Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
kitsune.x86.elf

Overview

General Information

Sample name:kitsune.x86.elf
Analysis ID:1581079
MD5:afafe44e75da13379d6c74e263213913
SHA1:7762088cbd13d325664bd38bef5860b4dc3fc4e7
SHA256:5e0bf4cb5e267eacdad0681934369a646db7abb39e4f32b0c6f23f88def4e890
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai, Gafgyt
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Gafgyt
Yara detected Mirai
Machine Learning detection for sample
Opens /proc/net/* files useful for finding connected devices and routers
Detected TCP or UDP traffic on non-standard ports
Sample contains strings that are user agent strings indicative of HTTP manipulation
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581079
Start date and time:2024-12-26 22:19:23 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 55s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:kitsune.x86.elf
Detection:MAL
Classification:mal100.spre.troj.linELF@0/0@2/0
  • VT rate limit hit for: kitsune.x86.elf
Command:/tmp/kitsune.x86.elf
PID:5542
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
SourceRuleDescriptionAuthorStrings
kitsune.x86.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    kitsune.x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      kitsune.x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xda40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xda54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xda68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xda7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xda90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdaa4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdab8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdacc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdae0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdaf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdb94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdba8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdbbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xdbd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      kitsune.x86.elfLinux_Trojan_Gafgyt_a6a2adb9unknownunknown
      • 0x8a8:$a: CC 01 C2 89 55 B4 8B 45 B4 C9 C3 55 48 89 E5 48 81 EC 90 00
      kitsune.x86.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0x5574:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      Click to see the 11 entries
      SourceRuleDescriptionAuthorStrings
      5542.1.0000000000400000.0000000000411000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
        5542.1.0000000000400000.0000000000411000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          5542.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
          • 0xda40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xda54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xda68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xda7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xda90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdaa4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdab8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdacc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdae0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdaf4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb08:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb1c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb30:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb44:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb58:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb6c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb80:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdb94:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdba8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdbbc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          • 0xdbd0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
          5542.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_a6a2adb9unknownunknown
          • 0x8a8:$a: CC 01 C2 89 55 B4 8B 45 B4 C9 C3 55 48 89 E5 48 81 EC 90 00
          5542.1.0000000000400000.0000000000411000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
          • 0x5574:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
          Click to see the 33 entries
          TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
          2024-12-26T22:20:14.806764+010028437131A Network Trojan was detected192.168.2.1558992178.215.238.694258TCP
          2024-12-26T22:20:17.202231+010028437131A Network Trojan was detected192.168.2.1558994178.215.238.694258TCP
          2024-12-26T22:20:19.577116+010028437131A Network Trojan was detected192.168.2.1558996178.215.238.694258TCP
          2024-12-26T22:20:21.952245+010028437131A Network Trojan was detected192.168.2.1558998178.215.238.694258TCP
          2024-12-26T22:20:24.329141+010028437131A Network Trojan was detected192.168.2.1559000178.215.238.694258TCP
          2024-12-26T22:20:26.702488+010028437131A Network Trojan was detected192.168.2.1559002178.215.238.694258TCP
          2024-12-26T22:20:29.077830+010028437131A Network Trojan was detected192.168.2.1559004178.215.238.694258TCP
          2024-12-26T22:20:31.512932+010028437131A Network Trojan was detected192.168.2.1559006178.215.238.694258TCP
          2024-12-26T22:20:33.924478+010028437131A Network Trojan was detected192.168.2.1559008178.215.238.694258TCP
          2024-12-26T22:20:36.312085+010028437131A Network Trojan was detected192.168.2.1559010178.215.238.694258TCP
          2024-12-26T22:20:38.687679+010028437131A Network Trojan was detected192.168.2.1559012178.215.238.694258TCP
          2024-12-26T22:20:41.062133+010028437131A Network Trojan was detected192.168.2.1559014178.215.238.694258TCP
          2024-12-26T22:20:43.437587+010028437131A Network Trojan was detected192.168.2.1559016178.215.238.694258TCP
          2024-12-26T22:20:45.813135+010028437131A Network Trojan was detected192.168.2.1559018178.215.238.694258TCP
          2024-12-26T22:20:48.426343+010028437131A Network Trojan was detected192.168.2.1559020178.215.238.694258TCP
          2024-12-26T22:20:50.796356+010028437131A Network Trojan was detected192.168.2.1559022178.215.238.694258TCP
          2024-12-26T22:20:53.171394+010028437131A Network Trojan was detected192.168.2.1559024178.215.238.694258TCP
          2024-12-26T22:20:55.703528+010028437131A Network Trojan was detected192.168.2.1559026178.215.238.694258TCP
          2024-12-26T22:20:58.078014+010028437131A Network Trojan was detected192.168.2.1559028178.215.238.694258TCP
          2024-12-26T22:21:00.453497+010028437131A Network Trojan was detected192.168.2.1559030178.215.238.694258TCP
          2024-12-26T22:21:02.859460+010028437131A Network Trojan was detected192.168.2.1559032178.215.238.694258TCP
          2024-12-26T22:21:05.234373+010028437131A Network Trojan was detected192.168.2.1559034178.215.238.694258TCP
          2024-12-26T22:21:07.609764+010028437131A Network Trojan was detected192.168.2.1559036178.215.238.694258TCP
          2024-12-26T22:21:09.985000+010028437131A Network Trojan was detected192.168.2.1559038178.215.238.694258TCP
          2024-12-26T22:21:12.432365+010028437131A Network Trojan was detected192.168.2.1559040178.215.238.694258TCP
          2024-12-26T22:21:14.844199+010028437131A Network Trojan was detected192.168.2.1559042178.215.238.694258TCP
          2024-12-26T22:21:17.267711+010028437131A Network Trojan was detected192.168.2.1559044178.215.238.694258TCP
          2024-12-26T22:21:19.672116+010028437131A Network Trojan was detected192.168.2.1559046178.215.238.694258TCP
          2024-12-26T22:21:22.047237+010028437131A Network Trojan was detected192.168.2.1559048178.215.238.694258TCP
          2024-12-26T22:21:24.421491+010028437131A Network Trojan was detected192.168.2.1559050178.215.238.694258TCP
          2024-12-26T22:21:26.797469+010028437131A Network Trojan was detected192.168.2.1559052178.215.238.694258TCP
          2024-12-26T22:21:29.186733+010028437131A Network Trojan was detected192.168.2.1559054178.215.238.694258TCP
          2024-12-26T22:21:31.562707+010028437131A Network Trojan was detected192.168.2.1559056178.215.238.694258TCP
          2024-12-26T22:21:33.985001+010028437131A Network Trojan was detected192.168.2.1559058178.215.238.694258TCP
          2024-12-26T22:21:36.359748+010028437131A Network Trojan was detected192.168.2.1559060178.215.238.694258TCP
          2024-12-26T22:21:38.779553+010028437131A Network Trojan was detected192.168.2.1559062178.215.238.694258TCP
          2024-12-26T22:21:41.172847+010028437131A Network Trojan was detected192.168.2.1559064178.215.238.694258TCP
          2024-12-26T22:21:43.563194+010028437131A Network Trojan was detected192.168.2.1559066178.215.238.694258TCP
          2024-12-26T22:21:45.937736+010028437131A Network Trojan was detected192.168.2.1559068178.215.238.694258TCP
          2024-12-26T22:21:48.299875+010028437131A Network Trojan was detected192.168.2.1559070178.215.238.694258TCP
          2024-12-26T22:21:50.689644+010028437131A Network Trojan was detected192.168.2.1559072178.215.238.694258TCP
          2024-12-26T22:21:53.063565+010028437131A Network Trojan was detected192.168.2.1559074178.215.238.694258TCP
          2024-12-26T22:21:55.438514+010028437131A Network Trojan was detected192.168.2.1559076178.215.238.694258TCP
          2024-12-26T22:21:57.828906+010028437131A Network Trojan was detected192.168.2.1559078178.215.238.694258TCP
          2024-12-26T22:22:00.220209+010028437131A Network Trojan was detected192.168.2.1559080178.215.238.694258TCP
          2024-12-26T22:22:02.595534+010028437131A Network Trojan was detected192.168.2.1559082178.215.238.694258TCP
          2024-12-26T22:22:04.969883+010028437131A Network Trojan was detected192.168.2.1559084178.215.238.694258TCP
          2024-12-26T22:22:07.345312+010028437131A Network Trojan was detected192.168.2.1559086178.215.238.694258TCP
          2024-12-26T22:22:09.786933+010028437131A Network Trojan was detected192.168.2.1559088178.215.238.694258TCP
          2024-12-26T22:22:12.157758+010028437131A Network Trojan was detected192.168.2.1559090178.215.238.694258TCP
          2024-12-26T22:22:14.532718+010028437131A Network Trojan was detected192.168.2.1559092178.215.238.694258TCP
          2024-12-26T22:22:16.945010+010028437131A Network Trojan was detected192.168.2.1559094178.215.238.694258TCP
          2024-12-26T22:22:19.329382+010028437131A Network Trojan was detected192.168.2.1559096178.215.238.694258TCP
          2024-12-26T22:22:21.704439+010028437131A Network Trojan was detected192.168.2.1559098178.215.238.694258TCP
          2024-12-26T22:22:24.082345+010028437131A Network Trojan was detected192.168.2.1559100178.215.238.694258TCP
          2024-12-26T22:22:26.454148+010028437131A Network Trojan was detected192.168.2.1559102178.215.238.694258TCP
          2024-12-26T22:22:29.312982+010028437131A Network Trojan was detected192.168.2.1559104178.215.238.694258TCP
          2024-12-26T22:22:31.673832+010028437131A Network Trojan was detected192.168.2.1559106178.215.238.694258TCP
          2024-12-26T22:22:34.048941+010028437131A Network Trojan was detected192.168.2.1559108178.215.238.694258TCP
          2024-12-26T22:22:36.423448+010028437131A Network Trojan was detected192.168.2.1559110178.215.238.694258TCP
          2024-12-26T22:22:38.963073+010028437131A Network Trojan was detected192.168.2.1559112178.215.238.694258TCP
          2024-12-26T22:22:41.329579+010028437131A Network Trojan was detected192.168.2.1559114178.215.238.694258TCP
          2024-12-26T22:22:43.705460+010028437131A Network Trojan was detected192.168.2.1559116178.215.238.694258TCP
          2024-12-26T22:22:46.079766+010028437131A Network Trojan was detected192.168.2.1559118178.215.238.694258TCP
          2024-12-26T22:22:48.470450+010028437131A Network Trojan was detected192.168.2.1559120178.215.238.694258TCP
          2024-12-26T22:22:50.845930+010028437131A Network Trojan was detected192.168.2.1559122178.215.238.694258TCP
          2024-12-26T22:22:53.204929+010028437131A Network Trojan was detected192.168.2.1559124178.215.238.694258TCP
          2024-12-26T22:22:55.644423+010028437131A Network Trojan was detected192.168.2.1559126178.215.238.694258TCP
          2024-12-26T22:22:58.017939+010028437131A Network Trojan was detected192.168.2.1559128178.215.238.694258TCP
          2024-12-26T22:23:00.392484+010028437131A Network Trojan was detected192.168.2.1559130178.215.238.694258TCP
          2024-12-26T22:23:02.767727+010028437131A Network Trojan was detected192.168.2.1559132178.215.238.694258TCP
          2024-12-26T22:23:05.174401+010028437131A Network Trojan was detected192.168.2.1559134178.215.238.694258TCP
          2024-12-26T22:23:07.549633+010028437131A Network Trojan was detected192.168.2.1559136178.215.238.694258TCP
          2024-12-26T22:23:09.956077+010028437131A Network Trojan was detected192.168.2.1559138178.215.238.694258TCP
          2024-12-26T22:23:12.362325+010028437131A Network Trojan was detected192.168.2.1559140178.215.238.694258TCP
          2024-12-26T22:23:14.738144+010028437131A Network Trojan was detected192.168.2.1559142178.215.238.694258TCP
          2024-12-26T22:23:17.127882+010028437131A Network Trojan was detected192.168.2.1559144178.215.238.694258TCP
          2024-12-26T22:23:19.519269+010028437131A Network Trojan was detected192.168.2.1559146178.215.238.694258TCP
          2024-12-26T22:23:21.987304+010028437131A Network Trojan was detected192.168.2.1559148178.215.238.694258TCP
          2024-12-26T22:23:24.362253+010028437131A Network Trojan was detected192.168.2.1559150178.215.238.694258TCP
          2024-12-26T22:23:26.753133+010028437131A Network Trojan was detected192.168.2.1559152178.215.238.694258TCP
          2024-12-26T22:23:29.144197+010028437131A Network Trojan was detected192.168.2.1559154178.215.238.694258TCP
          2024-12-26T22:23:31.519376+010028437131A Network Trojan was detected192.168.2.1559156178.215.238.694258TCP
          2024-12-26T22:23:33.910365+010028437131A Network Trojan was detected192.168.2.1559158178.215.238.694258TCP
          2024-12-26T22:23:36.393345+010028437131A Network Trojan was detected192.168.2.1559160178.215.238.694258TCP
          2024-12-26T22:23:38.769096+010028437131A Network Trojan was detected192.168.2.1559162178.215.238.694258TCP
          2024-12-26T22:23:41.144173+010028437131A Network Trojan was detected192.168.2.1559164178.215.238.694258TCP
          2024-12-26T22:23:43.519092+010028437131A Network Trojan was detected192.168.2.1559166178.215.238.694258TCP
          2024-12-26T22:23:45.894747+010028437131A Network Trojan was detected192.168.2.1559168178.215.238.694258TCP
          2024-12-26T22:23:48.284964+010028437131A Network Trojan was detected192.168.2.1559170178.215.238.694258TCP

