Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
ub8ehJSePAfc9FYqZIT6.m68k.elf

Overview

General Information

Sample name:ub8ehJSePAfc9FYqZIT6.m68k.elf
Analysis ID:1581064
MD5:66a180c32017012ec4c189f8494242fa
SHA1:274219448fda71b2808e39da6b27cfffcadfd38b
SHA256:45570708bdd25741bfdeece0da98498174385ebb2182590e76ccbfcd763f617b
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581064
Start date and time:2024-12-26 22:02:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:ub8ehJSePAfc9FYqZIT6.m68k.elf
Detection:MAL
Classification:mal72.troj.linELF@0/0@0/0
  • VT rate limit hit for: ub8ehJSePAfc9FYqZIT6.m68k.elf
Command:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
PID:5483
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
ub8ehJSePAfc9FYqZIT6.m68k.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    ub8ehJSePAfc9FYqZIT6.m68k.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    SourceRuleDescriptionAuthorStrings
    5487.1.00007f7164001000.00007f7164019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      5487.1.00007f7164001000.00007f7164019000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      5497.1.00007f7164001000.00007f7164019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        5497.1.00007f7164001000.00007f7164019000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x151af:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151c3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151d7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151eb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x151ff:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15213:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15227:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1523b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1524f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15263:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15277:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1528b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1529f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152b3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152c7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152db:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x152ef:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15303:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x15317:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1532b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1533f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        5485.1.00007f7164001000.00007f7164019000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          Click to see the 11 entries
          No Suricata rule has matched

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elfAvira: detected
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elfReversingLabs: Detection: 65%
          Source: global trafficTCP traffic: 192.168.2.14:55782 -> 92.118.56.167:3778
          Source: global trafficTCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownTCP traffic detected without corresponding DNS query: 92.118.56.167
          Source: unknownNetwork traffic detected: HTTP traffic on port 46540 -> 443

          System Summary

          barindex
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5487.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5497.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5485.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5483.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5483, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5485, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5487, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5497, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Initial sampleString containing 'busybox' found: /bin/busybox
          Source: Initial sampleString containing 'busybox' found: /proc/net/tcp.x86.x86_64.arm.arm5.arm6.arm7.mips.mipsel.sh4.ppc/proc/proc/%d/exe/proc/%s/statusName:%s/bin/busybox/bin/systemd/usr/bintest/tmp/condi/tmp/zxcr9999/tmp/condinetwork/var/condibot/var/zxcr9999/var/CondiBot/var/condinet/bin/watchdog92.118.56.167
          Source: ELF static info symbol of initial sample.symtab present: no
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5487.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5497.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5485.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5483.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5483, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5485, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5487, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5497, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: classification engineClassification label: mal72.troj.linELF@0/0@0/0
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1583/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/2672/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/110/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/111/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/112/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/113/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/234/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1577/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/114/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/235/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/115/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/116/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/117/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/118/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/119/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3752/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3753/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3754/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3755/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/10/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/917/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/11/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/12/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/13/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/14/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/15/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/16/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/17/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/18/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/19/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1593/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/240/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/120/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3094/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/121/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/242/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3406/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/122/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/243/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/2/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/123/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/244/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1589/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/124/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/245/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1588/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/125/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/4/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/246/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3402/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/126/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/5/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/247/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/127/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/6/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/248/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/128/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/7/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/249/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/8/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/129/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/800/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/9/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/801/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/803/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/20/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/806/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/21/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/807/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/928/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/22/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/23/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/24/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/25/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/26/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/27/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/28/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/29/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3420/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/490/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/250/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/130/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/251/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/131/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/252/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/132/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/253/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/254/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/255/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/135/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/256/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1599/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/257/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/378/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/258/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/3412/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/259/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/30/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/35/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/1371/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/260/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/261/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)File opened: /proc/262/statusJump to behavior
