Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
83.222.191.146-mips-2024-12-28T00_37_43.elf

Overview

General Information

Sample name:83.222.191.146-mips-2024-12-28T00_37_43.elf
Analysis ID:1581814
MD5:4fae376f359f2e5514bbd7d28b42139c
SHA1:0e5b1a2f630719a8102f0a8130403308387be219
SHA256:86ca658b2aad4022ede6aea02e8de3e30312bcf37be4429adac11efa77cc44df
Tags:elfuser-threatquery
Infos:

Detection

Gafgyt
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Gafgyt
Connects to many ports of the same IP (likely port scanning)
Executes the "iptables" command to insert, remove and/or manipulate rules
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Executes the "iptables" command used for managing IP filtering and manipulation
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1581814
Start date and time:2024-12-29 02:10:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 23s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:83.222.191.146-mips-2024-12-28T00_37_43.elf
Detection:MAL
Classification:mal72.troj.linELF@0/0@20/0
Command:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
PID:5432
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
listening dn0
Standard Error:
  • system is lnxubuntu20
  • 83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5432, Parent: 5356, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
    • 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5434, Parent: 5432)
      • 83.222.191.146-mips-2024-12-28T00_37_43.elf New Fork (PID: 5436, Parent: 5434)
        • sh (PID: 5438, Parent: 5436, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5444, Parent: 5438)
          • iptables (PID: 5444, Parent: 5438, MD5: 1ab05fef765b6342cdfadaa5275b33af) Arguments: iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
        • sh (PID: 5450, Parent: 5436, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5455, Parent: 5450)
          • busybox (PID: 5455, Parent: 5450, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
        • sh (PID: 5456, Parent: 5436, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5461, Parent: 5456)
        • sh (PID: 5462, Parent: 5436, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5467, Parent: 5462)
        • sh (PID: 5468, Parent: 5436, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          • sh New Fork (PID: 5473, Parent: 5468)
          • busybox (PID: 5473, Parent: 5468, MD5: 70584dffe9cb0309eb22ba78aa54bcdc) Arguments: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
SourceRuleDescriptionAuthorStrings
83.222.191.146-mips-2024-12-28T00_37_43.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    SourceRuleDescriptionAuthorStrings
    5432.1.00007f6568400000.00007f656842d000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: 83.222.191.146-mips-2024-12-28T00_37_43.elfAvira: detected
      Source: 83.222.191.146-mips-2024-12-28T00_37_43.elfReversingLabs: Detection: 28%

      Networking

      barindex
      Source: global trafficTCP traffic: 83.222.191.146 ports 35342,2,3,4,5,2222
      Source: /bin/sh (PID: 5444)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
      Source: global trafficTCP traffic: 192.168.2.13:41976 -> 83.222.191.146:35342
      Source: /bin/sh (PID: 5444)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5432)Socket: 127.0.0.1:8345Jump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5436)Socket: 0.0.0.0:26721Jump to behavior
      Source: unknownUDP traffic detected without corresponding DNS query: 194.36.144.87
      Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
      Source: unknownUDP traffic detected without corresponding DNS query: 51.158.108.203
      Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
      Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
      Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
      Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
      Source: unknownUDP traffic detected without corresponding DNS query: 178.254.22.166
      Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
      Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
      Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
      Source: unknownUDP traffic detected without corresponding DNS query: 51.77.149.139
      Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
      Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
      Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
      Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
      Source: unknownUDP traffic detected without corresponding DNS query: 51.254.162.59
      Source: unknownUDP traffic detected without corresponding DNS query: 94.16.114.254
      Source: global trafficDNS traffic detected: DNS query: secure-network-rebirthltd.ru
      Source: Initial sampleString containing 'busybox' found: /bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
      Source: Initial sampleString containing 'busybox' found: busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
      Source: Initial sampleString containing 'busybox' found: socketsetsockoptbindlisten1.1.1.1hi im here, i think/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPTbusybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPTbindtoipconnectpoll/proc/net/tcp/proc//exe/fd0
      Source: ELF static info symbol of initial sample.symtab present: no
      Source: classification engineClassification label: mal72.troj.linELF@0/0@20/0