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: kitsune.x86.elfAvira: detected
          Source: kitsune.x86.elfMalware Configuration Extractor: Gafgyt {"C2 url": "178.215.238.69:4258"}
          Source: kitsune.x86.elfReversingLabs: Detection: 60%
          Source: kitsune.x86.elfJoe Sandbox ML: detected

          Spreading

          barindex
          Source: /tmp/kitsune.x86.elf (PID: 5542)Opens: /proc/net/routeJump to behavior

          Networking

          barindex
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:58994 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59002 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:58992 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59030 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59042 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59052 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59010 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59040 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59018 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59058 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59022 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59076 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59092 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59100 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59026 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:58998 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59020 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59108 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59016 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59074 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59112 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59038 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59136 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59116 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59028 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59124 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59160 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59050 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59046 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59104 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59110 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59166 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:58996 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59134 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59138 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59012 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59148 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59086 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59054 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59128 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59120 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59056 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59114 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59154 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59140 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59118 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59088 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59146 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59106 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59164 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59168 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59130 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59156 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59060 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59064 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59080 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59036 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59090 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59066 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59006 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59162 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59094 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59024 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59078 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59096 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59142 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59158 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59032 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59122 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59132 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59102 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59034 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59044 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59048 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59014 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59004 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59126 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59062 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59072 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59152 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59170 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59068 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59082 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59098 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59000 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59144 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59150 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59008 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59070 -> 178.215.238.69:4258
          Source: Network trafficSuricata IDS: 2843713 - Severity 1 - ETPRO MALWARE ELF/Mirai Variant CnC Checkin : 192.168.2.15:59084 -> 178.215.238.69:4258
          Source: global trafficTCP traffic: 192.168.2.15:58992 -> 178.215.238.69:4258
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: unknownTCP traffic detected without corresponding DNS query: 178.215.238.69
          Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
          Source: kitsune.x86.elfString found in binary or memory: http://fast.no/support/crawler.asp)
          Source: kitsune.x86.elfString found in binary or memory: http://feedback.redkolibri.com/
          Source: kitsune.x86.elfString found in binary or memory: http://www.baidu.com/search/spider.htm)
          Source: kitsune.x86.elfString found in binary or memory: http://www.baidu.com/search/spider.html)
          Source: kitsune.x86.elfString found in binary or memory: http://www.billybobbot.com/crawler/)

          System Summary

          barindex
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e4a1982b Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e4a1982b Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e4a1982b Author: unknown
          Source: Process Memory Space: kitsune.x86.elf PID: 5542, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: kitsune.x86.elf PID: 5542, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: Process Memory Space: kitsune.x86.elf PID: 5543, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
          Source: Process Memory Space: kitsune.x86.elf PID: 5543, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: kitsune.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_e4a1982b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d9f852c28433128b0fd330bee35f7bd4aada5226e9ca865fe5cd8cca52b2a622, id = e4a1982b-928a-4da5-b497-cedc1d26e845, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e4a1982b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d9f852c28433128b0fd330bee35f7bd4aada5226e9ca865fe5cd8cca52b2a622, id = e4a1982b-928a-4da5-b497-cedc1d26e845, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
          Source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_e4a1982b os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d9f852c28433128b0fd330bee35f7bd4aada5226e9ca865fe5cd8cca52b2a622, id = e4a1982b-928a-4da5-b497-cedc1d26e845, last_modified = 2021-09-16
          Source: Process Memory Space: kitsune.x86.elf PID: 5542, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: kitsune.x86.elf PID: 5542, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: Process Memory Space: kitsune.x86.elf PID: 5543, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
          Source: Process Memory Space: kitsune.x86.elf PID: 5543, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
          Source: classification engineClassification label: mal100.spre.troj.linELF@0/0@2/0

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: kitsune.x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: kitsune.x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: kitsune.x86.elf PID: 5542, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: kitsune.x86.elf PID: 5543, type: MEMORYSTR
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36
          Source: Initial sampleUser agent string found: Opera/9.80 (X11; Linux i686; Ubuntu/14.10) Presto/2.12.388 Version/12.16
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows; U; Windows NT 6.1; rv:2.2) Gecko/20110201
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; AS; rv:11.0) like Gecko
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Android; Linux armv7l; rv:9.0) Gecko/20111216 Firefox/9.0 Fennec/9.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1) AppleWebKit/536.5 (KHTML, like Gecko) Chrome/19.0.1084.56 Safari/536.5
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; en) Presto/2.10.229 Version/11.60
          Source: Initial sampleUser agent string found: Mozilla/5.0 (iPad; U; CPU OS 5_1 like Mac OS X) AppleWebKit/531.21.10 (KHTML, like Gecko) Version/4.0.4 Mobile/7B367 Safari/531.21.10 UCBrowser/3.4.3.532
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Nintendo WiiU) AppleWebKit/536.30 (KHTML, like Gecko) NX/3.0.4.2.12 NintendoBrowser/4.3.1.11264.US
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; pl) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; en) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; ja) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; cn) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20100101 Firefox/12.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (X11; U; Linux x86_64; de; rv:1.9.2.8) Gecko/20100723 Ubuntu/10.04 (lucid) Firefox/3.6.8
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:13.0) Gecko/20100101 Firefox/13.0.1
          Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.1; U; en) Presto/2.10.289 Version/12.01
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 5.1; rv:5.0.1) Gecko/20100101 Firefox/5.0.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; rv:5.0) Gecko/20100101 Firefox/5.02
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.0) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.116 Safari/537.36
          Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.143 Safari/537.36

          Remote Access Functionality

          barindex
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: TrafficSuricata IDS: ETPRO MALWARE ELF/Mirai Variant CnC Checkin
          Source: Yara matchFile source: kitsune.x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: kitsune.x86.elf, type: SAMPLE
          Source: Yara matchFile source: 5542.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: 5543.1.0000000000400000.0000000000411000.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: kitsune.x86.elf PID: 5542, type: MEMORYSTR
          Source: Yara matchFile source: Process Memory Space: kitsune.x86.elf PID: 5543, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping1
          Remote System Discovery
          Remote ServicesData from Local System1
          Data Obfuscation
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
          Non-Application Layer Protocol
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
          Application Layer Protocol
          Traffic DuplicationData Destruction
          {"C2 url": "178.215.238.69:4258"}
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          SourceDetectionScannerLabelLink
          kitsune.x86.elf61%ReversingLabsLinux.Trojan.Mirai
          kitsune.x86.elf100%AviraEXP/ELF.Mirai.Z.A
          kitsune.x86.elf100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          NameIPActiveMaliciousAntivirus DetectionReputation
          daisy.ubuntu.com
          162.213.35.24
          truefalse
            high
            NameMaliciousAntivirus DetectionReputation
            178.215.238.69:4258true
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              http://www.baidu.com/search/spider.html)kitsune.x86.elffalse
                high
                http://www.billybobbot.com/crawler/)kitsune.x86.elffalse
                  high
                  http://fast.no/support/crawler.asp)kitsune.x86.elffalse
                    high
                    http://feedback.redkolibri.com/kitsune.x86.elffalse
                      high
                      http://www.baidu.com/search/spider.htm)kitsune.x86.elffalse
                        high
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        178.215.238.69
                        unknownGermany
                        10753LVLT-10753UStrue
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        178.215.238.69kitsune.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                          kitsune.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                            kitsune.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                              kitsune.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                daisy.ubuntu.comkitsune.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 162.213.35.24
                                kitsune.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 162.213.35.25
                                kitsune.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 162.213.35.24
                                ub8ehJSePAfc9FYqZIT6.spc.elfGet hashmaliciousMiraiBrowse
                                • 162.213.35.25
                                boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                • 162.213.35.25
                                boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                • 162.213.35.24
                                boatnet.m68k.elfGet hashmaliciousMiraiBrowse
                                • 162.213.35.25
                                boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                • 162.213.35.25
                                boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                • 162.213.35.25
                                boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                • 162.213.35.25
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                LVLT-10753USkitsune.arm6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 178.215.238.69
                                kitsune.mpsl.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 178.215.238.69
                                kitsune.ppc.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 178.215.238.69
                                kitsune.mips.elfGet hashmaliciousGafgyt, MiraiBrowse
                                • 178.215.238.69
                                ngwa5.elfGet hashmaliciousMiraiBrowse
                                • 178.215.238.25
                                fnkea7.elfGet hashmaliciousMiraiBrowse
                                • 178.215.238.25
                                wkb86.elfGet hashmaliciousMiraiBrowse
                                • 178.215.238.25
                                wlw68k.elfGet hashmaliciousMiraiBrowse
                                • 178.215.238.25
                                njvwa4.elfGet hashmaliciousMiraiBrowse
                                • 178.215.238.25
                                wrjkngh4.elfGet hashmaliciousMiraiBrowse
                                • 178.215.238.25
                                No context
                                No context
                                No created / dropped files found
                                File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                Entropy (8bit):5.870957778193571
                                TrID:
                                • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                File name:kitsune.x86.elf
                                File size:108'630 bytes
                                MD5:afafe44e75da13379d6c74e263213913
                                SHA1:7762088cbd13d325664bd38bef5860b4dc3fc4e7
                                SHA256:5e0bf4cb5e267eacdad0681934369a646db7abb39e4f32b0c6f23f88def4e890
                                SHA512:938f2474741e445dc8fea3c3cd23b2d5c4340a3ddc454c45e3b8917bf612174e8a13520a0f21b007d631b309889e06e363ccfccf5dd5e0b072c7a3359b921e48
                                SSDEEP:3072:j6dye4BmJQRphaZw/1vc45AzkSXmdRWaLHgb4:dRphaZcErmdRWaDgb4
                                TLSH:40B35C07DA21807AC09B43B21BDF96219D23B4FD1772310A33E5AEE4AF095859F9D786
                                File Content Preview:.ELF..............>.......@.....@........>..........@.8...@.......................@.......@...../......./......... .............0.......0.a.....0.a.....8)......8......... .....Q.td....................................................H...._........H........

