Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
Space.mips.elf

Overview

General Information

Sample name:Space.mips.elf
Analysis ID:1581297
MD5:bfaa04ccd012b09be805bd489a4775bb
SHA1:de53bbdf475cdb83582b2018196ad1d4b8719547
SHA256:421d80f8efd39afb7cfa2bc967026786261fd4267497db25bf33e37d5ee88e47
Tags:elfuser-abuse_ch
Infos:

Detection

Score:60
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581297
Start date and time:2024-12-27 10:33:30 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 48s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:Space.mips.elf
Detection:MAL
Classification:mal60.evad.linELF@0/0@0/0
  • VT rate limit hit for: Space.mips.elf
Command:/tmp/Space.mips.elf
PID:6217
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
6217.1.00007ff748400000.00007ff74842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6219.1.00007ff748400000.00007ff74842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6221.1.00007ff748400000.00007ff74842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6227.1.00007ff748400000.00007ff74842c000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x28f4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28f9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x28fec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29000:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29014:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29028:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2903c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29050:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29064:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x29078:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2908c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x290dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: Space.mips.elf PID: 6217Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x3b10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3b9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3bec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3c8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ca0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Click to see the 3 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Space.mips.elfReversingLabs: Detection: 42%
Source: global trafficTCP traffic: 192.168.2.23:53256 -> 159.100.18.129:3778
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: unknownTCP traffic detected without corresponding DNS query: 159.100.18.129
Source: Space.mips.elfString found in binary or memory: http://upx.sf.net
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: 6217.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6219.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6221.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6227.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6217, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6219, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6221, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: Space.mips.elf PID: 6227, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: LOAD without section mappingsProgram segment: 0x100000
Source: 6217.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6219.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6221.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6227.1.00007ff748400000.00007ff74842c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6217, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6219, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6221, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: Space.mips.elf PID: 6227, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal60.evad.linELF@0/0@0/0

Data Obfuscation

barindex
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1582/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/3088/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/230/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/110/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/231/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/111/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/232/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1579/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/112/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/233/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1699/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/113/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/234/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1335/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1698/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/114/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/235/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1334/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1576/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/2302/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/115/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/236/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/116/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/237/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/117/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/118/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/910/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/119/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/912/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/10/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/2307/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/11/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/918/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/12/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/13/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/14/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/15/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/16/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/17/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/18/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1594/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/120/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/121/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1349/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/122/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/243/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/123/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/2/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/124/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/3/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/4/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/125/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/126/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1344/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1465/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1586/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/127/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/6/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/248/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/128/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/249/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1463/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/800/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/9/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/801/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/20/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/21/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1900/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/22/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/23/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/24/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/25/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/26/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/27/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/28/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/29/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/491/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/250/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/130/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/251/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/252/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/132/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/253/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/254/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/255/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/256/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1599/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/257/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1477/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/379/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/258/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1476/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/259/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1475/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/936/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/30/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/2208/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/35/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1809/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/1494/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/260/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/261/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/141/statusJump to behavior