      Persistence and Installation Behavior

      barindex
      Source: /bin/sh (PID: 5444)Iptables executable using switch for changing the iptables rules: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5438)Shell command executed: sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5450)Shell command executed: sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5456)Shell command executed: sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5462)Shell command executed: sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5468)Shell command executed: sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"Jump to behavior
      Source: /bin/sh (PID: 5444)Iptables executable: /usr/sbin/iptables -> iptables -A INPUT -p tcp --dport 26721 -j ACCEPTJump to behavior
      Source: /tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf (PID: 5432)Queries kernel information via 'uname': Jump to behavior
      Source: /bin/busybox (PID: 5455)Queries kernel information via 'uname': Jump to behavior
      Source: /usr/bin/busybox (PID: 5473)Queries kernel information via 'uname': Jump to behavior
      Source: 83.222.191.146-mips-2024-12-28T00_37_43.elf, 5432.1.00007ffe6620f000.00007ffe66230000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
      Source: 83.222.191.146-mips-2024-12-28T00_37_43.elf, 5432.1.00005644c774f000.00005644c77f9000.rw-.sdmpBinary or memory string: DV!/etc/qemu-binfmt/mips
      Source: 83.222.191.146-mips-2024-12-28T00_37_43.elf, 5432.1.00005644c774f000.00005644c77f9000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
      Source: 83.222.191.146-mips-2024-12-28T00_37_43.elf, 5432.1.00007ffe6620f000.00007ffe66230000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips

      Stealing of Sensitive Information

      barindex
      Source: Yara matchFile source: 83.222.191.146-mips-2024-12-28T00_37_43.elf, type: SAMPLE
      Source: Yara matchFile source: 5432.1.00007f6568400000.00007f656842d000.r-x.sdmp, type: MEMORY

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 83.222.191.146-mips-2024-12-28T00_37_43.elf, type: SAMPLE
      Source: Yara matchFile source: 5432.1.00007f6568400000.00007f656842d000.r-x.sdmp, type: MEMORY
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information1
      Scripting
      Valid AccountsWindows Management Instrumentation1
      Scripting
      Path InterceptionDirect Volume AccessOS Credential Dumping11
      Security Software Discovery
      Remote ServicesData from Local System1
      Non-Standard Port
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory1
      System Network Configuration Discovery
      Remote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      No configs have been found
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Number of created Files
      • Is malicious
      • Internet
      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1581814 Sample: 83.222.191.146-mips-2024-12... Startdate: 29/12/2024 Architecture: LINUX Score: 72 35 SECURE-NETWORK-REBIRTHLTD.RU 83.222.191.146, 2222, 35342, 41976 NET1-ASBG Bulgaria 2->35 37 secure-network-rebirthltd.ru 2->37 39 Antivirus / Scanner detection for submitted sample 2->39 41 Multi AV Scanner detection for submitted file 2->41 43 Yara detected Gafgyt 2->43 45 Connects to many ports of the same IP (likely port scanning) 2->45 10 83.222.191.146-mips-2024-12-28T00_37_43.elf 2->10         started        signatures3 process4 process5 12 83.222.191.146-mips-2024-12-28T00_37_43.elf 10->12         started        process6 14 83.222.191.146-mips-2024-12-28T00_37_43.elf 12->14         started        process7 16 83.222.191.146-mips-2024-12-28T00_37_43.elf sh 14->16         started        18 83.222.191.146-mips-2024-12-28T00_37_43.elf sh 14->18         started        20 83.222.191.146-mips-2024-12-28T00_37_43.elf sh 14->20         started        22 2 other processes 14->22 process8 24 sh iptables 16->24         started        27 sh busybox 18->27         started        29 sh busybox 20->29         started        31 sh 22->31         started        33 sh 22->33         started        signatures9 47 Executes the "iptables" command to insert, remove and/or manipulate rules 24->47