                                ELF header

                                Class:ELF64
                                Data:2's complement, little endian
                                Version:1 (current)
                                Machine:Advanced Micro Devices X86-64
                                Version Number:0x1
                                Type:EXEC (Executable file)
                                OS/ABI:UNIX - System V
                                ABI Version:0
                                Entry Point Address:0x400194
                                Flags:0x0
                                ELF Header Size:64
                                Program Header Offset:64
                                Program Header Size:56
                                Number of Program Headers:3
                                Section Header Offset:81648
                                Section Header Size:64
                                Number of Section Headers:15
                                Header String Table Index:12
                                NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                NULL0x00x00x00x00x0000
                                .initPROGBITS0x4000e80xe80x130x00x6AX001
                                .textPROGBITS0x4001000x1000xbde40x00x6AX0016
                                .finiPROGBITS0x40bee40xbee40xe0x00x6AX001
                                .rodataPROGBITS0x40bf000xbf000x4b2f0x00x2A0032
                                .eh_framePROGBITS0x610a300x10a300x22fc0x00x3WA008
                                .ctorsPROGBITS0x612d300x12d300x100x00x3WA008
                                .dtorsPROGBITS0x612d400x12d400x100x00x3WA008
                                .jcrPROGBITS0x612d500x12d500x80x00x3WA008
                                .dataPROGBITS0x612d600x12d600x6080x00x3WA0032
                                .bssNOBITS0x6133800x133680x6ae80x00x3WA0032
                                .commentPROGBITS0x00x133680xb1c0x00x0001
                                .shstrtabSTRTAB0x00x13e840x660x00x0001
                                .symtabSYMTAB0x00x142b00x43800x180x0142498
                                .strtabSTRTAB0x00x186300x22260x00x0001
                                TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                LOAD0x00x4000000x4000000x10a2f0x10a2f6.39590x5R E0x200000.init .text .fini .rodata
                                LOAD0x10a300x610a300x610a300x29380x94383.56720x6RW 0x200000.eh_frame .ctors .dtors .jcr .data .bss
                                GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                .symtab0x4000e80SECTION<unknown>DEFAULT1
                                .symtab0x4001000SECTION<unknown>DEFAULT2
                                .symtab0x40bee40SECTION<unknown>DEFAULT3
                                .symtab0x40bf000SECTION<unknown>DEFAULT4
                                .symtab0x610a300SECTION<unknown>DEFAULT5
                                .symtab0x612d300SECTION<unknown>DEFAULT6
                                .symtab0x612d400SECTION<unknown>DEFAULT7
                                .symtab0x612d500SECTION<unknown>DEFAULT8
                                .symtab0x612d600SECTION<unknown>DEFAULT9
                                .symtab0x6133800SECTION<unknown>DEFAULT10
                                .symtab0x00SECTION<unknown>DEFAULT11
                                C.1.3849.symtab0x41082040OBJECT<unknown>DEFAULT4
                                C.53.5637.symtab0x40d620208OBJECT<unknown>DEFAULT4
                                C.60.5739.symtab0x40e1402256OBJECT<unknown>DEFAULT4
                                Q.symtab0x61340016384OBJECT<unknown>DEFAULT10
                                Randhex.symtab0x401841385FUNC<unknown>DEFAULT2
                                SendSTD.symtab0x4014b4405FUNC<unknown>DEFAULT2
                                UDPRAW.symtab0x401745252FUNC<unknown>DEFAULT2
                                _Exit.symtab0x40363043FUNC<unknown>DEFAULT2
                                _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __CTOR_END__.symtab0x612d380OBJECT<unknown>DEFAULT6
                                __CTOR_LIST__.symtab0x612d300OBJECT<unknown>DEFAULT6
                                __C_ctype_b.symtab0x612f888OBJECT<unknown>DEFAULT9
                                __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __C_ctype_b_data.symtab0x40eab0768OBJECT<unknown>DEFAULT4
                                __C_ctype_tolower.symtab0x6133508OBJECT<unknown>DEFAULT9
                                __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __C_ctype_tolower_data.symtab0x410520768OBJECT<unknown>DEFAULT4
                                __C_ctype_toupper.symtab0x612f988OBJECT<unknown>DEFAULT9
                                __C_ctype_toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __C_ctype_toupper_data.symtab0x40edb0768OBJECT<unknown>DEFAULT4
                                __DTOR_END__.symtab0x612d480OBJECT<unknown>DEFAULT7
                                __DTOR_LIST__.symtab0x612d400OBJECT<unknown>DEFAULT7
                                __EH_FRAME_BEGIN__.symtab0x610a300OBJECT<unknown>DEFAULT5
                                __FRAME_END__.symtab0x612d280OBJECT<unknown>DEFAULT5
                                __GI___C_ctype_b.symtab0x612f888OBJECT<unknown>HIDDEN9
                                __GI___C_ctype_tolower.symtab0x6133508OBJECT<unknown>HIDDEN9
                                __GI___C_ctype_toupper.symtab0x612f988OBJECT<unknown>HIDDEN9
                                __GI___ctype_b.symtab0x612f908OBJECT<unknown>HIDDEN9
                                __GI___ctype_tolower.symtab0x6133588OBJECT<unknown>HIDDEN9
                                __GI___ctype_toupper.symtab0x612fa08OBJECT<unknown>HIDDEN9
                                __GI___errno_location.symtab0x4038cc6FUNC<unknown>HIDDEN2
                                __GI___fcntl_nocancel.symtab0x4035cc100FUNC<unknown>HIDDEN2
                                __GI___fgetc_unlocked.symtab0x408a14222FUNC<unknown>HIDDEN2
                                __GI___glibc_strerror_r.symtab0x4051d414FUNC<unknown>HIDDEN2
                                __GI___h_errno_location.symtab0x4076046FUNC<unknown>HIDDEN2
                                __GI___libc_fcntl.symtab0x403568100FUNC<unknown>HIDDEN2
                                __GI___sigaddset.symtab0x40567828FUNC<unknown>HIDDEN2
                                __GI___sigdelset.symtab0x40569430FUNC<unknown>HIDDEN2
                                __GI___sigismember.symtab0x40565832FUNC<unknown>HIDDEN2
                                __GI___uClibc_fini.symtab0x406df470FUNC<unknown>HIDDEN2
                                __GI___uClibc_init.symtab0x406e6f58FUNC<unknown>HIDDEN2
                                __GI___xpg_strerror_r.symtab0x4051e4196FUNC<unknown>HIDDEN2
                                __GI__exit.symtab0x40363043FUNC<unknown>HIDDEN2
                                __GI_abort.symtab0x4063bc200FUNC<unknown>HIDDEN2
                                __GI_atoi.symtab0x40686018FUNC<unknown>HIDDEN2
                                __GI_brk.symtab0x409b3443FUNC<unknown>HIDDEN2
                                __GI_chdir.symtab0x40365c38FUNC<unknown>HIDDEN2
                                __GI_clock_getres.symtab0x40719041FUNC<unknown>HIDDEN2
                                __GI_close.symtab0x40368441FUNC<unknown>HIDDEN2
                                __GI_closedir.symtab0x407338147FUNC<unknown>HIDDEN2
                                __GI_config_close.symtab0x4078ce43FUNC<unknown>HIDDEN2
                                __GI_config_open.symtab0x4078f946FUNC<unknown>HIDDEN2
                                __GI_config_read.symtab0x40760c706FUNC<unknown>HIDDEN2
                                __GI_connect.symtab0x40546443FUNC<unknown>HIDDEN2
                                __GI_errno.symtab0x6196584OBJECT<unknown>HIDDEN10
                                __GI_exit.symtab0x4069d495FUNC<unknown>HIDDEN2
                                __GI_fclose.symtab0x4079f8269FUNC<unknown>HIDDEN2
                                __GI_fcntl.symtab0x403568100FUNC<unknown>HIDDEN2
                                __GI_fflush_unlocked.symtab0x4088d0322FUNC<unknown>HIDDEN2
                                __GI_fgetc.symtab0x408704128FUNC<unknown>HIDDEN2
                                __GI_fgetc_unlocked.symtab0x408a14222FUNC<unknown>HIDDEN2
                                __GI_fgets.symtab0x408784116FUNC<unknown>HIDDEN2
                                __GI_fgets_unlocked.symtab0x408af4116FUNC<unknown>HIDDEN2
                                __GI_fopen.symtab0x407b0810FUNC<unknown>HIDDEN2
                                __GI_fork.symtab0x4036b038FUNC<unknown>HIDDEN2
                                __GI_fputs_unlocked.symtab0x4049c856FUNC<unknown>HIDDEN2
                                __GI_fseek.symtab0x409f045FUNC<unknown>HIDDEN2
                                __GI_fseeko64.symtab0x409f0c225FUNC<unknown>HIDDEN2
                                __GI_fstat.symtab0x409b6082FUNC<unknown>HIDDEN2
                                __GI_fstat64.symtab0x409b6082FUNC<unknown>HIDDEN2
                                __GI_fwrite_unlocked.symtab0x404a00128FUNC<unknown>HIDDEN2
                                __GI_getc_unlocked.symtab0x408a14222FUNC<unknown>HIDDEN2
                                __GI_getdtablesize.symtab0x4071bc36FUNC<unknown>HIDDEN2
                                __GI_getegid.symtab0x4071e08FUNC<unknown>HIDDEN2
                                __GI_geteuid.symtab0x4071e88FUNC<unknown>HIDDEN2
                                __GI_getgid.symtab0x4071f08FUNC<unknown>HIDDEN2
                                __GI_gethostbyname.symtab0x40541410FUNC<unknown>HIDDEN2
                                __GI_gethostbyname2.symtab0x40542065FUNC<unknown>HIDDEN2
                                __GI_gethostbyname2_r.symtab0x4093a4761FUNC<unknown>HIDDEN2
                                __GI_gethostbyname_r.symtab0x40b5b0802FUNC<unknown>HIDDEN2
                                __GI_gethostname.symtab0x40b8d494FUNC<unknown>HIDDEN2
                                __GI_getpagesize.symtab0x4071f819FUNC<unknown>HIDDEN2
                                __GI_getpid.symtab0x4036d88FUNC<unknown>HIDDEN2
                                __GI_getrlimit.symtab0x40720c40FUNC<unknown>HIDDEN2
                                __GI_getsockname.symtab0x40549041FUNC<unknown>HIDDEN2
                                __GI_getuid.symtab0x4072348FUNC<unknown>HIDDEN2
                                __GI_h_errno.symtab0x61965c4OBJECT<unknown>HIDDEN10
                                __GI_htonl.symtab0x4053885FUNC<unknown>HIDDEN2
                                __GI_htons.symtab0x4053808FUNC<unknown>HIDDEN2
                                __GI_inet_addr.symtab0x4053f429FUNC<unknown>HIDDEN2
                                __GI_inet_aton.symtab0x40931c135FUNC<unknown>HIDDEN2
                                __GI_inet_ntoa.symtab0x4053e910FUNC<unknown>HIDDEN2
                                __GI_inet_ntoa_r.symtab0x40539c77FUNC<unknown>HIDDEN2
                                __GI_inet_ntop.symtab0x40a68f518FUNC<unknown>HIDDEN2
                                __GI_inet_pton.symtab0x40a3af493FUNC<unknown>HIDDEN2
                                __GI_initstate_r.symtab0x4067a4185FUNC<unknown>HIDDEN2
                                __GI_ioctl.symtab0x4036e0101FUNC<unknown>HIDDEN2
                                __GI_isatty.symtab0x4052f425FUNC<unknown>HIDDEN2
                                __GI_isspace.symtab0x40389818FUNC<unknown>HIDDEN2
                                __GI_kill.symtab0x40374844FUNC<unknown>HIDDEN2
                                __GI_lseek.symtab0x40bdd445FUNC<unknown>HIDDEN2
                                __GI_lseek64.symtab0x40b9d85FUNC<unknown>HIDDEN2
                                __GI_memchr.symtab0x408ce0236FUNC<unknown>HIDDEN2
                                __GI_memcpy.symtab0x404b60102FUNC<unknown>HIDDEN2
                                __GI_memmove.symtab0x408dcc702FUNC<unknown>HIDDEN2
                                __GI_mempcpy.symtab0x408b7090FUNC<unknown>HIDDEN2
                                __GI_memrchr.symtab0x40908c233FUNC<unknown>HIDDEN2
                                __GI_memset.symtab0x404bd0210FUNC<unknown>HIDDEN2
                                __GI_mmap.symtab0x40716048FUNC<unknown>HIDDEN2
                                __GI_mremap.symtab0x409bb442FUNC<unknown>HIDDEN2
                                __GI_munmap.symtab0x40723c38FUNC<unknown>HIDDEN2
                                __GI_nanosleep.symtab0x40726438FUNC<unknown>HIDDEN2
                                __GI_ntohl.symtab0x4053955FUNC<unknown>HIDDEN2
                                __GI_ntohs.symtab0x40538d8FUNC<unknown>HIDDEN2
                                __GI_open.symtab0x403774106FUNC<unknown>HIDDEN2
                                __GI_opendir.symtab0x407461157FUNC<unknown>HIDDEN2
                                __GI_poll.symtab0x40b93441FUNC<unknown>HIDDEN2
                                __GI_raise.symtab0x4096a018FUNC<unknown>HIDDEN2
                                __GI_random.symtab0x40649072FUNC<unknown>HIDDEN2
                                __GI_random_r.symtab0x40669390FUNC<unknown>HIDDEN2
                                __GI_rawmemchr.symtab0x40a1e4189FUNC<unknown>HIDDEN2
                                __GI_read.symtab0x4037e039FUNC<unknown>HIDDEN2
                                __GI_readdir64.symtab0x407574143FUNC<unknown>HIDDEN2
                                __GI_recv.symtab0x4054f011FUNC<unknown>HIDDEN2
                                __GI_recvfrom.symtab0x4054fc45FUNC<unknown>HIDDEN2
                                __GI_sbrk.symtab0x40728c74FUNC<unknown>HIDDEN2
                                __GI_select.symtab0x40380844FUNC<unknown>HIDDEN2
                                __GI_send.symtab0x40552c11FUNC<unknown>HIDDEN2
                                __GI_sendto.symtab0x40553848FUNC<unknown>HIDDEN2
                                __GI_setsid.symtab0x40383438FUNC<unknown>HIDDEN2
                                __GI_setsockopt.symtab0x40556853FUNC<unknown>HIDDEN2
                                __GI_setstate_r.symtab0x4065e8171FUNC<unknown>HIDDEN2
                                __GI_sigaction.symtab0x4070ed114FUNC<unknown>HIDDEN2
                                __GI_signal.symtab0x4055d0133FUNC<unknown>HIDDEN2
                                __GI_sigprocmask.symtab0x4072d847FUNC<unknown>HIDDEN2
                                __GI_sleep.symtab0x406a34142FUNC<unknown>HIDDEN2
                                __GI_socket.symtab0x4055a047FUNC<unknown>HIDDEN2
                                __GI_sprintf.symtab0x4038d4149FUNC<unknown>HIDDEN2
                                __GI_srandom_r.symtab0x4066ed183FUNC<unknown>HIDDEN2
                                __GI_stat.symtab0x40b96079FUNC<unknown>HIDDEN2
                                __GI_stat64.symtab0x40b96079FUNC<unknown>HIDDEN2
                                __GI_strcasecmp.symtab0x4052b848FUNC<unknown>HIDDEN2
                                __GI_strchr.symtab0x404cb0417FUNC<unknown>HIDDEN2
                                __GI_strchrnul.symtab0x409178268FUNC<unknown>HIDDEN2
                                __GI_strcmp.symtab0x404e5433FUNC<unknown>HIDDEN2
                                __GI_strcoll.symtab0x404e5433FUNC<unknown>HIDDEN2
                                __GI_strcpy.symtab0x404e80213FUNC<unknown>HIDDEN2
                                __GI_strcspn.symtab0x408bd0135FUNC<unknown>HIDDEN2
                                __GI_strdup.symtab0x40b9e054FUNC<unknown>HIDDEN2
                                __GI_strlen.symtab0x404f60225FUNC<unknown>HIDDEN2
                                __GI_strncpy.symtab0x40a2a4131FUNC<unknown>HIDDEN2
                                __GI_strnlen.symtab0x405044201FUNC<unknown>HIDDEN2
                                __GI_strpbrk.symtab0x40a158140FUNC<unknown>HIDDEN2
                                __GI_strrchr.symtab0x40928453FUNC<unknown>HIDDEN2
                                __GI_strspn.symtab0x408c58135FUNC<unknown>HIDDEN2
                                __GI_strstr.symtab0x405110193FUNC<unknown>HIDDEN2
                                __GI_strtok.symtab0x4052e810FUNC<unknown>HIDDEN2
                                __GI_strtok_r.symtab0x4092bc94FUNC<unknown>HIDDEN2
                                __GI_strtol.symtab0x40687410FUNC<unknown>HIDDEN2
                                __GI_strtoll.symtab0x40687410FUNC<unknown>HIDDEN2
                                __GI_sysconf.symtab0x406ba3560FUNC<unknown>HIDDEN2
                                __GI_tcgetattr.symtab0x405310110FUNC<unknown>HIDDEN2
                                __GI_time.symtab0x40385c8FUNC<unknown>HIDDEN2
                                __GI_toupper.symtab0x4038ac30FUNC<unknown>HIDDEN2
                                __GI_uname.symtab0x40b9b038FUNC<unknown>HIDDEN2
                                __GI_vsnprintf.symtab0x40396c189FUNC<unknown>HIDDEN2
                                __GI_wait4.symtab0x40730847FUNC<unknown>HIDDEN2
                                __GI_waitpid.symtab0x4038647FUNC<unknown>HIDDEN2
                                __GI_wcrtomb.symtab0x40792868FUNC<unknown>HIDDEN2
                                __GI_wcsnrtombs.symtab0x40797c123FUNC<unknown>HIDDEN2
                                __GI_wcsrtombs.symtab0x40796c15FUNC<unknown>HIDDEN2
                                __GI_write.symtab0x40386c42FUNC<unknown>HIDDEN2
                                __JCR_END__.symtab0x612d500OBJECT<unknown>DEFAULT8
                                __JCR_LIST__.symtab0x612d500OBJECT<unknown>DEFAULT8
                                __app_fini.symtab0x6196488OBJECT<unknown>HIDDEN10
                                __atexit_lock.symtab0x61331040OBJECT<unknown>DEFAULT9
                                __bss_start.symtab0x6133680NOTYPE<unknown>DEFAULTSHN_ABS
                                __check_one_fd.symtab0x406e3a53FUNC<unknown>DEFAULT2
                                __close_nameservers.symtab0x40b510109FUNC<unknown>HIDDEN2
                                __ctype_b.symtab0x612f908OBJECT<unknown>DEFAULT9
                                __ctype_tolower.symtab0x6133588OBJECT<unknown>DEFAULT9
                                __ctype_toupper.symtab0x612fa08OBJECT<unknown>DEFAULT9
                                __curbrk.symtab0x6196608OBJECT<unknown>HIDDEN10
                                __data_start.symtab0x612d700NOTYPE<unknown>DEFAULT9
                                __decode_dotted.symtab0x40a898280FUNC<unknown>HIDDEN2
                                __decode_header.symtab0x40badc156FUNC<unknown>HIDDEN2
                                __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                __dns_lookup.symtab0x40a9b01853FUNC<unknown>HIDDEN2
                                __do_global_ctors_aux.symtab0x40beb00FUNC<unknown>DEFAULT2
                                __do_global_dtors_aux.symtab0x4001000FUNC<unknown>DEFAULT2
                                __dso_handle.symtab0x612d600OBJECT<unknown>HIDDEN9
                                __encode_dotted.symtab0x40be04162FUNC<unknown>HIDDEN2
                                __encode_header.symtab0x40ba18193FUNC<unknown>HIDDEN2
                                __encode_question.symtab0x40bb7880FUNC<unknown>HIDDEN2
                                __environ.symtab0x6196388OBJECT<unknown>DEFAULT10
                                __errno_location.symtab0x4038cc6FUNC<unknown>DEFAULT2
                                __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __exit_cleanup.symtab0x6196288OBJECT<unknown>HIDDEN10
                                __fcntl_nocancel.symtab0x4035cc100FUNC<unknown>DEFAULT2
                                __fgetc_unlocked.symtab0x408a14222FUNC<unknown>DEFAULT2
                                __fini_array_end.symtab0x612d2c0NOTYPE<unknown>HIDDEN5
                                __fini_array_start.symtab0x612d2c0NOTYPE<unknown>HIDDEN5
                                __get_hosts_byname_r.symtab0x40b58048FUNC<unknown>HIDDEN2
                                __getdents.symtab0x409de4288FUNC<unknown>HIDDEN2
                                __getdents64.symtab0x409de4288FUNC<unknown>HIDDEN2
                                __getpagesize.symtab0x4071f819FUNC<unknown>DEFAULT2
                                __glibc_strerror_r.symtab0x4051d414FUNC<unknown>DEFAULT2
                                __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __h_errno_location.symtab0x4076046FUNC<unknown>DEFAULT2
                                __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __init_array_end.symtab0x612d2c0NOTYPE<unknown>HIDDEN5
                                __init_array_start.symtab0x612d2c0NOTYPE<unknown>HIDDEN5
                                __libc_close.symtab0x40368441FUNC<unknown>DEFAULT2
                                __libc_connect.symtab0x40546443FUNC<unknown>DEFAULT2
                                __libc_fcntl.symtab0x403568100FUNC<unknown>DEFAULT2
                                __libc_fork.symtab0x4036b038FUNC<unknown>DEFAULT2
                                __libc_lseek.symtab0x40bdd445FUNC<unknown>DEFAULT2
                                __libc_lseek64.symtab0x40b9d85FUNC<unknown>DEFAULT2
                                __libc_nanosleep.symtab0x40726438FUNC<unknown>DEFAULT2
                                __libc_open.symtab0x403774106FUNC<unknown>DEFAULT2
                                __libc_read.symtab0x4037e039FUNC<unknown>DEFAULT2