Source: /tmp/Space.mips.elf (PID: 6217)File opened: /proc/262/statusJump to behavior
Source: Space.mips.elfSubmission file: segment LOAD with 7.9489 entropy (max. 8.0)
Source: /tmp/Space.mips.elf (PID: 6217)Queries kernel information via 'uname': Jump to behavior
Source: Space.mips.elf, 6217.1.00007fff40771000.00007fff40792000.rw-.sdmp, Space.mips.elf, 6219.1.00007fff40771000.00007fff40792000.rw-.sdmp, Space.mips.elf, 6221.1.00007fff40771000.00007fff40792000.rw-.sdmp, Space.mips.elf, 6227.1.00007fff40771000.00007fff40792000.rw-.sdmpBinary or memory string: ldq0x86_64/usr/bin/qemu-mips/tmp/Space.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Space.mips.elf
Source: Space.mips.elf, 6217.1.00005593641cc000.0000559364274000.rw-.sdmp, Space.mips.elf, 6219.1.00005593641cc000.0000559364274000.rw-.sdmp, Space.mips.elf, 6221.1.00005593641cc000.0000559364274000.rw-.sdmp, Space.mips.elf, 6227.1.00005593641cc000.0000559364274000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: Space.mips.elf, 6217.1.00005593641cc000.0000559364274000.rw-.sdmp, Space.mips.elf, 6219.1.00005593641cc000.0000559364274000.rw-.sdmp, Space.mips.elf, 6221.1.00005593641cc000.0000559364274000.rw-.sdmp, Space.mips.elf, 6227.1.00005593641cc000.0000559364274000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: Space.mips.elf, 6217.1.00007fff40771000.00007fff40792000.rw-.sdmp, Space.mips.elf, 6219.1.00007fff40771000.00007fff40792000.rw-.sdmp, Space.mips.elf, 6221.1.00007fff40771000.00007fff40792000.rw-.sdmp, Space.mips.elf, 6227.1.00007fff40771000.00007fff40792000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
Obfuscated Files or Information
1
OS Credential Dumping
11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581297 Sample: Space.mips.elf Startdate: 27/12/2024 Architecture: LINUX Score: 60 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 159.100.18.129, 3778, 53256, 53258 DE-FIRSTCOLOwwwfirst-colonetDE Germany 2->22 24 2 other IPs or domains 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Multi AV Scanner detection for submitted file 2->28 30 Sample is packed with UPX 2->30 8 Space.mips.elf 2->8         started        signatures3 process4 process5 10 Space.mips.elf 8->10         started        12 Space.mips.elf 8->12         started        14 Space.mips.elf 8->14         started        process6 16 Space.mips.elf 10->16         started        18 Space.mips.elf 10->18         started       
SourceDetectionScannerLabelLink
Space.mips.elf42%ReversingLabsLinux.Trojan.Multiverze
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://upx.sf.netSpace.mips.elffalse
    high
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    159.100.18.129
    unknownGermany
    44066DE-FIRSTCOLOwwwfirst-colonetDEfalse
    109.202.202.202
    unknownSwitzerland
    13030INIT7CHfalse
    91.189.91.43
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    91.189.91.42
    unknownUnited Kingdom
    41231CANONICAL-ASGBfalse
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43sh4.nn.elfGet hashmaliciousOkiruBrowse
      mipsel.nn.elfGet hashmaliciousOkiruBrowse
        powerpc.nn.elfGet hashmaliciousOkiruBrowse
          db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
            RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
              RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                  db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                    db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                      db0fa4b8db0333367e9bda3ab68b8042.arm.elfGet hashmaliciousUnknownBrowse
                        91.189.91.42sh4.nn.elfGet hashmaliciousOkiruBrowse
                          mipsel.nn.elfGet hashmaliciousOkiruBrowse
                            powerpc.nn.elfGet hashmaliciousOkiruBrowse
                              db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                  RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                    RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                      db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                        db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                          db0fa4b8db0333367e9bda3ab68b8042.arm.elfGet hashmaliciousUnknownBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBarm6.nn.elfGet hashmaliciousOkiruBrowse
                                            • 185.125.190.26
                                            sh4.nn.elfGet hashmaliciousOkiruBrowse
                                            • 91.189.91.42
                                            mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                            • 91.189.91.42
                                            powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                            • 91.189.91.42
                                            db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            RpcSecurity.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            RpcSecurity.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            INIT7CHsh4.nn.elfGet hashmaliciousOkiruBrowse
                                            • 109.202.202.202
                                            mipsel.nn.elfGet hashmaliciousOkiruBrowse
                                            • 109.202.202.202
                                            powerpc.nn.elfGet hashmaliciousOkiruBrowse
                                            • 109.202.202.202
                                            db0fa4b8db0333367e9bda3ab68b8042.mpsl.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            RpcSecurity.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            RpcSecurity.arc.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            RpcSecurity.sh4.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            db0fa4b8db0333367e9bda3ab68b8042.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            db0fa4b8db0333367e9bda3ab68b8042.ppc.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            db0fa4b8db0333367e9bda3ab68b8042.arm.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            DE-FIRSTCOLOwwwfirst-colonetDEboatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            159.100.14.33-boatnet.arm-2024-12-25T14_31_19.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            159.100.14.33-boatnet.arm7-2024-12-25T14_32_39.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            159.100.14.33-boatnet.m68k-2024-12-25T14_31_19.elfGet hashmaliciousMiraiBrowse
                                            • 159.100.14.33
                                            hidakibest.x86.elfGet hashmaliciousMirai, GafgytBrowse
                                            • 31.172.83.147
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header
                                            Entropy (8bit):7.946681228262986
                                            TrID:
                                            • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                            • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                            File name:Space.mips.elf
                                            File size:44'188 bytes
                                            MD5:bfaa04ccd012b09be805bd489a4775bb
                                            SHA1:de53bbdf475cdb83582b2018196ad1d4b8719547
                                            SHA256:421d80f8efd39afb7cfa2bc967026786261fd4267497db25bf33e37d5ee88e47
                                            SHA512:a6da645dba966dd2aed51876d49462c3af0a8847941da447110cb145e5fea372d184705ade19ac56d5d6741a5923bfeb3f94b9c2c539f0588d92f91c12c05fb6
                                            SSDEEP:768:M6DfzzMwdu3W4CbuznqQd8eYkGyJfH6QhjS0jlDGnHMhgNSRxUkCkHhVeg527FvM:tDEwdu3ubuznqreGyJfH6QhjDGnHMhg4
                                            TLSH:0D13F194370341EACB59D8F487F403627B761FF9618A8C087CA1DBE1AAE144CBCE4AD4