          Source: /tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf (PID: 5483)Queries kernel information via 'uname': Jump to behavior
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elf, 5483.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5485.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5487.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5497.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmpBinary or memory string: /usr/bin/qemu-m68k
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elf, 5483.1.0000555baedfa000.0000555baee82000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5485.1.0000555baedfa000.0000555baee5e000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5487.1.0000555baedfa000.0000555baee5e000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5497.1.0000555baedfa000.0000555baee82000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/m68k
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elf, 5483.1.0000555baedfa000.0000555baee82000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5485.1.0000555baedfa000.0000555baee5e000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5487.1.0000555baedfa000.0000555baee5e000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5497.1.0000555baedfa000.0000555baee82000.rw-.sdmpBinary or memory string: [U!/etc/qemu-binfmt/m68k
          Source: ub8ehJSePAfc9FYqZIT6.m68k.elf, 5483.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5485.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5487.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmp, ub8ehJSePAfc9FYqZIT6.m68k.elf, 5497.1.00007ffc33b91000.00007ffc33bb2000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-m68k/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: ub8ehJSePAfc9FYqZIT6.m68k.elf, type: SAMPLE
          Source: Yara matchFile source: 5487.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5497.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5485.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5483.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5483, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5485, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5487, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5497, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: ub8ehJSePAfc9FYqZIT6.m68k.elf, type: SAMPLE
          Source: Yara matchFile source: 5487.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5497.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5485.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5483.1.00007f7164001000.00007f7164019000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5483, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5485, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5487, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: ub8ehJSePAfc9FYqZIT6.m68k.elf PID: 5497, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume Access1
          OS Credential Dumping
          11
          Security Software Discovery
          Remote ServicesData from Local System1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          No configs have been found
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          SourceDetectionScannerLabelLink
          ub8ehJSePAfc9FYqZIT6.m68k.elf66%ReversingLabsLinux.Trojan.Mirai
          ub8ehJSePAfc9FYqZIT6.m68k.elf100%AviraLINUX/Mirai.bonb
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          No contacted domains info
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          185.125.190.26
          unknownUnited Kingdom
          41231CANONICAL-ASGBfalse
          92.118.56.167
          unknownGermany
          9009M247GBfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          185.125.190.26boatnet.ppc.elfGet hashmaliciousMiraiBrowse
            boatnet.arm7.elfGet hashmaliciousMiraiBrowse
              byte.arm5.elfGet hashmaliciousUnknownBrowse
                wlw68k.elfGet hashmaliciousMiraiBrowse
                  main_mips.elfGet hashmaliciousMiraiBrowse
                    main_x86.elfGet hashmaliciousMiraiBrowse
                      Aqua.mpsl.elfGet hashmaliciousUnknownBrowse
                        Aqua.x86.elfGet hashmaliciousUnknownBrowse
                          Aqua.i686.elfGet hashmaliciousUnknownBrowse
                            Aqua.ppc.elfGet hashmaliciousUnknownBrowse
                              92.118.56.167ub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                  No context
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  CANONICAL-ASGBwin.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  .i.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                  • 185.125.190.26
                                  boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                  • 91.189.91.42
                                  boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                  • 185.125.190.26
                                  boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                  • 91.189.91.42
                                  boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                  • 91.189.91.42
                                  most-m68k.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  sshd.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  bin.sh.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  M247GBub8ehJSePAfc9FYqZIT6.i686.elfGet hashmaliciousUnknownBrowse
                                  • 92.118.56.167
                                  ub8ehJSePAfc9FYqZIT6.x86.elfGet hashmaliciousUnknownBrowse
                                  • 92.118.56.167
                                  http://au.kirmalk.com/watch.php?vid=7750fd3c8Get hashmaliciousUnknownBrowse
                                  • 38.132.109.126
                                  nklppc.elfGet hashmaliciousUnknownBrowse
                                  • 193.160.72.174
                                  https://en.newsnowbangla.com/archives/69912Get hashmaliciousHTMLPhisher, TechSupportScamBrowse
                                  • 45.10.162.162
                                  arm.elfGet hashmaliciousUnknownBrowse
                                  • 92.249.48.36
                                  powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 38.204.189.65
                                  hmips.elfGet hashmaliciousMiraiBrowse
                                  • 38.207.37.102
                                  nshppc.elfGet hashmaliciousMiraiBrowse
                                  • 185.120.145.21
                                  la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                                  • 196.18.78.47
                                  No context
                                  No context
                                  No created / dropped files found
                                  File type:ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
                                  Entropy (8bit):6.276114470513515
                                  TrID:
                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                  File name:ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  File size:97'552 bytes
                                  MD5:66a180c32017012ec4c189f8494242fa
                                  SHA1:274219448fda71b2808e39da6b27cfffcadfd38b
                                  SHA256:45570708bdd25741bfdeece0da98498174385ebb2182590e76ccbfcd763f617b
                                  SHA512:eb9d5f5f796b50b454f8f4b51ca414a72224d7c72867c9f62816a8f4d491d8487855ac6a318ec291e4698eed21677f2521507b33a83e6808389232d5eaa5663a
                                  SSDEEP:1536:ry9srCNMjSqaNElmnwzX8/EqXabQeuacWjcW0JcWcBl4rZpipI4WlV/N4zfVZol+:ryqrzjSq+OXqqbQeuacWjcW0JcWcBSrO
                                  TLSH:809329C7F811ED7EF80BD67748A34D0E7571F2A00A930A327767BA67AC760A5141BD82
                                  File Content Preview:.ELF.......................D...4..{......4. ...(......................x...x....... .......x............x..*....... .dt.Q............................NV..a....da...P N^NuNV..J9...@f>"y.... QJ.g.X.#.....N."y.... QJ.f.A.....J.g.Hy....N.X........@N^NuNV..N^NuN

                                  ELF header

                                  Class:ELF32
                                  Data:2's complement, big endian
                                  Version:1 (current)
                                  Machine:MC68000
                                  Version Number:0x1
                                  Type:EXEC (Executable file)
                                  OS/ABI:UNIX - System V
                                  ABI Version:0
                                  Entry Point Address:0x80000144
                                  Flags:0x0
                                  ELF Header Size:52
                                  Program Header Offset:52
                                  Program Header Size:32
                                  Number of Program Headers:3
                                  Section Header Offset:97152
                                  Section Header Size:40
                                  Number of Section Headers:10
                                  Header String Table Index:9
                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                  NULL0x00x00x00x00x0000
                                  .initPROGBITS0x800000940x940x140x00x6AX002
                                  .textPROGBITS0x800000a80xa80x1504a0x00x6AX004
                                  .finiPROGBITS0x800150f20x150f20xe0x00x6AX002
                                  .rodataPROGBITS0x800151000x151000x27c10x00x2A002
                                  .ctorsPROGBITS0x800198c80x178c80x80x00x3WA004
                                  .dtorsPROGBITS0x800198d00x178d00x80x00x3WA004