                                __libc_recv.symtab0x4054f011FUNC<unknown>DEFAULT2
                                __libc_recvfrom.symtab0x4054fc45FUNC<unknown>DEFAULT2
                                __libc_select.symtab0x40380844FUNC<unknown>DEFAULT2
                                __libc_send.symtab0x40552c11FUNC<unknown>DEFAULT2
                                __libc_sendto.symtab0x40553848FUNC<unknown>DEFAULT2
                                __libc_sigaction.symtab0x4070ed114FUNC<unknown>DEFAULT2
                                __libc_stack_end.symtab0x6196308OBJECT<unknown>DEFAULT10
                                __libc_waitpid.symtab0x4038647FUNC<unknown>DEFAULT2
                                __libc_write.symtab0x40386c42FUNC<unknown>DEFAULT2
                                __local_nameserver.symtab0x410a1016OBJECT<unknown>HIDDEN4
                                __malloc_consolidate.symtab0x406046407FUNC<unknown>HIDDEN2
                                __malloc_largebin_index.symtab0x4056b4110FUNC<unknown>DEFAULT2
                                __malloc_lock.symtab0x6131d040OBJECT<unknown>DEFAULT9
                                __malloc_state.symtab0x6197601752OBJECT<unknown>DEFAULT10
                                __malloc_trim.symtab0x405fb0150FUNC<unknown>DEFAULT2
                                __nameserver.symtab0x619e588OBJECT<unknown>HIDDEN10
                                __nameservers.symtab0x619e604OBJECT<unknown>HIDDEN10
                                __open_etc_hosts.symtab0x40bbc810FUNC<unknown>HIDDEN2
                                __open_nameservers.symtab0x40b145968FUNC<unknown>HIDDEN2
                                __pagesize.symtab0x6196408OBJECT<unknown>DEFAULT10
                                __preinit_array_end.symtab0x612d2c0NOTYPE<unknown>HIDDEN5
                                __preinit_array_start.symtab0x612d2c0NOTYPE<unknown>HIDDEN5
                                __progname.symtab0x6133408OBJECT<unknown>DEFAULT9
                                __progname_full.symtab0x6133488OBJECT<unknown>DEFAULT9
                                __pthread_initialize_minimal.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                __pthread_mutex_init.symtab0x406dd73FUNC<unknown>DEFAULT2
                                __pthread_mutex_lock.symtab0x406dd43FUNC<unknown>DEFAULT2
                                __pthread_mutex_trylock.symtab0x406dd43FUNC<unknown>DEFAULT2
                                __pthread_mutex_unlock.symtab0x406dd43FUNC<unknown>DEFAULT2
                                __pthread_return_0.symtab0x406dd43FUNC<unknown>DEFAULT2
                                __read_etc_hosts_r.symtab0x40bbd2511FUNC<unknown>HIDDEN2
                                __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                __res_sync.symtab0x619e488OBJECT<unknown>HIDDEN10
                                __resolv_attempts.symtab0x6133651OBJECT<unknown>HIDDEN9
                                __resolv_lock.symtab0x61967040OBJECT<unknown>DEFAULT10
                                __resolv_timeout.symtab0x6133641OBJECT<unknown>HIDDEN9
                                __restore_rt.symtab0x4070e40NOTYPE<unknown>DEFAULT2
                                __rtld_fini.symtab0x6196508OBJECT<unknown>HIDDEN10
                                __searchdomain.symtab0x619e508OBJECT<unknown>HIDDEN10
                                __searchdomains.symtab0x619e644OBJECT<unknown>HIDDEN10
                                __sigaddset.symtab0x40567828FUNC<unknown>DEFAULT2
                                __sigdelset.symtab0x40569430FUNC<unknown>DEFAULT2
                                __sigismember.symtab0x40565832FUNC<unknown>DEFAULT2
                                __stdin.symtab0x612fc88OBJECT<unknown>DEFAULT9
                                __stdio_READ.symtab0x409ff058FUNC<unknown>HIDDEN2
                                __stdio_WRITE.symtab0x407b14171FUNC<unknown>HIDDEN2
                                __stdio_adjust_position.symtab0x40a02c131FUNC<unknown>HIDDEN2
                                __stdio_fwrite.symtab0x407df4259FUNC<unknown>HIDDEN2
                                __stdio_init_mutex.symtab0x403a8b15FUNC<unknown>HIDDEN2
                                __stdio_mutex_initializer.4920.symtab0x40f0b040OBJECT<unknown>DEFAULT4
                                __stdio_rfill.symtab0x40a0b037FUNC<unknown>HIDDEN2
                                __stdio_seek.symtab0x40a13431FUNC<unknown>HIDDEN2
                                __stdio_trans2r_o.symtab0x40a0d890FUNC<unknown>HIDDEN2
                                __stdio_trans2w_o.symtab0x407ef8149FUNC<unknown>HIDDEN2
                                __stdio_wcommit.symtab0x403b2439FUNC<unknown>HIDDEN2
                                __stdout.symtab0x612fd08OBJECT<unknown>DEFAULT9
                                __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __uClibc_fini.symtab0x406df470FUNC<unknown>DEFAULT2
                                __uClibc_init.symtab0x406e6f58FUNC<unknown>DEFAULT2
                                __uClibc_main.symtab0x406ea9570FUNC<unknown>DEFAULT2
                                __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __uclibc_progname.symtab0x6133388OBJECT<unknown>HIDDEN9
                                __xpg_strerror_r.symtab0x4051e4196FUNC<unknown>DEFAULT2
                                __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                __xstat32_conv.symtab0x409c8c172FUNC<unknown>HIDDEN2
                                __xstat64_conv.symtab0x409be0172FUNC<unknown>HIDDEN2
                                __xstat_conv.symtab0x409d38172FUNC<unknown>HIDDEN2
                                _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _bss_custom_printf_spec.symtab0x61941010OBJECT<unknown>DEFAULT10
                                _charpad.symtab0x403b4c77FUNC<unknown>DEFAULT2
                                _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _custom_printf_arginfo.symtab0x6196b080OBJECT<unknown>HIDDEN10
                                _custom_printf_handler.symtab0x61970080OBJECT<unknown>HIDDEN10
                                _custom_printf_spec.symtab0x6131c08OBJECT<unknown>HIDDEN9
                                _dl_aux_init.symtab0x409b1c23FUNC<unknown>DEFAULT2
                                _dl_phdr.symtab0x619e388OBJECT<unknown>DEFAULT10
                                _dl_phnum.symtab0x619e408OBJECT<unknown>DEFAULT10
                                _edata.symtab0x6133680NOTYPE<unknown>DEFAULTSHN_ABS
                                _end.symtab0x619e680NOTYPE<unknown>DEFAULTSHN_ABS
                                _errno.symtab0x6196584OBJECT<unknown>DEFAULT10
                                _exit.symtab0x40363043FUNC<unknown>DEFAULT2
                                _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _fini.symtab0x40bee40FUNC<unknown>DEFAULT3
                                _fixed_buffers.symtab0x6174108192OBJECT<unknown>DEFAULT10
                                _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _fp_out_narrow.symtab0x403b99120FUNC<unknown>DEFAULT2
                                _fpmaxtostr.symtab0x4080e41565FUNC<unknown>HIDDEN2
                                _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _h_errno.symtab0x61965c4OBJECT<unknown>DEFAULT10
                                _init.symtab0x4000e80FUNC<unknown>DEFAULT1
                                _load_inttype.symtab0x407f9085FUNC<unknown>HIDDEN2
                                _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _ppfs_init.symtab0x4042c8114FUNC<unknown>HIDDEN2
                                _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _ppfs_parsespec.symtab0x4045621126FUNC<unknown>HIDDEN2
                                _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _ppfs_prepargs.symtab0x40433c67FUNC<unknown>HIDDEN2
                                _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _ppfs_setargs.symtab0x404380436FUNC<unknown>HIDDEN2
                                _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _promoted_size.symtab0x40453446FUNC<unknown>DEFAULT2
                                _pthread_cleanup_pop_restore.symtab0x406de218FUNC<unknown>DEFAULT2
                                _pthread_cleanup_push_defer.symtab0x406dda8FUNC<unknown>DEFAULT2
                                _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _sigintr.symtab0x6197508OBJECT<unknown>HIDDEN10
                                _start.symtab0x40019442FUNC<unknown>DEFAULT2
                                _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _stdio_fopen.symtab0x407bc0563FUNC<unknown>HIDDEN2
                                _stdio_init.symtab0x403a2c95FUNC<unknown>HIDDEN2
                                _stdio_openlist.symtab0x612fd88OBJECT<unknown>DEFAULT9
                                _stdio_openlist_add_lock.symtab0x612fe040OBJECT<unknown>DEFAULT9
                                _stdio_openlist_dec_use.symtab0x4087f8216FUNC<unknown>HIDDEN2
                                _stdio_openlist_del_count.symtab0x6174044OBJECT<unknown>DEFAULT10
                                _stdio_openlist_del_lock.symtab0x61301040OBJECT<unknown>DEFAULT9
                                _stdio_openlist_use_count.symtab0x6174004OBJECT<unknown>DEFAULT10
                                _stdio_streams.symtab0x613040384OBJECT<unknown>DEFAULT9
                                _stdio_term.symtab0x403a9a135FUNC<unknown>HIDDEN2
                                _stdio_user_locking.symtab0x6130384OBJECT<unknown>DEFAULT9
                                _stdlib_strto_l.symtab0x406880339FUNC<unknown>HIDDEN2
                                _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _store_inttype.symtab0x407fe846FUNC<unknown>HIDDEN2
                                _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _string_syserrmsgs.symtab0x40f1b02906OBJECT<unknown>HIDDEN4
                                _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _uintmaxtostr.symtab0x408018201FUNC<unknown>HIDDEN2
                                _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _vfprintf_internal.symtab0x403c111716FUNC<unknown>HIDDEN2
                                _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                abort.symtab0x4063bc200FUNC<unknown>DEFAULT2
                                abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                atoi.symtab0x40686018FUNC<unknown>DEFAULT2
                                atoi.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                bcopy.symtab0x4052a814FUNC<unknown>DEFAULT2
                                bcopy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                been_there_done_that.symtab0x6196204OBJECT<unknown>DEFAULT10
                                bot.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                brk.symtab0x409b3443FUNC<unknown>DEFAULT2
                                brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                bsd_signal.symtab0x4055d0133FUNC<unknown>DEFAULT2
                                buf.3312.symtab0x61943016OBJECT<unknown>DEFAULT10
                                buf.5843.symtab0x619440448OBJECT<unknown>DEFAULT10
                                bzero.symtab0x404a80210FUNC<unknown>DEFAULT2
                                c.symtab0x612f7c4OBJECT<unknown>DEFAULT9
                                calloc.symtab0x4096b4248FUNC<unknown>DEFAULT2
                                calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                chdir.symtab0x40365c38FUNC<unknown>DEFAULT2
                                chdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                clock_getres.symtab0x40719041FUNC<unknown>DEFAULT2
                                clock_getres.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                close.symtab0x40368441FUNC<unknown>DEFAULT2
                                close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                closedir.symtab0x407338147FUNC<unknown>DEFAULT2
                                closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                closenameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                commServer.symtab0x612d808OBJECT<unknown>DEFAULT9
                                completed.5156.symtab0x6133801OBJECT<unknown>DEFAULT10
                                connect.symtab0x40546443FUNC<unknown>DEFAULT2
                                connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                connectTimeout.symtab0x4010c3582FUNC<unknown>DEFAULT2
                                crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                currentServer.symtab0x612f784OBJECT<unknown>DEFAULT9
                                data_start.symtab0x612d700NOTYPE<unknown>DEFAULT9
                                decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                dns.symtab0x612d888OBJECT<unknown>DEFAULT9
                                dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                environ.symtab0x6196388OBJECT<unknown>DEFAULT10
                                errno.symtab0x6196584OBJECT<unknown>DEFAULT10
                                errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                exit.symtab0x4069d495FUNC<unknown>DEFAULT2
                                exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                exp10_table.symtab0x410870208OBJECT<unknown>DEFAULT4
                                fclose.symtab0x4079f8269FUNC<unknown>DEFAULT2
                                fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fcntl.symtab0x403568100FUNC<unknown>DEFAULT2
                                fd_to_DIR.symtab0x4073cc149FUNC<unknown>DEFAULT2
                                fdgets.symtab0x400323130FUNC<unknown>DEFAULT2
                                fdopendir.symtab0x4074fe115FUNC<unknown>DEFAULT2
                                fflush_unlocked.symtab0x4088d0322FUNC<unknown>DEFAULT2
                                fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fgetc.symtab0x408704128FUNC<unknown>DEFAULT2
                                fgetc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fgetc_unlocked.symtab0x408a14222FUNC<unknown>DEFAULT2
                                fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fgets.symtab0x408784116FUNC<unknown>DEFAULT2
                                fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fgets_unlocked.symtab0x408af4116FUNC<unknown>DEFAULT2
                                fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fmt.symtab0x41085020OBJECT<unknown>DEFAULT4
                                fopen.symtab0x407b0810FUNC<unknown>DEFAULT2
                                fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fork.symtab0x4036b038FUNC<unknown>DEFAULT2
                                fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fputs_unlocked.symtab0x4049c856FUNC<unknown>DEFAULT2
                                fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                frame_dummy.symtab0x4001500FUNC<unknown>DEFAULT2
                                free.symtab0x4061dd451FUNC<unknown>DEFAULT2
                                free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fseek.symtab0x409f045FUNC<unknown>DEFAULT2
                                fseeko.symtab0x409f045FUNC<unknown>DEFAULT2
                                fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fseeko64.symtab0x409f0c225FUNC<unknown>DEFAULT2
                                fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fstat.symtab0x409b6082FUNC<unknown>DEFAULT2
                                fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                fstat64.symtab0x409b6082FUNC<unknown>DEFAULT2
                                fwrite_unlocked.symtab0x404a00128FUNC<unknown>DEFAULT2
                                fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getArch.symtab0x4026b911FUNC<unknown>DEFAULT2
                                getHost.symtab0x400e4465FUNC<unknown>DEFAULT2
                                getOurIP.symtab0x4003a5485FUNC<unknown>DEFAULT2
                                getRandomIP.symtab0x4002f447FUNC<unknown>DEFAULT2
                                get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getc.symtab0x408704128FUNC<unknown>DEFAULT2
                                getc_unlocked.symtab0x408a14222FUNC<unknown>DEFAULT2
                                getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getdtablesize.symtab0x4071bc36FUNC<unknown>DEFAULT2
                                getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getegid.symtab0x4071e08FUNC<unknown>DEFAULT2
                                getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                geteuid.symtab0x4071e88FUNC<unknown>DEFAULT2
                                geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getgid.symtab0x4071f08FUNC<unknown>DEFAULT2
                                getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                gethostbyname.symtab0x40541410FUNC<unknown>DEFAULT2
                                gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                gethostbyname2.symtab0x40542065FUNC<unknown>DEFAULT2
                                gethostbyname2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                gethostbyname2_r.symtab0x4093a4761FUNC<unknown>DEFAULT2
                                gethostbyname2_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                gethostbyname_r.symtab0x40b5b0802FUNC<unknown>DEFAULT2
                                gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                gethostname.symtab0x40b8d494FUNC<unknown>DEFAULT2
                                gethostname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getpagesize.symtab0x4071f819FUNC<unknown>DEFAULT2
                                getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getpid.symtab0x4036d88FUNC<unknown>DEFAULT2
                                getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getrlimit.symtab0x40720c40FUNC<unknown>DEFAULT2
                                getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getrlimit64.symtab0x40720c40FUNC<unknown>DEFAULT2
                                getsockname.symtab0x40549041FUNC<unknown>DEFAULT2
                                getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getsockopt.symtab0x4054bc50FUNC<unknown>DEFAULT2
                                getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                getuid.symtab0x4072348FUNC<unknown>DEFAULT2
                                getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                h_errno.symtab0x61965c4OBJECT<unknown>DEFAULT10
                                hoste.5842.symtab0x61960032OBJECT<unknown>DEFAULT10
                                htonl.symtab0x4053885FUNC<unknown>DEFAULT2
                                htons.symtab0x4053808FUNC<unknown>DEFAULT2
                                i.4975.symtab0x612f804OBJECT<unknown>DEFAULT9
                                index.symtab0x404cb0417FUNC<unknown>DEFAULT2
                                inet_addr.symtab0x4053f429FUNC<unknown>DEFAULT2
                                inet_aton.symtab0x40931c135FUNC<unknown>DEFAULT2
                                inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                inet_ntoa.symtab0x4053e910FUNC<unknown>DEFAULT2
                                inet_ntoa.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                inet_ntoa_r.symtab0x40539c77FUNC<unknown>DEFAULT2
                                inet_ntop.symtab0x40a68f518FUNC<unknown>DEFAULT2
                                inet_ntop4.symtab0x40a59c243FUNC<unknown>DEFAULT2
                                inet_pton.symtab0x40a3af493FUNC<unknown>DEFAULT2
                                inet_pton4.symtab0x40a328135FUNC<unknown>DEFAULT2
                                initConnection.symtab0x402f38296FUNC<unknown>DEFAULT2
                                init_rand.symtab0x4001c0126FUNC<unknown>DEFAULT2
                                initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                initstate.symtab0x406532110FUNC<unknown>DEFAULT2
                                initstate_r.symtab0x4067a4185FUNC<unknown>DEFAULT2
                                ioctl.symtab0x4036e0101FUNC<unknown>DEFAULT2
                                ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                isatty.symtab0x4052f425FUNC<unknown>DEFAULT2
                                isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                isspace.symtab0x40389818FUNC<unknown>DEFAULT2
                                isspace.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                kill.symtab0x40374844FUNC<unknown>DEFAULT2
                                kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                last_id.5904.symtab0x6133602OBJECT<unknown>DEFAULT9
                                last_ns_num.5903.symtab0x6196684OBJECT<unknown>DEFAULT10
                                listFork.symtab0x401309211FUNC<unknown>DEFAULT2
                                llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                lseek.symtab0x40bdd445FUNC<unknown>DEFAULT2