                                            File Content Preview:.ELF.......................(...4.........4. ...(.......................l...l.................C...C......................UPX!.d.....................V.......?.E.h4...@b..) ..]....E..`..........@4#.Y..~.9....b...Q".|.H.%Q.z....6u.."....cLw...................

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, big endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x109828
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:2
                                            Section Header Offset:0
                                            Section Header Size:40
                                            Number of Section Headers:0
                                            Header String Table Index:0
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x1000000x1000000xab6c0xab6c7.94890x5R E0x10000
                                            LOAD0xcffc0x43cffc0x43cffc0x00x00.00000x6RW 0x10000
                                            TimestampSource PortDest PortSource IPDest IP
                                            Dec 27, 2024 10:34:13.124886036 CET532563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:13.192795038 CET43928443192.168.2.2391.189.91.42
                                            Dec 27, 2024 10:34:13.244786024 CET377853256159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:13.244899988 CET532563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:13.261069059 CET532563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:13.380534887 CET377853256159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:13.380589008 CET532563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:13.500195980 CET377853256159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:14.603192091 CET377853256159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:14.603451967 CET532563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:14.603728056 CET532563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:14.604331970 CET532583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:14.725167036 CET377853258159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:14.725502014 CET532583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:14.726824045 CET532583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:14.846286058 CET377853258159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:14.846544981 CET532583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:14.966109037 CET377853258159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:15.984077930 CET377853258159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:15.984345913 CET532583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:15.984384060 CET532583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:15.984930992 CET532603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:16.104708910 CET377853260159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:16.104845047 CET532603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:16.105570078 CET532603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:16.225092888 CET377853260159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:16.225491047 CET532603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:16.345124960 CET377853260159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:17.418056965 CET377853260159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:17.418399096 CET532603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:17.418399096 CET532603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:17.418884039 CET532623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:17.538431883 CET377853262159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:17.538646936 CET532623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:17.539330959 CET532623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:17.658864021 CET377853262159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:17.659275055 CET532623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:17.779122114 CET377853262159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:18.568073988 CET42836443192.168.2.2391.189.91.43
                                            Dec 27, 2024 10:34:18.726412058 CET532643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.843786001 CET377853262159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:18.843857050 CET532623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.843905926 CET532623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.844513893 CET532663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.846163988 CET377853264159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:18.846205950 CET532643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.861366987 CET532643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.964170933 CET377853266159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:18.964226007 CET532663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.966634989 CET532663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:18.980891943 CET377853264159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:18.980950117 CET532643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:19.086097956 CET377853266159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:19.086208105 CET532663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:19.100518942 CET377853264159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:19.205796003 CET377853266159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.103872061 CET4251680192.168.2.23109.202.202.202
                                            Dec 27, 2024 10:34:20.153934002 CET377853264159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.154155016 CET532643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.154294014 CET532643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.154886961 CET532683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.269536972 CET377853266159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.269887924 CET532663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.269887924 CET532663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.270322084 CET532703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.274353027 CET377853268159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.274429083 CET532683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.275481939 CET532683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.389776945 CET377853270159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.390047073 CET532703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.391448021 CET532703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.394958019 CET377853268159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.395010948 CET532683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.510883093 CET377853270159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.511168003 CET532703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:20.514456987 CET377853268159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:20.630719900 CET377853270159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:21.579778910 CET377853268159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:21.579898119 CET532683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.579929113 CET532683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.580528021 CET532723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.695616961 CET377853270159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:21.695712090 CET532703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.695761919 CET532703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.696439981 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.699994087 CET377853272159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:21.700078964 CET532723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.701385975 CET532723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.815951109 CET377853274159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:21.816154003 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.817718983 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.820847988 CET377853272159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:21.821202993 CET532723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.937282085 CET377853274159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:21.937432051 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:21.940654993 CET377853272159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:22.057177067 CET377853274159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:23.006273985 CET377853272159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:23.006408930 CET532723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:23.006669044 CET532723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:23.007144928 