                                  .dataPROGBITS0x800198dc0x178dc0x2640x00x3WA004
                                  .bssNOBITS0x80019b400x17b400x28180x00x3WA004
                                  .shstrtabSTRTAB0x00x17b400x3e0x00x0001
                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                  LOAD0x00x800000000x800000000x178c10x178c16.29170x5R E0x2000.init .text .fini .rodata
                                  LOAD0x178c80x800198c80x800198c80x2780x2a903.65170x6RW 0x2000.ctors .dtors .data .bss
                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                  TimestampSource PortDest PortSource IPDest IP
                                  Dec 26, 2024 22:02:51.623198032 CET557823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:51.893619061 CET37785578292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:51.893717051 CET557823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:51.895474911 CET557823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:52.014880896 CET37785578292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:52.014924049 CET557823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:52.134398937 CET37785578292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:53.157857895 CET37785578292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:53.158396959 CET557823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:53.158396959 CET557823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:53.159070969 CET557843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:53.278642893 CET37785578492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:53.278922081 CET557843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:53.279983997 CET557843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:53.399496078 CET37785578492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:53.399595976 CET557843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:53.519067049 CET37785578492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:54.510026932 CET37785578492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:54.510525942 CET557843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:54.510525942 CET557843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:54.510838985 CET557863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:54.630335093 CET37785578692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:54.633678913 CET557863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:54.633678913 CET557863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:54.753484964 CET37785578692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:54.753693104 CET557863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:54.873167038 CET37785578692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:55.866508007 CET37785578692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:55.866660118 CET557863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:55.866660118 CET557863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:55.867264986 CET557883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:55.986749887 CET37785578892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:55.987010002 CET557883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:55.988078117 CET557883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:56.107597113 CET37785578892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:56.107696056 CET557883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:56.227471113 CET37785578892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:57.231489897 CET37785578892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:57.231654882 CET557883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:57.231654882 CET557883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:57.232224941 CET557903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:57.351834059 CET37785579092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:57.351933956 CET557903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:57.353136063 CET557903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:57.472631931 CET37785579092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:57.472707033 CET557903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:57.592273951 CET37785579092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:58.052848101 CET557923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.172480106 CET37785579292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:58.172540903 CET557923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.174458027 CET557923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.293965101 CET37785579292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:58.294240952 CET557923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.413733959 CET37785579292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:58.588402033 CET37785579092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:58.588785887 CET557903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.588785887 CET557903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.589335918 CET557943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.708781958 CET37785579492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:58.709001064 CET557943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.709970951 CET557943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.829399109 CET37785579492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:58.829483032 CET557943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:58.949037075 CET37785579492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:59.405711889 CET37785579292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:59.405988932 CET557923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.406363010 CET557923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.407084942 CET557963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.526650906 CET37785579692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:59.526880980 CET557963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.527981043 CET557963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.647603035 CET37785579692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:59.647831917 CET557963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.768476963 CET37785579692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:59.939564943 CET37785579492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:02:59.939929008 CET557943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.939929008 CET557943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:02:59.940572023 CET557983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.060180902 CET37785579892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:00.060293913 CET557983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.061460972 CET557983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.180989027 CET37785579892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:00.181315899 CET557983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.554035902 CET557983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.752301931 CET37785579892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:00.752336979 CET37785579892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:00.761358976 CET37785579692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:00.761584997 CET557963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.761584997 CET557963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.762250900 CET558003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.881916046 CET37785580092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:00.882076025 CET558003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:00.883181095 CET558003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.004671097 CET37785580092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:01.004757881 CET558003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.125658035 CET37785580092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:01.292560101 CET37785579892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:01.292855978 CET557983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.292855978 CET557983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.294162035 CET558023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.413633108 CET37785580292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:01.413933992 CET558023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.414793015 CET558023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.534339905 CET37785580292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:01.534420967 CET558023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:01.654052019 CET37785580292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.120280981 CET37785580092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.120534897 CET558003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.120534897 CET558003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.121226072 CET558043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.240829945 CET37785580492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.240951061 CET558043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.242018938 CET558043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.361583948 CET37785580492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.361901045 CET558043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.481452942 CET37785580492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.652453899 CET37785580292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.652910948 CET558023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.652910948 CET558023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.653534889 CET558063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.773145914 CET37785580692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.773412943 CET558063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.774346113 CET558063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:02.893851995 CET37785580692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:02.894171953 CET558063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:03.013688087 CET37785580692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:03.178071976 CET46540443192.168.2.14185.125.190.26