                                lseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                lseek64.symtab0x40b9d85FUNC<unknown>DEFAULT2
                                macAddress.symtab0x6133f06OBJECT<unknown>DEFAULT10
                                main.symtab0x4030601285FUNC<unknown>DEFAULT2
                                mainCommSock.symtab0x6133e04OBJECT<unknown>DEFAULT10
                                malloc.symtab0x4057222187FUNC<unknown>DEFAULT2
                                malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                malloc_trim.symtab0x4063a028FUNC<unknown>DEFAULT2
                                memchr.symtab0x408ce0236FUNC<unknown>DEFAULT2
                                memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                memcpy.symtab0x404b60102FUNC<unknown>DEFAULT2
                                memmove.symtab0x408dcc702FUNC<unknown>DEFAULT2
                                memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                mempcpy.symtab0x408b7090FUNC<unknown>DEFAULT2
                                memrchr.symtab0x40908c233FUNC<unknown>DEFAULT2
                                memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                memset.symtab0x404bd0210FUNC<unknown>DEFAULT2
                                mmap.symtab0x40716048FUNC<unknown>DEFAULT2
                                mmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                mremap.symtab0x409bb442FUNC<unknown>DEFAULT2
                                mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                munmap.symtab0x40723c38FUNC<unknown>DEFAULT2
                                munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                mylock.symtab0x61320040OBJECT<unknown>DEFAULT9
                                mylock.symtab0x61323040OBJECT<unknown>DEFAULT9
                                nanosleep.symtab0x40726438FUNC<unknown>DEFAULT2
                                nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                next_start.1699.symtab0x6194208OBJECT<unknown>DEFAULT10
                                nprocessors_onln.symtab0x406ac4223FUNC<unknown>DEFAULT2
                                ntohl.symtab0x4053955FUNC<unknown>DEFAULT2
                                ntohl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                ntohs.symtab0x40538d8FUNC<unknown>DEFAULT2
                                ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                numpids.symtab0x6133e88OBJECT<unknown>DEFAULT10
                                object.5168.symtab0x6133a048OBJECT<unknown>DEFAULT10
                                open.symtab0x403774106FUNC<unknown>DEFAULT2
                                open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                opendir.symtab0x407461157FUNC<unknown>DEFAULT2
                                opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                opennameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                ourIP.symtab0x6196a04OBJECT<unknown>DEFAULT10
                                ovhl7.symtab0x4019c23319FUNC<unknown>DEFAULT2
                                p.5154.symtab0x612d680OBJECT<unknown>DEFAULT9
                                parse_config.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                pids.symtab0x6196a88OBJECT<unknown>DEFAULT10
                                poll.symtab0x40b93441FUNC<unknown>DEFAULT2
                                poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                prefix.5143.symtab0x40f0e812OBJECT<unknown>DEFAULT4
                                print.symtab0x4008b31084FUNC<unknown>DEFAULT2
                                printchar.symtab0x40064075FUNC<unknown>DEFAULT2
                                printi.symtab0x400772321FUNC<unknown>DEFAULT2
                                prints.symtab0x40068b231FUNC<unknown>DEFAULT2
                                processCmd.symtab0x4026c42164FUNC<unknown>DEFAULT2
                                program_invocation_name.symtab0x6133488OBJECT<unknown>DEFAULT9
                                program_invocation_short_name.symtab0x6133408OBJECT<unknown>DEFAULT9
                                qual_chars.5150.symtab0x40f10020OBJECT<unknown>DEFAULT4
                                raise.symtab0x4096a018FUNC<unknown>DEFAULT2
                                raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                rand.symtab0x40648411FUNC<unknown>DEFAULT2
                                rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                rand_cmwc.symtab0x40023e182FUNC<unknown>DEFAULT2
                                random.symtab0x40649072FUNC<unknown>DEFAULT2
                                random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                random_poly_info.symtab0x40fd1040OBJECT<unknown>DEFAULT4
                                random_r.symtab0x40669390FUNC<unknown>DEFAULT2
                                random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                randtbl.symtab0x613290128OBJECT<unknown>DEFAULT9
                                rawmemchr.symtab0x40a1e4189FUNC<unknown>DEFAULT2
                                rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                read.symtab0x4037e039FUNC<unknown>DEFAULT2
                                read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                read_etc_hosts_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                readdir64.symtab0x407574143FUNC<unknown>DEFAULT2
                                readdir64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                realloc.symtab0x4097ac878FUNC<unknown>DEFAULT2
                                realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                recv.symtab0x4054f011FUNC<unknown>DEFAULT2
                                recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                recvLine.symtab0x400e85574FUNC<unknown>DEFAULT2
                                recvfrom.symtab0x4054fc45FUNC<unknown>DEFAULT2
                                recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                resolv_conf_mtime.5885.symtab0x6196984OBJECT<unknown>DEFAULT10
                                rindex.symtab0x40928453FUNC<unknown>DEFAULT2
                                sbrk.symtab0x40728c74FUNC<unknown>DEFAULT2
                                sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                select.symtab0x40380844FUNC<unknown>DEFAULT2
                                select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                send.symtab0x40552c11FUNC<unknown>DEFAULT2
                                send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                sendto.symtab0x40553848FUNC<unknown>DEFAULT2
                                sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                setsid.symtab0x40383438FUNC<unknown>DEFAULT2
                                setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                setsockopt.symtab0x40556853FUNC<unknown>DEFAULT2
                                setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                setstate.symtab0x4064d890FUNC<unknown>DEFAULT2
                                setstate_r.symtab0x4065e8171FUNC<unknown>DEFAULT2
                                sigaction.symtab0x4070ed114FUNC<unknown>DEFAULT2
                                sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                signal.symtab0x4055d0133FUNC<unknown>DEFAULT2
                                signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                sigprocmask.symtab0x4072d847FUNC<unknown>DEFAULT2
                                sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                skip_and_NUL_space.symtab0x40b11944FUNC<unknown>DEFAULT2
                                skip_nospace.symtab0x40b0f041FUNC<unknown>DEFAULT2
                                sleep.symtab0x406a34142FUNC<unknown>DEFAULT2
                                sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                socket.symtab0x4055a047FUNC<unknown>DEFAULT2
                                socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                socket_connect.symtab0x4013dc216FUNC<unknown>DEFAULT2
                                sockprintf.symtab0x400cef341FUNC<unknown>DEFAULT2
                                spec_and_mask.5149.symtab0x40f12016OBJECT<unknown>DEFAULT4
                                spec_base.5142.symtab0x40f0f47OBJECT<unknown>DEFAULT4
                                spec_chars.5146.symtab0x40f18021OBJECT<unknown>DEFAULT4
                                spec_flags.5145.symtab0x40f1988OBJECT<unknown>DEFAULT4
                                spec_or_mask.5148.symtab0x40f13016OBJECT<unknown>DEFAULT4
                                spec_ranges.5147.symtab0x40f1409OBJECT<unknown>DEFAULT4
                                sprintf.symtab0x4038d4149FUNC<unknown>DEFAULT2
                                sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                srand.symtab0x4065a072FUNC<unknown>DEFAULT2
                                srandom.symtab0x4065a072FUNC<unknown>DEFAULT2
                                srandom_r.symtab0x4066ed183FUNC<unknown>DEFAULT2
                                stat.symtab0x40b96079FUNC<unknown>DEFAULT2
                                stat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                stat64.symtab0x40b96079FUNC<unknown>DEFAULT2
                                stderr.symtab0x612fc08OBJECT<unknown>DEFAULT9
                                stdin.symtab0x612fb08OBJECT<unknown>DEFAULT9
                                stdout.symtab0x612fb88OBJECT<unknown>DEFAULT9
                                strcasecmp.symtab0x4052b848FUNC<unknown>DEFAULT2
                                strcasecmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strchr.symtab0x404cb0417FUNC<unknown>DEFAULT2
                                strchrnul.symtab0x409178268FUNC<unknown>DEFAULT2
                                strchrnul.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strcmp.symtab0x404e5433FUNC<unknown>DEFAULT2
                                strcoll.symtab0x404e5433FUNC<unknown>DEFAULT2
                                strcpy.symtab0x404e80213FUNC<unknown>DEFAULT2
                                strcspn.symtab0x408bd0135FUNC<unknown>DEFAULT2
                                strdup.symtab0x40b9e054FUNC<unknown>DEFAULT2
                                strdup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strerror_r.symtab0x4051e4196FUNC<unknown>DEFAULT2
                                strlen.symtab0x404f60225FUNC<unknown>DEFAULT2
                                strncpy.symtab0x40a2a4131FUNC<unknown>DEFAULT2
                                strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strnlen.symtab0x405044201FUNC<unknown>DEFAULT2
                                strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strpbrk.symtab0x40a158140FUNC<unknown>DEFAULT2
                                strrchr.symtab0x40928453FUNC<unknown>DEFAULT2
                                strrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strspn.symtab0x408c58135FUNC<unknown>DEFAULT2
                                strstr.symtab0x405110193FUNC<unknown>DEFAULT2
                                strstr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strtoimax.symtab0x40687410FUNC<unknown>DEFAULT2
                                strtok.symtab0x4052e810FUNC<unknown>DEFAULT2
                                strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strtok_r.symtab0x4092bc94FUNC<unknown>DEFAULT2
                                strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strtol.symtab0x40687410FUNC<unknown>DEFAULT2
                                strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                strtoll.symtab0x40687410FUNC<unknown>DEFAULT2
                                strtoq.symtab0x40687410FUNC<unknown>DEFAULT2
                                sysconf.symtab0x406ba3560FUNC<unknown>DEFAULT2
                                sysconf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                tcgetattr.symtab0x405310110FUNC<unknown>DEFAULT2
                                tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                time.symtab0x40385c8FUNC<unknown>DEFAULT2
                                time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                toupper.symtab0x4038ac30FUNC<unknown>DEFAULT2
                                toupper.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                trim.symtab0x40058a182FUNC<unknown>DEFAULT2
                                type_codes.symtab0x40f15024OBJECT<unknown>DEFAULT4
                                type_sizes.symtab0x40f16812OBJECT<unknown>DEFAULT4
                                uname.symtab0x40b9b038FUNC<unknown>DEFAULT2
                                uname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                unknown.1721.symtab0x40f1a014OBJECT<unknown>DEFAULT4
                                unsafe_state.symtab0x61326040OBJECT<unknown>DEFAULT9
                                useragents.symtab0x612da0472OBJECT<unknown>DEFAULT9
                                vsnprintf.symtab0x40396c189FUNC<unknown>DEFAULT2
                                vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                wait4.symtab0x40730847FUNC<unknown>DEFAULT2
                                wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                waitpid.symtab0x4038647FUNC<unknown>DEFAULT2
                                waitpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                wcrtomb.symtab0x40792868FUNC<unknown>DEFAULT2
                                wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                wcsnrtombs.symtab0x40797c123FUNC<unknown>DEFAULT2
                                wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                wcsrtombs.symtab0x40796c15FUNC<unknown>DEFAULT2
                                wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                write.symtab0x40386c42FUNC<unknown>DEFAULT2
                                write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                xdigits.3743.symtab0x4109a017OBJECT<unknown>DEFAULT4
                                xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                                xtdcustom.symtab0x401649252FUNC<unknown>DEFAULT2
                                TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                2024-12-26T22:20:14.806764+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1558992178.215.238.694258TCP
                                2024-12-26T22:20:17.202231+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1558994178.215.238.694258TCP
                                2024-12-26T22:20:19.577116+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1558996178.215.238.694258TCP
                                2024-12-26T22:20:21.952245+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1558998178.215.238.694258TCP
                                2024-12-26T22:20:24.329141+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559000178.215.238.694258TCP
                                2024-12-26T22:20:26.702488+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559002178.215.238.694258TCP
                                2024-12-26T22:20:29.077830+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559004178.215.238.694258TCP
                                2024-12-26T22:20:31.512932+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559006178.215.238.694258TCP
                                2024-12-26T22:20:33.924478+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559008178.215.238.694258TCP
                                2024-12-26T22:20:36.312085+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559010178.215.238.694258TCP
                                2024-12-26T22:20:38.687679+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559012178.215.238.694258TCP
                                2024-12-26T22:20:41.062133+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559014178.215.238.694258TCP
                                2024-12-26T22:20:43.437587+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559016178.215.238.694258TCP
                                2024-12-26T22:20:45.813135+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559018178.215.238.694258TCP
                                2024-12-26T22:20:48.426343+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559020178.215.238.694258TCP
                                2024-12-26T22:20:50.796356+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559022178.215.238.694258TCP
                                2024-12-26T22:20:53.171394+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559024178.215.238.694258TCP
                                2024-12-26T22:20:55.703528+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559026178.215.238.694258TCP
                                2024-12-26T22:20:58.078014+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559028178.215.238.694258TCP
                                2024-12-26T22:21:00.453497+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559030178.215.238.694258TCP
                                2024-12-26T22:21:02.859460+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559032178.215.238.694258TCP
                                2024-12-26T22:21:05.234373+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559034178.215.238.694258TCP
                                2024-12-26T22:21:07.609764+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559036178.215.238.694258TCP
                                2024-12-26T22:21:09.985000+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559038178.215.238.694258TCP
                                2024-12-26T22:21:12.432365+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559040178.215.238.694258TCP
                                2024-12-26T22:21:14.844199+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559042178.215.238.694258TCP
                                2024-12-26T22:21:17.267711+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559044178.215.238.694258TCP
                                2024-12-26T22:21:19.672116+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559046178.215.238.694258TCP
                                2024-12-26T22:21:22.047237+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559048178.215.238.694258TCP
                                2024-12-26T22:21:24.421491+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559050178.215.238.694258TCP
                                2024-12-26T22:21:26.797469+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559052178.215.238.694258TCP
                                2024-12-26T22:21:29.186733+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559054178.215.238.694258TCP
                                2024-12-26T22:21:31.562707+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559056178.215.238.694258TCP
                                2024-12-26T22:21:33.985001+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559058178.215.238.694258TCP
                                2024-12-26T22:21:36.359748+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559060178.215.238.694258TCP
                                2024-12-26T22:21:38.779553+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559062178.215.238.694258TCP
                                2024-12-26T22:21:41.172847+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559064178.215.238.694258TCP
                                2024-12-26T22:21:43.563194+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559066178.215.238.694258TCP
                                2024-12-26T22:21:45.937736+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559068178.215.238.694258TCP
                                2024-12-26T22:21:48.299875+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559070178.215.238.694258TCP
                                2024-12-26T22:21:50.689644+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559072178.215.238.694258TCP
                                2024-12-26T22:21:53.063565+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559074178.215.238.694258TCP
                                2024-12-26T22:21:55.438514+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559076178.215.238.694258TCP
                                2024-12-26T22:21:57.828906+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559078178.215.238.694258TCP
                                2024-12-26T22:22:00.220209+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559080178.215.238.694258TCP
                                2024-12-26T22:22:02.595534+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559082178.215.238.694258TCP
                                2024-12-26T22:22:04.969883+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559084178.215.238.694258TCP
                                2024-12-26T22:22:07.345312+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559086178.215.238.694258TCP
                                2024-12-26T22:22:09.786933+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559088178.215.238.694258TCP