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      83.222.191.146-mips-2024-12-28T00_37_43.elf29%ReversingLabsLinux.Backdoor.Mirai
      83.222.191.146-mips-2024-12-28T00_37_43.elf100%AviraEXP/ELF.Agent.J.8
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      secure-network-rebirthltd.ru
      83.222.191.146
      truefalse
        high
        SECURE-NETWORK-REBIRTHLTD.RU
        83.222.191.146
        truefalse
          high
          • No. of IPs < 25%
          • 25% < No. of IPs < 50%
          • 50% < No. of IPs < 75%
          • 75% < No. of IPs
          IPDomainCountryFlagASNASN NameMalicious
          83.222.191.146
          secure-network-rebirthltd.ruBulgaria
          43561NET1-ASBGfalse
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          83.222.191.146dlr.arm6.elfGet hashmaliciousGafgytBrowse
          • /binaries/arm6
          dlr.mpsl.elfGet hashmaliciousGafgytBrowse
          • /binaries/mpsl
          dlr.arm7.elfGet hashmaliciousUnknownBrowse
          • /binaries/arm7
          dlr.mips.elfGet hashmaliciousGafgytBrowse
          • /binaries/mips
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          secure-network-rebirthltd.ruppc.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          x86.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          x86_64.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm5.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          m68k.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm4.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm7.elfGet hashmaliciousMiraiBrowse
          • 83.222.191.146
          spc.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          mpsl.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          mips.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          SECURE-NETWORK-REBIRTHLTD.RUppc.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          x86.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          x86_64.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm5.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          m68k.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm4.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm7.elfGet hashmaliciousMiraiBrowse
          • 83.222.191.146
          spc.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          mpsl.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          mips.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          NET1-ASBGppc.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          x86.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          x86_64.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm5.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          m68k.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm4.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          arm7.elfGet hashmaliciousMiraiBrowse
          • 83.222.191.146
          spc.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          mpsl.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          mips.elfGet hashmaliciousUnknownBrowse
          • 83.222.191.146
          No context
          No context
          No created / dropped files found
          File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
          Entropy (8bit):5.091403215701722
          TrID:
          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
          File name:83.222.191.146-mips-2024-12-28T00_37_43.elf
          File size:203'576 bytes
          MD5:4fae376f359f2e5514bbd7d28b42139c
          SHA1:0e5b1a2f630719a8102f0a8130403308387be219
          SHA256:86ca658b2aad4022ede6aea02e8de3e30312bcf37be4429adac11efa77cc44df
          SHA512:e7c0f54882e2451f524690293c985570fc54818c66367db17e48803cd1298d108b9d9ad8e19dc646d89797c19025290925954491c003569747133654aa4e3066
          SSDEEP:3072:+xNydN4Ovn1NYu/HH3wdgjhVn50nvE8nTWdGHitw:+xNydNL/1NJ/HsgFl5D8idGCtw
          TLSH:6614A61E6E228F7EF76C873047B74E34A76923D627E1D684E1ACD1105F2029E541FBA8
          File Content Preview:.ELF.....................@.`...4.........4. ...(.............@...@...........................F...F....W.............dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

