778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:15.112561941 CET377842414154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:15.112741947 CET424143778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:15.114257097 CET424143778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:15.234054089 CET377842414154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:15.234214067 CET424143778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:15.354119062 CET377842414154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:16.413544893 CET377842414154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:16.413656950 CET424143778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:16.413685083 CET424143778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:16.414336920 CET424163778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:16.533853054 CET377842416154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:16.534008026 CET424163778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:16.534746885 CET424163778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:16.654267073 CET377842416154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:16.654568911 CET424163778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:16.774734020 CET377842416154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:17.832151890 CET377842416154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:17.832310915 CET424163778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:17.832458973 CET424163778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:17.833343029 CET424183778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:17.952951908 CET377842418154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:17.953053951 CET424183778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:17.954329967 CET424183778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:18.074043036 CET377842418154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:18.074227095 CET424183778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:18.193819046 CET377842418154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:19.254904032 CET377842418154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:19.255151033 CET424183778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:19.255301952 CET424183778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:19.256022930 CET424203778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:19.375535965 CET377842420154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:19.375740051 CET424203778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:19.376856089 CET424203778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:19.496438980 CET377842420154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:19.496666908 CET424203778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:19.616209030 CET377842420154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:20.675513983 CET377842420154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:20.675688028 CET424203778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:20.675853014 CET424203778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:20.676613092 CET424223778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:20.796206951 CET377842422154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:20.796298981 CET424223778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:20.797343969 CET424223778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:20.916779995 CET377842422154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:20.916878939 CET424223778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:21.036581993 CET377842422154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:22.102181911 CET377842422154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:22.102320910 CET424223778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:22.102507114 CET424223778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:22.103177071 CET424243778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:22.222688913 CET377842424154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:22.222836971 CET424243778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:22.224277973 CET424243778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:22.343868017 CET377842424154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:22.344063997 CET424243778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:22.463654041 CET377842424154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:23.522958994 CET377842424154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:23.523262978 CET424243778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:23.523263931 CET424243778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:23.523947954 CET424263778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:23.643534899 CET377842426154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:23.643862963 CET424263778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:23.644844055 CET424263778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:23.764452934 CET377842426154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:23.764735937 CET424263778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:23.884430885 CET377842426154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:24.943720102 CET377842426154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:24.943917990 CET424263778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:24.943952084 CET424263778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:24.944495916 CET424283778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:25.064127922 CET377842428154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:25.064398050 CET424283778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:25.065201044 CET424283778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:25.184864044 CET377842428154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:25.185105085 CET424283778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:25.304824114 CET377842428154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:25.928308010 CET43928443192.168.2.2391.189.91.42
                                                      Dec 25, 2024 11:31:26.363719940 CET377842428154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:26.364043951 CET424283778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:26.364114046 CET424283778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:26.364829063 CET424303778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:26.484497070 CET377842430154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:26.484632015 CET424303778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:26.485920906 CET424303778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:26.605475903 CET377842430154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:26.605739117 CET424303778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:26.725291967 CET377842430154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:27.783911943 CET377842430154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:27.784235001 CET424303778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:27.784372091 CET424303778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:27.785150051 CET424323778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:27.905069113 CET377842432154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:27.905313015 CET424323778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:27.906694889 CET424323778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:28.026299953 CET377842432154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:28.026602030 CET424323778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:28.146723986 CET377842432154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:36.048016071 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:36.168174982 CET377842348154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:36.472665071 CET377842348154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:36.472776890 CET423483778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:37.915509939 CET424323778192.168.2.23154.216.20.216
                                                      Dec 25, 2024 11:31:38.035458088 CET377842432154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:38.336432934 CET377842432154.216.20.216192.168.2.23
                                                      Dec 25, 2024 11:31:38.336570024 CET424323778192.168.2.23154.216.20.216

                                                      System Behavior

                                                      Start time (UTC):10:30:23
                                                      Start date (UTC):25/12/2024
                                                      Path:/tmp/Space.x86_64.elf
                                                      Arguments:/tmp/Space.x86_64.elf
                                                      File size:37540 bytes
                                                      MD5 hash:2a970c08a36bf8f55635f35c36450c39

                                                      Start time (UTC):10:30:23
                                                      Start date (UTC):25/12/2024
                                                      Path:/tmp/Space.x86_64.elf
                                                      Arguments:-
                                                      File size:37540 bytes
                                                      MD5 hash:2a970c08a36bf8f55635f35c36450c39

                                                      Start time (UTC):10:30:23
                                                      Start date (UTC):25/12/2024
                                                      Path:/tmp/Space.x86_64.elf
                                                      Arguments:-
                                                      File size:37540 bytes
                                                      MD5 hash:2a970c08a36bf8f55635f35c36450c39

                                                      Start time (UTC):10:30:23
                                                      Start date (UTC):25/12/2024
                                                      Path:/tmp/Space.x86_64.elf
                                                      Arguments:-
                                                      File size:37540 bytes
                                                      MD5 hash:2a970c08a36bf8f55635f35c36450c39

                                                      Start time (UTC):10:30:28
                                                      Start date (UTC):25/12/2024
                                                      Path:/tmp/Space.x86_64.elf
                                                      Arguments:-
                                                      File size:37540 bytes
                                                      MD5 hash:2a970c08a36bf8f55635f35c36450c39

                                                      Start time (UTC):10:30:28
                                                      Start date (UTC):25/12/2024
                                                      Path:/tmp/Space.x86_64.elf
                                                      Arguments:-
                                                      File size:37540 bytes
                                                      MD5 hash:2a970c08a36bf8f55635f35c36450c39

                                                      Start time (UTC):10:30:36
                                                      Start date (UTC):25/12/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):10:30:36
                                                      Start date (UTC):25/12/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.tFqBW9n4JQ /tmp/tmp.4cRzMqmGbF /tmp/tmp.nu7u3pCc3Y
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                      Start time (UTC):10:30:36
                                                      Start date (UTC):25/12/2024
                                                      Path:/usr/bin/dash
                                                      Arguments:-
                                                      File size:129816 bytes
                                                      MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                      Start time (UTC):10:30:36
                                                      Start date (UTC):25/12/2024
                                                      Path:/usr/bin/rm
                                                      Arguments:rm -f /tmp/tmp.tFqBW9n4JQ /tmp/tmp.4cRzMqmGbF /tmp/tmp.nu7u3pCc3Y
                                                      File size:72056 bytes
                                                      MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b