                                2024-12-26T22:22:12.157758+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559090178.215.238.694258TCP
                                2024-12-26T22:22:14.532718+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559092178.215.238.694258TCP
                                2024-12-26T22:22:16.945010+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559094178.215.238.694258TCP
                                2024-12-26T22:22:19.329382+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559096178.215.238.694258TCP
                                2024-12-26T22:22:21.704439+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559098178.215.238.694258TCP
                                2024-12-26T22:22:24.082345+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559100178.215.238.694258TCP
                                2024-12-26T22:22:26.454148+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559102178.215.238.694258TCP
                                2024-12-26T22:22:29.312982+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559104178.215.238.694258TCP
                                2024-12-26T22:22:31.673832+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559106178.215.238.694258TCP
                                2024-12-26T22:22:34.048941+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559108178.215.238.694258TCP
                                2024-12-26T22:22:36.423448+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559110178.215.238.694258TCP
                                2024-12-26T22:22:38.963073+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559112178.215.238.694258TCP
                                2024-12-26T22:22:41.329579+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559114178.215.238.694258TCP
                                2024-12-26T22:22:43.705460+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559116178.215.238.694258TCP
                                2024-12-26T22:22:46.079766+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559118178.215.238.694258TCP
                                2024-12-26T22:22:48.470450+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559120178.215.238.694258TCP
                                2024-12-26T22:22:50.845930+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559122178.215.238.694258TCP
                                2024-12-26T22:22:53.204929+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559124178.215.238.694258TCP
                                2024-12-26T22:22:55.644423+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559126178.215.238.694258TCP
                                2024-12-26T22:22:58.017939+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559128178.215.238.694258TCP
                                2024-12-26T22:23:00.392484+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559130178.215.238.694258TCP
                                2024-12-26T22:23:02.767727+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559132178.215.238.694258TCP
                                2024-12-26T22:23:05.174401+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559134178.215.238.694258TCP
                                2024-12-26T22:23:07.549633+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559136178.215.238.694258TCP
                                2024-12-26T22:23:09.956077+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559138178.215.238.694258TCP
                                2024-12-26T22:23:12.362325+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559140178.215.238.694258TCP
                                2024-12-26T22:23:14.738144+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559142178.215.238.694258TCP
                                2024-12-26T22:23:17.127882+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559144178.215.238.694258TCP
                                2024-12-26T22:23:19.519269+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559146178.215.238.694258TCP
                                2024-12-26T22:23:21.987304+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559148178.215.238.694258TCP
                                2024-12-26T22:23:24.362253+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559150178.215.238.694258TCP
                                2024-12-26T22:23:26.753133+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559152178.215.238.694258TCP
                                2024-12-26T22:23:29.144197+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559154178.215.238.694258TCP
                                2024-12-26T22:23:31.519376+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559156178.215.238.694258TCP
                                2024-12-26T22:23:33.910365+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559158178.215.238.694258TCP
                                2024-12-26T22:23:36.393345+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559160178.215.238.694258TCP
                                2024-12-26T22:23:38.769096+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559162178.215.238.694258TCP
                                2024-12-26T22:23:41.144173+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559164178.215.238.694258TCP
                                2024-12-26T22:23:43.519092+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559166178.215.238.694258TCP
                                2024-12-26T22:23:45.894747+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559168178.215.238.694258TCP
                                2024-12-26T22:23:48.284964+01002843713ETPRO MALWARE ELF/Mirai Variant CnC Checkin1192.168.2.1559170178.215.238.694258TCP
                                TimestampSource PortDest PortSource IPDest IP
                                Dec 26, 2024 22:20:14.687041044 CET589924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:14.806642056 CET425858992178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:14.806735039 CET589924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:14.806763887 CET589924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:14.926292896 CET425858992178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:17.081938028 CET425858992178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:17.082129955 CET589924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:17.082613945 CET589944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:17.201631069 CET425858992178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:17.202090979 CET425858994178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:17.202230930 CET589944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:17.202230930 CET589944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:17.321856976 CET425858994178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:19.456587076 CET425858994178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:19.456799984 CET589944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:19.457437992 CET589964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:19.576615095 CET425858994178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:19.576968908 CET425858996178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:19.577095032 CET589964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:19.577116013 CET589964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:19.696605921 CET425858996178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:21.831774950 CET425858996178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:21.832082987 CET589964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:21.832564116 CET589984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:21.951682091 CET425858996178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:21.952142954 CET425858998178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:21.952219009 CET589984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:21.952244997 CET589984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:22.071886063 CET425858998178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:24.208686113 CET425858998178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:24.208895922 CET589984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:24.209464073 CET590004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:24.328603029 CET425858998178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:24.328964949 CET425859000178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:24.329102039 CET590004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:24.329140902 CET590004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:24.448695898 CET425859000178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:26.581608057 CET425859000178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:26.581969976 CET590004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:26.582763910 CET590024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:26.701612949 CET425859000178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:26.702265024 CET425859002178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:26.702487946 CET590024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:26.702487946 CET590024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:26.822045088 CET425859002178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:28.957345009 CET425859002178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:28.957564116 CET590024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:28.958189964 CET590044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:29.077094078 CET425859002178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:29.077650070 CET425859004178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:29.077830076 CET590044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:29.077830076 CET590044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:29.197419882 CET425859004178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:31.391506910 CET425859004178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:31.391818047 CET590044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:31.393266916 CET590064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:31.511424065 CET425859004178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:31.512774944 CET425859006178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:31.512871981 CET590064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:31.512932062 CET590064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:31.633487940 CET425859006178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:33.800702095 CET425859006178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:33.800990105 CET590064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:33.801763058 CET590084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:33.921736956 CET425859006178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:33.922348976 CET425859008178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:33.922769070 CET590084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:33.924478054 CET590084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:34.044101000 CET425859008178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:36.191346884 CET425859008178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:36.191565037 CET590084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:36.192193985 CET590104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:36.311105013 CET425859008178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:36.311678886 CET425859010178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:36.311913967 CET590104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:36.312084913 CET590104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:36.431519985 CET425859010178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:38.566709995 CET425859010178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:38.567184925 CET590104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:38.568003893 CET590124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:38.686820984 CET425859010178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:38.687463045 CET425859012178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:38.687598944 CET590124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:38.687679052 CET590124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:38.807328939 CET425859012178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:40.941309929 CET425859012178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:40.941581964 CET590124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:40.942471027 CET590144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:41.061229944 CET425859012178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:41.061969042 CET425859014178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:41.062089920 CET590144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:41.062133074 CET590144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:41.181680918 CET425859014178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:43.316776991 CET425859014178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:43.316970110 CET590144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:43.317569971 CET590164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:43.436585903 CET425859014178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:43.437202930 CET425859016178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:43.437587023 CET590164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:43.437587023 CET590164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:43.557244062 CET425859016178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:45.691673040 CET425859016178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:45.691920996 CET590164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:45.692529917 CET590184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:45.812546968 CET425859016178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:45.812980890 CET425859018178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:45.813134909 CET590184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:45.813134909 CET590184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:45.932706118 CET425859018178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:48.066792965 CET425859018178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:48.067020893 CET590184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:48.067719936 CET590204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:48.426206112 CET425859018178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:48.426223040 CET425859020178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:48.426311970 CET590204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:48.426342964 CET590204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:48.545993090 CET425859020178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:50.676095009 CET425859020178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:50.676261902 CET590204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:50.676744938 CET590224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:50.795831919 CET425859020178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:50.796217918 CET425859022178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:50.796298981 CET590224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:50.796355963 CET590224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:50.916292906 CET425859022178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:53.050616026 CET425859022178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:53.050851107 CET590224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:53.051668882 CET590244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:53.170533895 CET425859022178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:53.171133995 CET425859024178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:53.171377897 CET590244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:53.171394110 CET590244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:53.290950060 CET425859024178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:55.582758904 CET425859024178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:55.583138943 CET590244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:55.583687067 CET590264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:55.702779055 CET425859024178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:55.703299999 CET425859026178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:55.703399897 CET590264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:55.703527927 CET590264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:55.823373079 CET425859026178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:57.957335949 CET425859026178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:57.957547903 CET590264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:57.958421946 CET590284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:58.077091932 CET425859026178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:58.077863932 CET425859028178.215.238.69192.168.2.15
                                Dec 26, 2024 22:20:58.077992916 CET590284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:58.078013897 CET590284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:20:58.197454929 CET425859028178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:00.332948923 CET425859028178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:00.333277941 CET590284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:00.333851099 CET590304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:00.452830076 CET425859028178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:00.453334093 CET425859030178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:00.453464985 CET590304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:00.453496933 CET590304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:00.573043108 CET425859030178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:02.738683939 CET425859030178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:02.738970995 CET590304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:02.739661932 CET590324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:02.858520031 CET425859030178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:02.859343052 CET425859032178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:02.859460115 CET590324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:02.859460115 CET590324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:02.979057074 CET425859032178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:05.114018917 CET425859032178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:05.114245892 CET590324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:05.114763021 CET590344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:05.233912945 CET425859032178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:05.234277010 CET425859034178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:05.234373093 CET590344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:05.234373093 CET590344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:05.354059935 CET425859034178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:07.488765955 CET425859034178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:07.489089012 CET590344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:07.489911079 CET590364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:07.608737946 CET425859034178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:07.609523058 CET425859036178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:07.609678984 CET590364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:07.609764099 CET590364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:07.729250908 CET425859036178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:09.864485979 CET425859036178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:09.864769936 CET590364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:09.865370035 CET590384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:09.984288931 CET425859036178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:09.984889984 CET425859038178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:09.984956026 CET590384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:09.984999895 CET590384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:10.104691982 CET425859038178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:12.312174082 CET425859038178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:12.312359095 CET590384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:12.312858105 CET590404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:12.431914091 CET425859038178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:12.432286978 CET425859040178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:12.432337999 CET590404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:12.432364941 CET590404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:12.552083969 CET425859040178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:14.723587990 CET425859040178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:14.723927021 CET590404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:14.724489927 CET590424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:14.843477964 CET425859040178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:14.844027042 