CET532763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:23.126713037 CET377853276159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:23.126816988 CET532763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:23.127912998 CET532763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:23.247370958 CET377853276159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:23.247476101 CET532763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:23.366933107 CET377853276159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:24.478856087 CET377853276159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:24.479012966 CET532763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:24.479131937 CET532763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:24.479806900 CET532783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:24.599419117 CET377853278159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:24.599653006 CET532783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:24.600780964 CET532783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:24.720562935 CET377853278159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:24.720776081 CET532783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:24.840447903 CET377853278159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:25.951848030 CET377853278159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:25.952096939 CET532783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:25.952096939 CET532783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:25.952737093 CET532803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:26.072256088 CET377853280159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:26.072443962 CET532803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:26.076456070 CET532803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:26.195930004 CET377853280159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:26.196094990 CET532803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:26.315553904 CET377853280159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:27.380213022 CET377853280159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:27.380379915 CET532803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:27.380420923 CET532803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:27.380951881 CET532823778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:27.500560045 CET377853282159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:27.500817060 CET532823778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:27.502445936 CET532823778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:27.621963978 CET377853282159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:27.622092962 CET532823778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:27.741698980 CET377853282159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:28.807764053 CET377853282159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:28.807909012 CET532823778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:28.807945967 CET532823778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:28.808703899 CET532843778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:28.928162098 CET377853284159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:28.928291082 CET532843778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:28.929689884 CET532843778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:29.049249887 CET377853284159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:29.049418926 CET532843778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:29.168979883 CET377853284159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:30.239130974 CET377853284159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:30.239289999 CET532843778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:30.239398956 CET532843778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:30.240139961 CET532863778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:30.359875917 CET377853286159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:30.359994888 CET532863778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:30.361330986 CET532863778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:30.480829954 CET377853286159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:30.480992079 CET532863778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:30.600569963 CET377853286159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:31.618030071 CET377853286159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:31.618263960 CET532863778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:31.618263960 CET532863778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:31.618891001 CET532883778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:31.738444090 CET377853288159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:31.738588095 CET532883778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:31.740215063 CET532883778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:31.826513052 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:31.859648943 CET377853288159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:31.859729052 CET532883778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:31.946050882 CET377853274159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:31.979208946 CET377853288159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:32.235919952 CET377853274159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:32.236203909 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:33.043381929 CET377853288159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:33.043623924 CET532883778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:33.043623924 CET532883778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:33.044868946 CET532903778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:33.164374113 CET377853290159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:33.164648056 CET532903778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:33.166021109 CET532903778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:33.285475969 CET377853290159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:33.285612106 CET532903778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:33.405332088 CET377853290159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:33.925966024 CET43928443192.168.2.2391.189.91.42
                                            Dec 27, 2024 10:34:34.469228983 CET377853290159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:34.469371080 CET532903778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:34.469448090 CET532903778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:34.470191002 CET532923778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:34.589745998 CET377853292159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:34.590013981 CET532923778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:34.591532946 CET532923778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:34.711046934 CET377853292159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:34.711165905 CET532923778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:34.830595970 CET377853292159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:35.894364119 CET377853292159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:35.894768953 CET532923778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:35.894768953 CET532923778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:35.895318031 CET532943778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:36.014834881 CET377853294159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:36.015039921 CET532943778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:36.016204119 CET532943778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:36.135762930 CET377853294159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:36.135986090 CET532943778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:36.255640984 CET377853294159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:37.320816994 CET377853294159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:37.321055889 CET532943778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:37.321118116 CET532943778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:37.321712017 CET532963778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:37.441247940 CET377853296159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:37.441431999 CET532963778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:37.442302942 CET532963778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:37.563072920 CET377853296159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:37.563218117 CET532963778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:37.682863951 CET377853296159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:38.745816946 