                                  Dec 26, 2024 22:03:03.496308088 CET37785580492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:03.496572971 CET558043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:03.496572971 CET558043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:03.497312069 CET558083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:03.616887093 CET37785580892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:03.617144108 CET558083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:03.618033886 CET558083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:03.738420963 CET37785580892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:03.738619089 CET558083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.091358900 CET37785580692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:04.091406107 CET37785580892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:04.091655016 CET558063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.091793060 CET558063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.092394114 CET558103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.211935997 CET37785581092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:04.212069988 CET558103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.213255882 CET558103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.332717896 CET37785581092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:04.332936049 CET558103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.452697992 CET37785581092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:04.848268032 CET37785580892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:04.848521948 CET558083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.848651886 CET558083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.849366903 CET558123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.968956947 CET37785581292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:04.969189882 CET558123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:04.970232964 CET558123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.089673042 CET37785581292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:05.089973927 CET558123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.209709883 CET37785581292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:05.441343069 CET37785581092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:05.441565990 CET558103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.441688061 CET558103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.442423105 CET558143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.561933041 CET37785581492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:05.562149048 CET558143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.563232899 CET558143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.682679892 CET37785581492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:05.682888031 CET558143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:05.802330017 CET37785581492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:06.222764969 CET37785581292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:06.222964048 CET558123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.223011971 CET558123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.223613024 CET558163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.343163013 CET37785581692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:06.343483925 CET558163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.344599962 CET558163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.464308977 CET37785581692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:06.464526892 CET558163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.584163904 CET37785581692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:06.791827917 CET37785581492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:06.792083025 CET558143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.792083025 CET558143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.792495012 CET558183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.912144899 CET37785581892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:06.912400961 CET558183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:06.913228035 CET558183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.032888889 CET37785581892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:07.033001900 CET558183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.152774096 CET37785581892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:07.631592035 CET37785581692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:07.631855965 CET558163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.631855965 CET558163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.632327080 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.751879930 CET37785582092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:07.752053022 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.753025055 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.872654915 CET37785582092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:07.872728109 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:07.992189884 CET37785582092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:08.202960014 CET37785581892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:08.203130960 CET558183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:08.203274965 CET558183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:08.203852892 CET558223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:08.323301077 CET37785582292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:08.323441982 CET558223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:08.324753046 CET558223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:08.444189072 CET37785582292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:08.444319010 CET558223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:08.563802958 CET37785582292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:09.662679911 CET37785582292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:09.662884951 CET558223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:09.662884951 CET558223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:09.663650036 CET558243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:09.783139944 CET37785582492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:09.783377886 CET558243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:09.784461975 CET558243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:09.903899908 CET37785582492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:09.904095888 CET558243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:10.023778915 CET37785582492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:11.013252974 CET37785582492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:11.013571024 CET558243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:11.013608932 CET558243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:11.014311075 CET558263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:11.134907007 CET37785582692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:11.135075092 CET558263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:11.135799885 CET558263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:11.255150080 CET37785582692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:11.255343914 CET558263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:11.374804974 CET37785582692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:12.421546936 CET37785582692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:12.421761990 CET558263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:12.421761990 CET558263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:12.422246933 CET558283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:12.541846037 CET37785582892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:12.542079926 CET558283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:12.543171883 CET558283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:12.905524015 CET558283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:12.910257101 CET37785582892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:13.025196075 CET37785582892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:14.145194054 CET37785582892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:14.145392895 CET558283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:14.145477057 CET558283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:14.146070004 CET558303778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:14.265537977 CET37785583092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:14.265660048 CET558303778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:14.266666889 CET558303778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:14.386142015 CET37785583092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:14.386249065 CET558303778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:14.505914927 CET37785583092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:15.495054007 CET37785583092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:15.495301008 CET558303778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:15.495301962 CET558303778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:15.495898008 CET558323778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:15.615392923 CET37785583292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:15.615693092 CET558323778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:15.617126942 CET558323778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:15.736510038 CET37785583292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:15.736677885 CET558323778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:15.856115103 CET37785583292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:16.844711065 CET37785583292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:16.844990969 CET558323778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:16.845029116 