CET425859042178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:14.844197989 CET590424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:14.844198942 CET590424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:14.964775085 CET425859042178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:17.147098064 CET425859042178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:17.147402048 CET590424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:17.148026943 CET590444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:17.267066002 CET425859042178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:17.267570019 CET425859044178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:17.267689943 CET590444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:17.267710924 CET590444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:17.387214899 CET425859044178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:19.551753998 CET425859044178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:19.552035093 CET590444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:19.552480936 CET590464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:19.671703100 CET425859044178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:19.672000885 CET425859046178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:19.672090054 CET590464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:19.672116041 CET590464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:19.791881084 CET425859046178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:21.926724911 CET425859046178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:21.926955938 CET590464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:21.927596092 CET590484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:22.046516895 CET425859046178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:22.047105074 CET425859048178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:22.047178984 CET590484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:22.047236919 CET590484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:22.166815042 CET425859048178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:24.301434994 CET425859048178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:24.301573038 CET590484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:24.301963091 CET590504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:24.421114922 CET425859048178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:24.421430111 CET425859050178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:24.421489954 CET590504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:24.421490908 CET590504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:24.541238070 CET425859050178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:26.676894903 CET425859050178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:26.677098989 CET590504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:26.677683115 CET590524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:26.796818018 CET425859050178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:26.797358990 CET425859052178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:26.797445059 CET590524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:26.797468901 CET590524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:26.916985035 CET425859052178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:29.066358089 CET425859052178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:29.066592932 CET590524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:29.067153931 CET590544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:29.186310053 CET425859052178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:29.186640978 CET425859054178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:29.186733007 CET590544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:29.186733007 CET590544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:29.306353092 CET425859054178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:31.442378998 CET425859054178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:31.442590952 CET590544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:31.443128109 CET590564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:31.562186003 CET425859054178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:31.562585115 CET425859056178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:31.562706947 CET590564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:31.562706947 CET590564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:31.682229042 CET425859056178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:33.864533901 CET425859056178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:33.864695072 CET590564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:33.865313053 CET590584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:33.984266043 CET425859056178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:33.984925985 CET425859058178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:33.984986067 CET590584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:33.985001087 CET590584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:34.104614973 CET425859058178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:36.239255905 CET425859058178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:36.239402056 CET590584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:36.240123987 CET590604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:36.359004021 CET425859058178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:36.359672070 CET425859060178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:36.359747887 CET590604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:36.359747887 CET590604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:36.479286909 CET425859060178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:38.658982038 CET425859060178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:38.659195900 CET590604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:38.659740925 CET590624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:38.778845072 CET425859060178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:38.779452085 CET425859062178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:38.779552937 CET590624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:38.779552937 CET590624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:38.899297953 CET425859062178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:41.051728010 CET425859062178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:41.051928997 CET590624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:41.052424908 CET590644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:41.172673941 CET425859062178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:41.172687054 CET425859064178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:41.172846079 CET590644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:41.172847033 CET590644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:41.292838097 CET425859064178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:43.442799091 CET425859064178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:43.443047047 CET590644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:43.443574905 CET590664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:43.562757969 CET425859064178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:43.563038111 CET425859066178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:43.563121080 CET590664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:43.563194036 CET590664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:43.682698965 CET425859066178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:45.817332029 CET425859066178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:45.817507029 CET590664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:45.817914009 CET590684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:45.937207937 CET425859066178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:45.937575102 CET425859068178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:45.937638044 CET590684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:45.937736034 CET590684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:46.057207108 CET425859068178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:48.178186893 CET425859068178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:48.178412914 CET590684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:48.179183960 CET590704258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:48.298991919 CET425859068178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:48.299721956 CET425859070178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:48.299803019 CET590704258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:48.299875021 CET590704258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:48.419403076 CET425859070178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:50.569107056 CET425859070178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:50.569284916 CET590704258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:50.569976091 CET590724258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:50.688957930 CET425859070178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:50.689522028 CET425859072178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:50.689630985 CET590724258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:50.689644098 CET590724258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:50.809216022 CET425859072178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:52.943039894 CET425859072178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:52.943263054 CET590724258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:52.943881989 CET590744258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:53.062841892 CET425859072178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:53.063463926 CET425859074178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:53.063532114 CET590744258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:53.063565016 CET590744258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:53.183265924 CET425859074178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:55.318104029 CET425859074178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:55.318299055 CET590744258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:55.318830013 CET590764258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:55.437860966 CET425859074178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:55.438397884 CET425859076178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:55.438482046 CET590764258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:55.438513994 CET590764258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:55.558059931 CET425859076178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:57.708455086 CET425859076178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:57.708769083 CET590764258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:57.709331036 CET590784258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:57.828279972 CET425859076178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:57.828752041 CET425859078178.215.238.69192.168.2.15
                                Dec 26, 2024 22:21:57.828855038 CET590784258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:57.828906059 CET590784258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:21:57.948484898 CET425859078178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:00.099498987 CET425859078178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:00.099788904 CET590784258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:00.100444078 CET590804258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:00.219317913 CET425859078178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:00.220007896 CET425859080178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:00.220149994 CET590804258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:00.220208883 CET590804258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:00.342395067 CET425859080178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:02.474930048 CET425859080178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:02.475215912 CET590804258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:02.475915909 CET590824258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:02.594783068 CET425859080178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:02.595395088 CET425859082178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:02.595479012 CET590824258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:02.595534086 CET590824258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:02.715092897 CET425859082178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:04.849339962 CET425859082178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:04.849462032 CET590824258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:04.849936962 CET590844258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:04.969039917 CET425859082178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:04.969710112 CET425859084178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:04.969816923 CET590844258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:04.969882965 CET590844258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:05.089366913 CET425859084178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:07.224384069 CET425859084178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:07.224658012 CET590844258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:07.225526094 CET590864258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:07.344227076 CET425859084178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:07.345012903 CET425859086178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:07.345120907 CET590864258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:07.345312119 CET590864258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:07.464850903 CET425859086178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:09.666093111 CET425859086178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:09.666496038 CET590864258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:09.667190075 CET590884258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:09.786113977 CET425859086178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:09.786711931 CET425859088178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:09.786932945 CET590884258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:09.786932945 CET590884258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:09.906507015 CET425859088178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:12.036710024 CET425859088178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:12.036990881 CET590884258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:12.037888050 CET590904258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:12.156685114 CET425859088178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:12.157468081 CET425859090178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:12.157665014 CET590904258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:12.157757998 CET590904258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:12.277544975 CET425859090178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:14.411920071 CET425859090178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:14.412244081 CET590904258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:14.413139105 CET590924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:14.531853914 CET425859090178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:14.532650948 CET425859092178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:14.532704115 CET590924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:14.532717943 CET590924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:14.652326107 CET425859092178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:16.824825048 CET425859092178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:16.824944973 CET590924258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:16.825427055 CET590944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:16.944550991 CET425859092178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:16.944916964 CET425859094178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:16.944981098 CET590944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:16.945009947 CET590944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:17.064527988 CET425859094178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:19.209028959 CET425859094178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:19.209161997 CET590944258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:19.209764957 CET590964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:19.328704119 CET425859094178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:19.329294920 CET425859096178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:19.329355955 CET590964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:19.329381943 CET590964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:19.448847055 CET425859096178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:21.584072113 CET425859096178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:21.584186077 CET590964258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:21.584738016 CET590984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:21.703841925 CET425859096178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:21.704369068 CET425859098178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:21.704438925 CET590984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:21.704438925 CET590984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:21.824079037 CET425859098178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:23.961782932 CET425859098178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:23.961932898 CET590984258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:23.962426901 CET591004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:24.081703901 CET425859098178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:24.082259893 CET425859100178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:24.082345009 CET591004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:24.082345009 CET591004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:24.201961040 CET425859100178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:26.334047079 CET425859100178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:26.334187031 CET591004258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:26.334583998 CET591024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:26.453751087 CET425859100178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:26.454042912 CET425859102178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:26.454099894 CET591024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:26.454148054 CET591024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:26.573604107 CET425859102178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:28.709126949 CET425859102178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:28.709275007 CET591024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:28.709846973 CET591044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:29.084877014 CET591024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:29.312726021 CET425859102178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:29.312838078 CET425859102178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:29.312844992 CET591024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:29.312849998 CET425859104178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:29.312869072 CET425859102178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:29.312912941 CET591044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:29.312938929 CET591024258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:29.312982082 CET591044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:29.432570934 CET425859104178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:31.552967072 CET425859104178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:31.553348064 CET591044258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:31.554151058 CET591064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:31.672842979 CET425859104178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:31.673614979 CET425859106178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:31.673736095 CET591064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:31.673831940 CET591064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:31.793514967 CET425859106178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:33.928287029 CET425859106178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:33.928523064 CET591064258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:33.929199934 CET591084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:34.048197985 CET425859106178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:34.048727036 CET425859108178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:34.048873901 CET591084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:34.048940897 CET591084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:34.168479919 CET425859108178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:36.302898884 CET425859108178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:36.303219080 