CET377853296159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:38.745979071 CET532963778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:38.745979071 CET532963778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:38.746792078 CET532983778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:38.866281986 CET377853298159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:38.866528034 CET532983778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:38.867794991 CET532983778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:38.987246990 CET377853298159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:38.987483025 CET532983778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:39.107201099 CET377853298159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:40.172688961 CET377853298159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:40.172894955 CET532983778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:40.172894955 CET532983778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:40.173316002 CET533003778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:40.292859077 CET377853300159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:40.293015957 CET533003778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:40.293802023 CET533003778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:40.413299084 CET377853300159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:40.413438082 CET533003778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:40.533195972 CET377853300159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:41.552098036 CET377853300159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:41.552234888 CET533003778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:41.552277088 CET533003778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:41.552930117 CET533023778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:41.672581911 CET377853302159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:41.672749996 CET533023778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:41.673861980 CET533023778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:41.793406010 CET377853302159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:41.793606997 CET533023778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:41.913301945 CET377853302159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:42.931946039 CET377853302159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:42.932126045 CET533023778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:42.932214975 CET533023778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:42.933005095 CET533043778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:43.052634954 CET377853304159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:43.052757025 CET533043778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:43.053651094 CET533043778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:43.173223972 CET377853304159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:43.173398018 CET533043778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:43.293107033 CET377853304159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:44.164522886 CET42836443192.168.2.2391.189.91.43
                                            Dec 27, 2024 10:34:44.360790014 CET377853304159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:44.360908031 CET533043778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:44.360940933 CET533043778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:44.361486912 CET533063778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:44.481041908 CET377853306159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:44.481152058 CET533063778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:44.482472897 CET533063778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:44.602579117 CET377853306159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:44.602704048 CET533063778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:44.722323895 CET377853306159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:45.786719084 CET377853306159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:45.787005901 CET533063778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:45.787076950 CET533063778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:45.787987947 CET533083778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:45.907707930 CET377853308159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:45.907825947 CET533083778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:45.909048080 CET533083778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:46.028598070 CET377853308159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:46.028780937 CET533083778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:46.148315907 CET377853308159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:47.165817022 CET377853308159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:47.165950060 CET533083778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:47.165986061 CET533083778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:47.166492939 CET533103778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:47.285955906 CET377853310159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:47.286128044 CET533103778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:47.287293911 CET533103778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:47.407618046 CET377853310159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:47.407740116 CET533103778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:47.527152061 CET377853310159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:48.636934996 CET377853310159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:48.637062073 CET533103778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:48.637113094 CET533103778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:48.637744904 CET533123778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:48.758126020 CET377853312159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:48.758263111 CET533123778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:48.759757042 CET533123778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:48.879276037 CET377853312159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:48.879395008 CET533123778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:48.998859882 CET377853312159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:50.063008070 CET377853312159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:50.063147068 CET533123778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:50.063244104 CET533123778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:50.064078093 CET533143778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:50.183571100 CET377853314159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:50.183757067 CET533143778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:50.185103893 CET533143778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:50.304853916 CET377853314159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:50.305044889 CET533143778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:50.307662964 CET4251680192.168.2.23109.202.202.202
                                            Dec 27, 2024 10:34:50.424549103 CET377853314159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:51.488571882 CET377853314159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:51.488895893 CET533143778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:51.488928080 CET533143778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:51.489531994 CET533163778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:51.609117031 CET377853316159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:51.609203100 CET533163778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:51.610395908 CET533163778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:51.730030060 CET377853316159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:51.730139971 CET533163778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:51.849636078 CET377853316159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:52.868196964 CET377853316159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:52.868424892 CET533163778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:52.868474960 CET533163778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:52.869230032 CET533183778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:52.988754034 CET377853318159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:52.989027977 CET533183778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:52.990550041 CET533183778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:53.110761881 CET377853318159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:53.110958099 