CET558323778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:16.846052885 CET558343778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:16.965507984 CET37785583492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:16.965634108 CET558343778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:16.967199087 CET558343778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:17.086625099 CET37785583492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:17.086745024 CET558343778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:17.206389904 CET37785583492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:17.763097048 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:17.882904053 CET37785582092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:18.121500969 CET37785582092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:18.121912003 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:18.195327997 CET37785583492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:18.195540905 CET558343778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:18.195955038 CET558343778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:18.196719885 CET558363778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:18.317262888 CET37785583692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:18.317485094 CET558363778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:18.318666935 CET558363778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:18.438774109 CET37785583692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:18.439017057 CET558363778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:18.558759928 CET37785583692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:19.787353039 CET37785583692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:19.787472963 CET558363778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:19.787542105 CET558363778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:19.788274050 CET558383778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:19.907771111 CET37785583892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:19.907996893 CET558383778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:19.909512043 CET558383778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:20.028964043 CET37785583892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:20.029139996 CET558383778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:20.148813009 CET37785583892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:21.400496960 CET37785583892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:21.400731087 CET558383778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:21.400981903 CET558383778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:21.402033091 CET558403778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:21.521444082 CET37785584092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:21.521684885 CET558403778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:21.523122072 CET558403778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:21.644994020 CET37785584092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:21.645091057 CET558403778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:21.764559031 CET37785584092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:22.806929111 CET37785584092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:22.807183981 CET558403778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:22.807183981 CET558403778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:22.808006048 CET558423778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:22.927398920 CET37785584292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:22.927584887 CET558423778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:22.928901911 CET558423778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:23.048310995 CET37785584292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:23.048430920 CET558423778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:23.168199062 CET37785584292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:24.228118896 CET37785584292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:24.228359938 CET558423778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:24.228423119 CET558423778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:24.229141951 CET558443778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:24.349374056 CET37785584492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:24.349567890 CET558443778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:24.351078033 CET558443778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:24.472584963 CET37785584492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:24.472737074 CET558443778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:24.592696905 CET37785584492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:25.631906986 CET37785584492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:25.632019997 CET558443778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:25.632169008 CET558443778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:25.632970095 CET558463778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:25.752415895 CET37785584692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:25.752541065 CET558463778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:25.753866911 CET558463778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:25.873275995 CET37785584692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:25.873373985 CET558463778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:25.993010044 CET37785584692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:26.987158060 CET37785584692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:26.987292051 CET558463778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:26.987292051 CET558463778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:26.987938881 CET558483778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:27.107464075 CET37785584892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:27.107563972 CET558483778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:27.108625889 CET558483778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:27.228059053 CET37785584892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:27.228128910 CET558483778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:27.347697020 CET37785584892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:28.354419947 CET37785584892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:28.354526997 CET558483778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:28.354584932 CET558483778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:28.355099916 CET558503778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:28.474569082 CET37785585092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:28.474651098 CET558503778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:28.475296974 CET558503778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:28.594733953 CET37785585092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:28.594814062 CET558503778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:28.714534044 CET37785585092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:29.703902006 CET37785585092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:29.704125881 CET558503778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:29.704197884 CET558503778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:29.705235958 CET558523778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:29.824722052 CET37785585292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:29.825010061 CET558523778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:29.826489925 CET558523778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:30.216828108 CET558523778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:30.379055023 CET37785585292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:30.379074097 CET37785585292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:31.489217043 CET37785585292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:31.489368916 CET558523778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:31.489566088 CET558523778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:31.490400076 CET558543778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:31.610058069 CET37785585492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:31.610177994 CET558543778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:31.611125946 CET558543778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:31.730720043 CET37785585492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:31.730854034 CET558543778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:31.850400925 CET37785585492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:32.839663982 CET37785585492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:32.839982986 CET558543778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:32.840106964 CET558543778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:32.841247082 CET558563778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:32.960783958 CET37785585692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:32.960932016 CET558563778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:32.962466955 CET558563778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:33.081923008 CET37785585692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:33.082026958 CET558563778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:33.201519012 CET37785585692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:33.640671015 CET46540443192.168.2.14185.125.190.26