CET591084258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:36.303868055 CET591104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:36.422795057 CET425859108178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:36.423304081 CET425859110178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:36.423414946 CET591104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:36.423448086 CET591104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:36.543159008 CET425859110178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:38.842669010 CET425859110178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:38.842927933 CET591104258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:38.843547106 CET591124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:38.962454081 CET425859110178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:38.962980986 CET425859112178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:38.963054895 CET591124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:38.963073015 CET591124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:39.082592964 CET425859112178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:41.209475994 CET425859112178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:41.209614992 CET591124258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:41.210099936 CET591144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:41.329138994 CET425859112178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:41.329509020 CET425859114178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:41.329559088 CET591144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:41.329579115 CET591144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:41.449060917 CET425859114178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:43.584606886 CET425859114178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:43.584897041 CET591144258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:43.585766077 CET591164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:43.704385996 CET425859114178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:43.705269098 CET425859116178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:43.705375910 CET591164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:43.705460072 CET591164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:43.825192928 CET425859116178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:45.959592104 CET425859116178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:45.959731102 CET591164258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:45.960186005 CET591184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:46.079330921 CET425859116178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:46.079648018 CET425859118178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:46.079711914 CET591184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:46.079766035 CET591184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:46.199418068 CET425859118178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:48.350265026 CET425859118178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:48.350406885 CET591184258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:48.350903988 CET591204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:48.469904900 CET425859118178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:48.470372915 CET425859120178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:48.470432043 CET591204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:48.470449924 CET591204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:48.589905024 CET425859120178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:50.725006104 CET425859120178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:50.725145102 CET591204258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:50.725893021 CET591224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:50.845035076 CET425859120178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:50.845860958 CET425859122178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:50.845907927 CET591224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:50.845930099 CET591224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:50.965478897 CET425859122178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:53.084480047 CET425859122178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:53.084650993 CET591224258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:53.085238934 CET591244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:53.204503059 CET425859122178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:53.204818964 CET425859124178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:53.204904079 CET591244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:53.204929113 CET591244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:53.324635029 CET425859124178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:55.523643017 CET425859124178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:55.523895025 CET591244258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:55.524781942 CET591264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:55.643466949 CET425859124178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:55.644256115 CET425859126178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:55.644345045 CET591264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:55.644423008 CET591264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:55.763912916 CET425859126178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:57.897578955 CET425859126178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:57.897731066 CET591264258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:57.898312092 CET591284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:58.017450094 CET425859126178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:58.017870903 CET425859128178.215.238.69192.168.2.15
                                Dec 26, 2024 22:22:58.017939091 CET591284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:58.017939091 CET591284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:22:58.137679100 CET425859128178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:00.272344112 CET425859128178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:00.272439957 CET591284258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:00.272947073 CET591304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:00.392064095 CET425859128178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:00.392409086 CET425859130178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:00.392483950 CET591304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:00.392483950 CET591304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:00.512026072 CET425859130178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:02.647134066 CET425859130178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:02.647299051 CET591304258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:02.647855043 CET591324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:02.766932011 CET425859130178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:02.767534971 CET425859132178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:02.767674923 CET591324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:02.767726898 CET591324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:02.887248993 CET425859132178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:05.053528070 CET425859132178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:05.053817034 CET591324258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:05.054596901 CET591344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:05.173537970 CET425859132178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:05.174252033 CET425859134178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:05.174401045 CET591344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:05.174401045 CET591344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:05.293987989 CET425859134178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:07.429006100 CET425859134178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:07.429313898 CET591344258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:07.429869890 CET591364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:07.549200058 CET425859134178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:07.549483061 CET425859136178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:07.549633026 CET591364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:07.549633026 CET591364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:07.669339895 CET425859136178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:09.834934950 CET425859136178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:09.835222960 CET591364258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:09.835768938 CET591384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:09.955364943 CET425859136178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:09.955921888 CET425859138178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:09.956077099 CET591384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:09.956077099 CET591384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:10.075742006 CET425859138178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:12.241756916 CET425859138178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:12.241996050 CET591384258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:12.242733955 CET591404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:12.361594915 CET425859138178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:12.362191916 CET425859140178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:12.362323999 CET591404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:12.362324953 CET591404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:12.481952906 CET425859140178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:14.616451025 CET425859140178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:14.616702080 CET591404258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:14.617319107 CET591424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:14.737338066 CET425859140178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:14.738013029 CET425859142178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:14.738128901 CET591424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:14.738143921 CET591424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:14.859056950 CET425859142178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:17.007303953 CET425859142178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:17.007529974 CET591424258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:17.008172035 CET591444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:17.127218962 CET425859142178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:17.127737999 CET425859144178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:17.127882004 CET591444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:17.127882004 CET591444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:17.247615099 CET425859144178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:19.398310900 CET425859144178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:19.398706913 CET591444258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:19.399561882 CET591464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:19.518248081 CET425859144178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:19.519000053 CET425859146178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:19.519150019 CET591464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:19.519268990 CET591464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:19.638889074 CET425859146178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:21.866339922 CET425859146178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:21.866657972 CET591464258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:21.867559910 CET591484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:21.986253977 CET425859146178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:21.987122059 CET425859148178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:21.987225056 CET591484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:21.987303972 CET591484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:22.107162952 CET425859148178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:24.241552114 CET425859148178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:24.241741896 CET591484258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:24.242451906 CET591504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:24.361424923 CET425859148178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:24.362008095 CET425859150178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:24.362173080 CET591504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:24.362252951 CET591504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:24.484286070 CET425859150178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:26.632555962 CET425859150178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:26.632781982 CET591504258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:26.633358002 CET591524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:26.752470016 CET425859150178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:26.752830029 CET425859152178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:26.753133059 CET591524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:26.753133059 CET591524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:26.872826099 CET425859152178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:29.023581028 CET425859152178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:29.023848057 CET591524258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:29.024513960 CET591544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:29.143779039 CET425859152178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:29.144033909 CET425859154178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:29.144196033 CET591544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:29.144196987 CET591544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:29.263909101 CET425859154178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:31.398125887 CET425859154178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:31.398545027 CET591544258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:31.399723053 CET591564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:31.518266916 CET425859154178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:31.519229889 CET425859156178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:31.519376040 CET591564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:31.519376040 CET591564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:31.639067888 CET425859156178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:33.788590908 CET425859156178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:33.788882017 CET591564258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:33.789541006 CET591584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:33.909796953 CET425859156178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:33.910049915 CET425859158178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:33.910213947 CET591584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:33.910365105 CET591584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:34.029835939 CET425859158178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:36.272110939 CET425859158178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:36.272466898 CET591584258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:36.273313046 CET591604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:36.392172098 CET425859158178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:36.393054962 CET425859160178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:36.393191099 CET591604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:36.393345118 CET591604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:36.512887001 CET425859160178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:38.648338079 CET425859160178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:38.648672104 CET591604258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:38.649369001 CET591624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:38.768249989 CET425859160178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:38.768898964 CET425859162178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:38.769095898 CET591624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:38.769095898 CET591624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:38.888653994 CET425859162178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:41.023029089 CET425859162178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:41.023370981 CET591624258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:41.024090052 CET591644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:41.143387079 CET425859162178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:41.143861055 CET425859164178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:41.144172907 CET591644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:41.144172907 CET591644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:41.263761997 CET425859164178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:43.398304939 CET425859164178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:43.398605108 CET591644258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:43.399390936 CET591664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:43.518336058 CET425859164178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:43.518802881 CET425859166178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:43.518908024 CET591664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:43.519092083 CET591664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:43.638722897 CET425859166178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:45.773402929 CET425859166178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:45.773782015 CET591664258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:45.774849892 CET591684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:45.893471956 CET425859166178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:45.894509077 CET425859168178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:45.894747019 CET591684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:45.894747019 CET591684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:46.014303923 CET425859168178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:48.163904905 CET425859168178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:48.164226055 CET591684258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:48.165290117 CET591704258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:48.283911943 CET425859168178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:48.284744024 CET425859170178.215.238.69192.168.2.15
                                Dec 26, 2024 22:23:48.284964085 CET591704258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:48.284964085 CET591704258192.168.2.15178.215.238.69
                                Dec 26, 2024 22:23:48.404690981 CET425859170178.215.238.69192.168.2.15
                                TimestampSource PortDest PortSource IPDest IP
                                Dec 26, 2024 22:22:59.576716900 CET4300153192.168.2.158.8.8.8
                                Dec 26, 2024 22:22:59.576755047 CET3316453192.168.2.158.8.8.8
                                Dec 26, 2024 22:22:59.699228048 CET53430018.8.8.8192.168.2.15
                                Dec 26, 2024 22:22:59.699249029 CET53331648.8.8.8192.168.2.15
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Dec 26, 2024 22:22:59.576716900 CET192.168.2.158.8.8.80xdae5Standard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                Dec 26, 2024 22:22:59.576755047 CET192.168.2.158.8.8.80x70edStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Dec 26, 2024 22:22:59.699228048 CET8.8.8.8192.168.2.150xdae5No error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false
                                Dec 26, 2024 22:22:59.699228048 CET8.8.8.8192.168.2.150xdae5No error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false

                                System Behavior

                                Start time (UTC):21:20:13
                                Start date (UTC):26/12/2024
                                Path:/tmp/kitsune.x86.elf
                                Arguments:/tmp/kitsune.x86.elf
                                File size:108630 bytes
                                MD5 hash:afafe44e75da13379d6c74e263213913

                                Start time (UTC):21:20:13
                                Start date (UTC):26/12/2024
                                Path:/tmp/kitsune.x86.elf
                                Arguments:-
                                File size:108630 bytes
                                MD5 hash:afafe44e75da13379d6c74e263213913

                                Start time (UTC):21:20:13
                                Start date (UTC):26/12/2024
                                Path:/tmp/kitsune.x86.elf
                                Arguments:-
                                File size:108630 bytes
                                MD5 hash:afafe44e75da13379d6c74e263213913