CET533183778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:53.231048107 CET377853318159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:54.304034948 CET377853318159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:54.304250956 CET533183778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:54.304277897 CET533183778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:54.304857016 CET533203778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:54.424535036 CET377853320159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:54.424694061 CET533203778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:54.425610065 CET533203778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:54.545101881 CET377853320159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:54.545377970 CET533203778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:54.664948940 CET377853320159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:55.774633884 CET377853320159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:55.774771929 CET533203778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:55.774849892 CET533203778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:55.775341034 CET533223778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:55.894789934 CET377853322159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:55.894896030 CET533223778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:55.895939112 CET533223778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:56.015513897 CET377853322159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:56.015744925 CET533223778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:56.135205984 CET377853322159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:57.262913942 CET377853322159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:57.263170958 CET533223778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:57.263170958 CET533223778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:57.263777018 CET533243778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:57.383205891 CET377853324159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:57.383418083 CET533243778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:57.384357929 CET533243778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:57.506068945 CET377853324159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:57.506217003 CET533243778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:57.626514912 CET377853324159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:58.691838026 CET377853324159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:58.692028046 CET533243778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:58.692028046 CET533243778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:58.692750931 CET533263778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:58.812501907 CET377853326159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:58.812761068 CET533263778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:58.813713074 CET533263778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:58.933129072 CET377853326159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:34:58.933306932 CET533263778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:34:59.052854061 CET377853326159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:00.117132902 CET377853326159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:00.117274046 CET533263778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:00.117315054 CET533263778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:00.118124962 CET533283778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:00.237582922 CET377853328159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:00.237673998 CET533283778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:00.238883972 CET533283778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:00.358314037 CET377853328159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:00.358544111 CET533283778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:00.478034019 CET377853328159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:01.503189087 CET377853328159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:01.503341913 CET533283778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:01.503396988 CET533283778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:01.504093885 CET533303778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:01.623531103 CET377853330159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:01.623692036 CET533303778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:01.624773026 CET533303778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:01.744225025 CET377853330159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:01.744366884 CET533303778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:01.863841057 CET377853330159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:02.985162973 CET377853330159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:02.985289097 CET533303778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:02.985332966 CET533303778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:02.985858917 CET533323778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:03.106075048 CET377853332159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:03.106210947 CET533323778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:03.107144117 CET533323778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:03.226649046 CET377853332159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:03.226730108 CET533323778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:03.346540928 CET377853332159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:04.457304001 CET377853332159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:04.457462072 CET533323778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:04.457493067 CET533323778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:04.458031893 CET533343778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:04.577488899 CET377853334159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:04.577828884 CET533343778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:04.578653097 CET533343778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:04.698077917 CET377853334159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:04.698235035 CET533343778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:04.817727089 CET377853334159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:05.882704020 CET377853334159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:05.882921934 CET533343778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:05.882968903 CET533343778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:05.883649111 CET533363778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:06.003185987 CET377853336159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:06.003319025 CET533363778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:06.004165888 CET533363778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:06.123717070 CET377853336159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:06.123786926 CET533363778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:06.243323088 CET377853336159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:07.308070898 CET377853336159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:07.308408976 CET533363778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:07.308500051 CET533363778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:07.309151888 CET533383778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:07.428631067 CET377853338159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:07.428901911 CET533383778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:07.430129051 CET533383778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:07.549715996 CET377853338159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:07.549865961 CET533383778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:07.669389009 CET377853338159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:08.734206915 CET377853338159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:08.734401941 CET533383778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:08.734487057 CET533383778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:08.735409975 CET533403778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:08.854953051 CET377853340159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:08.855061054 CET533403778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:08.856462955 CET533403778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:08.975934982 CET377853340159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:08.976062059 CET533403778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:09.095674992 