                                  Dec 26, 2024 22:03:34.226752996 CET37785585692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:34.227010012 CET558563778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:34.227045059 CET558563778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:34.227807045 CET558583778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:34.347626925 CET37785585892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:34.347738981 CET558583778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:34.348853111 CET558583778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:34.468341112 CET37785585892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:34.468478918 CET558583778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:34.588049889 CET37785585892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:35.644129038 CET37785585892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:35.644434929 CET558583778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:35.644577980 CET558583778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:35.645394087 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:35.764802933 CET37785586092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:35.764883995 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:35.766237020 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:35.885798931 CET37785586092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:35.885884047 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:36.005364895 CET37785586092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:37.056828976 CET37785586092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:37.056978941 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.057003975 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.057653904 CET558623778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.659406900 CET37785586092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:37.659446001 CET37785586092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:37.659528971 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.659528971 CET558603778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.659579992 CET37785586292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:37.659734011 CET558623778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.660818100 CET558623778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.780261993 CET37785586292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:37.780497074 CET558623778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:37.900111914 CET37785586292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:38.890268087 CET37785586292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:38.890435934 CET558623778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:38.890686989 CET558623778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:38.891460896 CET558643778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:39.011044025 CET37785586492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:39.011285067 CET558643778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:39.012748003 CET558643778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:39.132229090 CET37785586492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:39.132455111 CET558643778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:39.252042055 CET37785586492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:40.241638899 CET37785586492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:40.241980076 CET558643778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:40.242060900 CET558643778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:40.242794037 CET558663778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:40.362570047 CET37785586692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:40.362667084 CET558663778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:40.364145041 CET558663778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:40.483594894 CET37785586692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:40.483680010 CET558663778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:40.603229046 CET37785586692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:41.591890097 CET37785586692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:41.591986895 CET558663778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:41.592053890 CET558663778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:41.592578888 CET558683778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:41.712060928 CET37785586892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:41.712184906 CET558683778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:41.713197947 CET558683778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:41.832638025 CET37785586892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:41.832739115 CET558683778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:41.952301025 CET37785586892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:42.973126888 CET37785586892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:42.973280907 CET558683778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:42.973280907 CET558683778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:42.973895073 CET558703778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:43.093595028 CET37785587092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:43.093683958 CET558703778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:43.094829082 CET558703778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:43.214468956 CET37785587092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:43.214540958 CET558703778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:43.334285021 CET37785587092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:44.321099997 CET37785587092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:44.321338892 CET558703778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:44.321338892 CET558703778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:44.321963072 CET558723778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:44.442708015 CET37785587292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:44.442816019 CET558723778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:44.443619967 CET558723778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:44.563132048 CET37785587292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:44.563333988 CET558723778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:44.684041977 CET37785587292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:45.705471992 CET37785587292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:45.705615997 CET558723778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:45.705696106 CET558723778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:45.706258059 CET558743778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:45.825854063 CET37785587492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:45.825977087 CET558743778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:45.826832056 CET558743778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:45.946356058 CET37785587492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:45.946563005 CET558743778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:46.066154957 CET37785587492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:47.056457996 CET37785587492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:47.056674004 CET558743778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:47.056756020 CET558743778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:47.057482004 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:47.177053928 CET37785587692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:47.177153111 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:47.178005934 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:47.297441959 CET37785587692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:47.297549963 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:47.417164087 CET37785587692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:48.687684059 CET37785587692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:48.687702894 CET37785587692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:48.687901020 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:48.687901020 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:48.687921047 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:48.688478947 CET558783778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:48.803607941 CET37785587692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:48.803761959 CET558763778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:48.808000088 CET37785587892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:48.808213949 CET558783778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:48.809689045 CET558783778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:48.929600000 CET37785587892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:48.929733038 CET558783778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:49.049789906 CET37785587892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:50.039462090 CET37785587892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:50.039750099 CET558783778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:50.039781094 CET558783778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:50.040390968 CET558803778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:50.160017967 CET37785588092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:50.160141945 CET558803778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:50.161504984 CET558803778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:50.281064987 CET37785588092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:50.281147003 CET558803778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:50.401098013 CET37785588092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:51.397145033 CET37785588092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:51.397418022 CET558803778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:51.397418022 CET558803778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:51.397918940 CET558823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:51.517446041 CET37785588292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:51.517666101 CET558823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:51.518579006 CET558823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:51.638129950 CET37785588292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:51.638278961 CET558823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:51.757849932 CET37785588292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:52.747157097 CET37785588292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:52.747387886 CET558823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:52.747458935 