CET377853340159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:10.117808104 CET377853340159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:10.117944956 CET533403778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:10.117980957 CET533403778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:10.118577003 CET533423778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:10.238043070 CET377853342159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:10.238121986 CET533423778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:10.239088058 CET533423778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:10.358659029 CET377853342159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:10.358746052 CET533423778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:10.478662014 CET377853342159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:11.589796066 CET377853342159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:11.590030909 CET533423778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:11.590046883 CET533423778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:11.590740919 CET533443778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:11.710282087 CET377853344159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:11.710453987 CET533443778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:11.711512089 CET533443778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:11.832334042 CET377853344159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:11.832628965 CET533443778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:11.952193975 CET377853344159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:13.014437914 CET377853344159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:13.014584064 CET533443778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:13.014700890 CET533443778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:13.015183926 CET533463778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:13.134627104 CET377853346159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:13.134766102 CET533463778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:13.136198997 CET533463778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:13.255695105 CET377853346159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:13.255814075 CET533463778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:13.375926971 CET377853346159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:14.393393993 CET377853346159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:14.393546104 CET533463778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:14.393578053 CET533463778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:14.394110918 CET533483778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:14.513691902 CET377853348159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:14.513853073 CET533483778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:14.514899015 CET533483778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:14.634392977 CET377853348159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:14.634541988 CET533483778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:14.754081964 CET377853348159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:14.880264044 CET43928443192.168.2.2391.189.91.42
                                            Dec 27, 2024 10:35:15.825983047 CET377853348159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:15.826109886 CET533483778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:15.826312065 CET533483778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:15.827111006 CET533503778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:15.946558952 CET377853350159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:15.946712017 CET533503778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:15.947602987 CET533503778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:16.067130089 CET377853350159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:16.067226887 CET533503778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:16.186657906 CET377853350159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:17.255115986 CET377853350159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:17.255364895 CET533503778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:17.255403996 CET533503778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:17.255906105 CET533523778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:17.375365973 CET377853352159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:17.375475883 CET533523778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:17.376367092 CET533523778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:17.495873928 CET377853352159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:17.495985031 CET533523778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:17.615472078 CET377853352159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:18.683357000 CET377853352159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:18.683492899 CET533523778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:18.683552027 CET533523778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:18.684207916 CET533543778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:18.803761959 CET377853354159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:18.803858995 CET533543778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:18.804994106 CET533543778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:18.924510956 CET377853354159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:18.924626112 CET533543778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:19.044295073 CET377853354159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:20.063852072 CET377853354159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:20.064047098 CET533543778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:20.064047098 CET533543778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:20.064621925 CET533563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:20.184108019 CET377853356159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:20.184225082 CET533563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:20.185209036 CET533563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:20.304604053 CET377853356159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:20.304822922 CET533563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:20.425720930 CET377853356159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:21.444495916 CET377853356159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:21.444900990 CET533563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:21.444900990 CET533563778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:21.445317030 CET533583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:21.564783096 CET377853358159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:21.565049887 CET533583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:21.565767050 CET533583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:21.685164928 CET377853358159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:21.685259104 CET533583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:21.804764032 CET377853358159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:31.574645996 CET533583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:31.726949930 CET377853358159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:32.288038015 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.402744055 CET377853358159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:32.402889013 CET533583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.402935028 CET533583778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.403423071 CET533603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.407567024 CET377853274159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:32.522881985 CET377853360159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:32.523025036 CET533603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.524296999 CET533603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.643765926 CET377853360159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:32.643883944 CET533603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.697813034 CET377853274159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:32.697923899 CET532743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:32.763528109 CET377853360159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:33.828299046 CET377853360159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:33.828424931 CET533603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:33.828466892 CET533603778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:33.828974009 CET533623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:33.948474884 CET377853362159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:33.948610067 CET533623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:33.949558973 CET533623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:34.068994045 CET377853362159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:34.069117069 CET533623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:34.188570023 CET377853362159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:35.357439995 CET42836443192.168.2.2391.189.91.43
                                            Dec 27, 2024 10:35:35.368767023 CET377853362159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:35.368978024 CET533623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:35.368978024 CET533623778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:35.369441986 CET533643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:35.489006042 CET377853364159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:35.489320993 CET533643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:35.490714073 CET533643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:35.610203981 CET377853364159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:35.610373020 CET533643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:35.729824066 CET377853364159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:36.794550896 CET377853364159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:36.795192957 CET533643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:36.795449972 CET533643778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:36.796468973 CET533663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:36.915940046 CET377853366159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:36.916239977 CET533663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:36.917892933 CET533663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:37.037746906 CET377853366159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:37.037972927 CET533663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:37.157602072 CET377853366159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:38.268006086 CET377853366159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:38.268224001 CET533663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:38.268287897 CET533663778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:38.268846035 CET533683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:38.388369083 CET377853368159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:38.388530970 CET533683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:38.389317036 CET533683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:38.508929014 CET377853368159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:38.509080887 CET533683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:38.628643990 CET377853368159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:39.695590019 CET377853368159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:39.695820093 CET533683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:39.695919037 CET533683778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:39.696628094 CET533703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:39.816104889 CET377853370159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:39.816302061 CET533703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:39.817750931 CET533703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:39.937175035 CET377853370159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:39.937376022 CET533703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:40.056941032 CET377853370159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:41.168555975 CET377853370159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:41.168726921 CET533703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:41.168765068 CET533703778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:41.169301987 CET533723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:41.288731098 CET377853372159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:41.288882971 CET533723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:41.290441990 CET533723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:41.409982920 CET377853372159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:41.410128117 CET533723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:41.529541016 CET377853372159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:42.593381882 CET377853372159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:42.593475103 CET533723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:42.593523979 CET533723778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:42.594011068 CET533743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:42.713445902 CET377853374159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:42.713578939 CET533743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:42.714564085 CET533743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:42.836080074 CET377853374159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:42.836334944 CET533743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:42.955877066 CET377853374159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:44.020488977 CET377853374159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:44.020859957 CET533743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:44.020859957 CET533743778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:44.021395922 CET533763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:44.140894890 CET377853376159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:44.141190052 CET533763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:44.142487049 CET533763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:44.262005091 CET377853376159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:44.262121916 CET533763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:44.381792068 CET377853376159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:45.445524931 CET377853376159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:45.445652962 CET533763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:45.445678949 CET533763778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:45.446227074 CET533783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:45.565998077 CET377853378159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:45.566198111 CET533783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:45.567965031 CET533783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:45.697948933 CET377853378159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:45.698071957 CET533783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:45.817531109 CET377853378159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:46.825779915 CET377853378159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:46.825937986 CET533783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:46.825978041 CET533783778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:46.826484919 CET533803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:46.947355032 CET377853380159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:46.947515965 CET533803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:46.948729992 CET533803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:47.068206072 CET377853380159.100.18.129192.168.2.23
                                            Dec 27, 2024 10:35:47.068324089 CET533803778192.168.2.23159.100.18.129
                                            Dec 27, 2024 10:35:47.187824965 CET377853380159.100.18.129192.168.2.23

                                            System Behavior

                                            Start time (UTC):09:34:11
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/Space.mips.elf
                                            Arguments:/tmp/Space.mips.elf
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):09:34:11
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/Space.mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):09:34:11
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/Space.mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):09:34:11
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/Space.mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):09:34:17
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/Space.mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                            Start time (UTC):09:34:17
                                            Start date (UTC):27/12/2024
                                            Path:/tmp/Space.mips.elf
                                            Arguments:-
                                            File size:5777432 bytes
                                            MD5 hash:0083f1f0e77be34ad27f849842bbb00c