CET558823778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:52.748272896 CET558843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:52.867854118 CET37785588492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:52.867974043 CET558843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:52.869056940 CET558843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:52.988540888 CET37785588492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:52.988662958 CET558843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:53.108338118 CET37785588492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:54.097939014 CET37785588492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:54.098134995 CET558843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:54.098182917 CET558843778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:54.098746061 CET558863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:54.218462944 CET37785588692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:54.218580961 CET558863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:54.219574928 CET558863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:54.339093924 CET37785588692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:54.339194059 CET558863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:54.458865881 CET37785588692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:55.506182909 CET37785588692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:55.506357908 CET558863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:55.506434917 CET558863778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:55.507163048 CET558883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:55.626770020 CET37785588892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:55.626874924 CET558883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:55.627605915 CET558883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:55.747147083 CET37785588892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:55.747251034 CET558883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:55.866868973 CET37785588892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:56.914339066 CET37785588892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:56.914531946 CET558883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:56.914623976 CET558883778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:56.915457964 CET558903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:57.035332918 CET37785589092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:57.035428047 CET558903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:57.036223888 CET558903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:57.155766964 CET37785589092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:57.155858994 CET558903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:57.275463104 CET37785589092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:58.594350100 CET37785589092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:58.594512939 CET558903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:58.594618082 CET558903778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:58.595411062 CET558923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:58.715087891 CET37785589292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:58.715188026 CET558923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:58.716574907 CET558923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:58.836258888 CET37785589292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:58.836333036 CET558923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:58.955900908 CET37785589292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:59.979538918 CET37785589292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:03:59.979856968 CET558923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:59.979856968 CET558923778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:03:59.980623960 CET558943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:00.100179911 CET37785589492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:00.100364923 CET558943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:00.101275921 CET558943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:00.220733881 CET37785589492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:00.220851898 CET558943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:00.340473890 CET37785589492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:01.341957092 CET37785589492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:01.342102051 CET558943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:01.342137098 CET558943778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:01.342812061 CET558963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:01.462430954 CET37785589692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:01.462644100 CET558963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:01.464046001 CET558963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:01.583559036 CET37785589692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:01.583669901 CET558963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:01.703273058 CET37785589692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:02.692097902 CET37785589692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:02.692426920 CET558963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:02.692508936 CET558963778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:02.693285942 CET558983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:02.812808037 CET37785589892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:02.812921047 CET558983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:02.814306974 CET558983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:02.933897018 CET37785589892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:02.934015036 CET558983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:03.053554058 CET37785589892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:04.045252085 CET37785589892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:04.045397043 CET558983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:04.045430899 CET558983778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:04.046036005 CET559003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:04.165612936 CET37785590092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:04.165945053 CET559003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:04.167340040 CET559003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:04.286890030 CET37785590092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:04.287101030 CET559003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:04.406631947 CET37785590092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:05.408783913 CET37785590092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:05.408915043 CET559003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:05.408957005 CET559003778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:05.409496069 CET559023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:05.529048920 CET37785590292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:05.529133081 CET559023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:05.530030012 CET559023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:05.649534941 CET37785590292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:05.649633884 CET559023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:05.769130945 CET37785590292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:06.759670973 CET37785590292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:06.759848118 CET559023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:06.759848118 CET559023778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:06.760379076 CET559043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:06.880404949 CET37785590492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:06.880486012 CET559043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:06.881392002 CET559043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:07.001017094 CET37785590492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:07.001101017 CET559043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:07.120918989 CET37785590492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:08.110326052 CET37785590492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:08.110426903 CET559043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:08.110454082 CET559043778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:08.111021996 CET559063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:08.230662107 CET37785590692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:08.230757952 CET559063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:08.232125044 CET559063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:08.351803064 CET37785590692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:08.351885080 CET559063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:08.471524000 CET37785590692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:09.486728907 CET37785590692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:09.486907959 CET559063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:09.486907959 CET559063778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:09.487523079 CET559083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:09.607062101 CET37785590892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:09.607163906 CET559083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:09.608424902 CET559083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:09.995208025 CET559083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:10.210696936 CET37785590892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:10.210789919 CET37785590892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:11.321966887 CET37785590892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:11.322093964 CET559083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:11.322129965 CET559083778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:11.322765112 CET559103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:11.442306995 CET37785591092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:11.442584991 CET559103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:11.443926096 CET559103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:11.563534021 CET37785591092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:11.563680887 CET559103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:11.683185101 CET37785591092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:12.672472000 CET37785591092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:12.672627926 CET559103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:12.672682047 CET559103778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:12.673381090 CET559123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:12.792867899 CET37785591292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:12.793051958 CET559123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:12.794337034 CET559123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:12.913799047 CET37785591292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:12.913969040 CET559123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:13.033550024 CET37785591292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:14.028492928 CET37785591292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:14.028842926 CET559123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:14.028877974 CET559123778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:14.029514074 CET559143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:14.149008036 CET37785591492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:14.149107933 CET559143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:14.149920940 CET559143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:14.269489050 CET37785591492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:14.269573927 CET559143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:14.389945030 CET37785591492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:15.379277945 CET37785591492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:15.379394054 CET559143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:15.379441023 CET559143778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:15.379986048 CET559163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:15.499536037 CET37785591692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:15.499732018 CET559163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:15.500658989 CET559163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:15.620233059 CET37785591692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:15.620367050 CET559163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:15.740020990 CET37785591692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:16.729844093 CET37785591692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:16.730117083 CET559163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:16.730202913 CET559163778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:16.731122971 CET559183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:16.850606918 CET37785591892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:16.850799084 CET559183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:16.852462053 CET559183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:16.971937895 CET37785591892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:16.972142935 CET559183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:17.091897011 CET37785591892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:18.122145891 CET37785591892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:18.122328997 CET559183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:18.122370958 CET559183778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:18.123275995 CET559203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:18.157337904 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:18.243000984 CET37785592092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:18.243164062 CET559203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:18.244801998 CET559203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:18.276889086 CET37785582092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:18.364370108 CET37785592092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:18.364563942 CET559203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:18.484250069 CET37785592092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:18.516809940 CET37785582092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:18.516880035 CET558203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:19.473040104 CET37785592092.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:19.473165035 CET559203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:19.473232985 CET559203778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:19.474015951 CET559223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:19.593528986 CET37785592292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:19.593617916 CET559223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:19.594645023 CET559223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:19.714112043 CET37785592292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:19.714214087 CET559223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:19.833817959 CET37785592292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:20.823131084 CET37785592292.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:20.823368073 CET559223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:20.823440075 CET559223778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:20.824213982 CET559243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:20.943756104 CET37785592492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:20.944053888 CET559243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:20.945420980 CET559243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:21.064918995 CET37785592492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:21.065157890 CET559243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:21.184835911 CET37785592492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:22.246861935 CET37785592492.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:22.247257948 CET559243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:22.247445107 CET559243778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:22.248332024 CET559263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:22.367820978 CET37785592692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:22.367938042 CET559263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:22.369486094 CET559263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:22.488936901 CET37785592692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:22.489052057 CET559263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:22.608624935 CET37785592692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:23.651027918 CET37785592692.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:23.651205063 CET559263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:23.651305914 CET559263778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:23.652240992 CET559283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:23.771845102 CET37785592892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:23.772109032 CET559283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:23.773550987 CET559283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:23.892997980 CET37785592892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:23.893291950 CET559283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:24.012829065 CET37785592892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:33.783597946 CET559283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:33.903115034 CET37785592892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:34.560592890 CET37785592892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:34.560619116 CET37785592892.118.56.167192.168.2.14
                                  Dec 26, 2024 22:04:34.560714006 CET559283778192.168.2.1492.118.56.167
                                  Dec 26, 2024 22:04:34.560714006 CET559283778192.168.2.1492.118.56.167

                                  System Behavior

                                  Start time (UTC):21:02:50
                                  Start date (UTC):26/12/2024
                                  Path:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  Arguments:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  File size:4463432 bytes
                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                  Start time (UTC):21:02:50
                                  Start date (UTC):26/12/2024
                                  Path:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  Arguments:-
                                  File size:4463432 bytes
                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                  Start time (UTC):21:02:50
                                  Start date (UTC):26/12/2024
                                  Path:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  Arguments:-
                                  File size:4463432 bytes
                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                  Start time (UTC):21:02:50
                                  Start date (UTC):26/12/2024
                                  Path:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  Arguments:-
                                  File size:4463432 bytes
                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                  Start time (UTC):21:02:56
                                  Start date (UTC):26/12/2024
                                  Path:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  Arguments:-
                                  File size:4463432 bytes
                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc

                                  Start time (UTC):21:02:56
                                  Start date (UTC):26/12/2024
                                  Path:/tmp/ub8ehJSePAfc9FYqZIT6.m68k.elf
                                  Arguments:-
                                  File size:4463432 bytes
                                  MD5 hash:cd177594338c77b895ae27c33f8f86cc