          ELF header

          Class:ELF32
          Data:2's complement, big endian
          Version:1 (current)
          Machine:MIPS R3000
          Version Number:0x1
          Type:EXEC (Executable file)
          OS/ABI:UNIX - System V
          ABI Version:0
          Entry Point Address:0x400260
          Flags:0x1007
          ELF Header Size:52
          Program Header Offset:52
          Program Header Size:32
          Number of Program Headers:3
          Section Header Offset:203016
          Section Header Size:40
          Number of Section Headers:14
          Header String Table Index:13
          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
          NULL0x00x00x00x00x0000
          .initPROGBITS0x4000940x940x8c0x00x6AX004
          .textPROGBITS0x4001200x1200x29a500x00x6AX0016
          .finiPROGBITS0x429b700x29b700x5c0x00x6AX004
          .rodataPROGBITS0x429bd00x29bd00x24f00x00x2A0016
          .ctorsPROGBITS0x46c0c40x2c0c40xc0x00x3WA004
          .dtorsPROGBITS0x46c0d00x2c0d00x80x00x3WA004
          .data.rel.roPROGBITS0x46c0dc0x2c0dc0x46c0x00x3WA004
          .dataPROGBITS0x46c5600x2c5600x49300x00x3WA0032
          .gotPROGBITS0x470e900x30e900xa140x40x10000003WAp0016
          .sbssNOBITS0x4718a40x318a40x3c0x00x10000003WAp004
          .bssNOBITS0x4718e00x318a40x46c00x00x3WA0016
          .mdebug.abi32PROGBITS0x14400x318a40x00x00x0001
          .shstrtabSTRTAB0x00x318a40x640x00x0001
          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
          LOAD0x00x4000000x4000000x2c0c00x2c0c05.40960x5R E0x10000.init .text .fini .rodata
          LOAD0x2c0c40x46c0c40x46c0c40x57e00x9edc1.37820x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
          GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
          TimestampSource PortDest PortSource IPDest IP
          Dec 29, 2024 02:10:54.653343916 CET4197635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:54.773019075 CET353424197683.222.191.146192.168.2.13
          Dec 29, 2024 02:10:54.773080111 CET4197635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:54.773751974 CET4197635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:54.894232035 CET353424197683.222.191.146192.168.2.13
          Dec 29, 2024 02:10:54.894285917 CET4197635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:55.014043093 CET353424197683.222.191.146192.168.2.13
          Dec 29, 2024 02:10:55.025716066 CET533142222192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:55.145406008 CET22225331483.222.191.146192.168.2.13
          Dec 29, 2024 02:10:55.145698071 CET533142222192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:55.146698952 CET533142222192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:55.146752119 CET533142222192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:55.266217947 CET22225331483.222.191.146192.168.2.13
          Dec 29, 2024 02:10:55.308063984 CET22225331483.222.191.146192.168.2.13
          Dec 29, 2024 02:10:56.992845058 CET353424197683.222.191.146192.168.2.13
          Dec 29, 2024 02:10:56.993313074 CET4197635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:57.113116980 CET353424197683.222.191.146192.168.2.13
          Dec 29, 2024 02:10:57.383040905 CET22225331483.222.191.146192.168.2.13
          Dec 29, 2024 02:10:57.383266926 CET533142222192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:58.241916895 CET4198035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:58.361459017 CET353424198083.222.191.146192.168.2.13
          Dec 29, 2024 02:10:58.361541986 CET4198035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:58.361582994 CET4198035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:58.481128931 CET353424198083.222.191.146192.168.2.13
          Dec 29, 2024 02:10:58.481225967 CET4198035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:10:58.600719929 CET353424198083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:00.626630068 CET353424198083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:00.626796007 CET4198035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:00.746393919 CET353424198083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:01.628125906 CET4198235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:01.747824907 CET353424198283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:01.747917891 CET4198235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:01.748126984 CET4198235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:01.867554903 CET353424198283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:01.867638111 CET4198235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:01.988042116 CET353424198283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:03.976918936 CET353424198283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:03.977076054 CET4198235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:04.096774101 CET353424198283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:04.978435993 CET4198435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:05.098149061 CET353424198483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:05.098252058 CET4198435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:05.098423004 CET4198435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:05.217987061 CET353424198483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:05.218075991 CET4198435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:05.337676048 CET353424198483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:07.345077991 CET353424198483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:07.345494032 CET4198435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:07.465181112 CET353424198483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:08.595659018 CET4198635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:08.715410948 CET353424198683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:08.715579033 CET4198635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:08.715579033 CET4198635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:08.835195065 CET353424198683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:08.835450888 CET4198635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:08.955137014 CET353424198683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:10.998619080 CET353424198683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:10.998877048 CET4198635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:11.118580103 CET353424198683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:12.001106024 CET4198835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:12.120939970 CET353424198883.222.191.146192.168.2.13
          Dec 29, 2024 02:11:12.121198893 CET4198835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:12.121289968 CET4198835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:12.240875006 CET353424198883.222.191.146192.168.2.13
          Dec 29, 2024 02:11:12.241134882 CET4198835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:12.360699892 CET353424198883.222.191.146192.168.2.13
          Dec 29, 2024 02:11:14.357717037 CET353424198883.222.191.146192.168.2.13
          Dec 29, 2024 02:11:14.357927084 CET4198835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:14.477468967 CET353424198883.222.191.146192.168.2.13
          Dec 29, 2024 02:11:15.359280109 CET4199035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:15.479123116 CET353424199083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:15.479279995 CET4199035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:15.479378939 CET4199035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:15.599087000 CET353424199083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:15.599206924 CET4199035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:15.718841076 CET353424199083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:17.763219118 CET353424199083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:17.763375044 CET4199035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:17.883035898 CET353424199083.222.191.146192.168.2.13
          Dec 29, 2024 02:11:19.015708923 CET4199235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:19.135554075 CET353424199283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:19.135641098 CET4199235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:19.135663986 CET4199235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:19.255275965 CET353424199283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:19.255350113 CET4199235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:19.375664949 CET353424199283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:21.451433897 CET353424199283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:21.451677084 CET4199235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:21.571330070 CET353424199283.222.191.146192.168.2.13
          Dec 29, 2024 02:11:47.484870911 CET4199435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:47.605005980 CET353424199483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:47.605227947 CET4199435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:47.605227947 CET4199435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:47.724872112 CET353424199483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:47.725069046 CET4199435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:47.844611883 CET353424199483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:49.921009064 CET353424199483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:49.921554089 CET4199435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:50.041204929 CET353424199483.222.191.146192.168.2.13
          Dec 29, 2024 02:11:54.302298069 CET4199635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:54.421950102 CET353424199683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:54.422219992 CET4199635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:54.422339916 CET4199635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:54.541816950 CET353424199683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:54.542043924 CET4199635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:54.661799908 CET353424199683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:56.662477970 CET353424199683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:56.662878990 CET4199635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:56.782453060 CET353424199683.222.191.146192.168.2.13
          Dec 29, 2024 02:11:57.895819902 CET4199835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:58.015599966 CET353424199883.222.191.146192.168.2.13
          Dec 29, 2024 02:11:58.015757084 CET4199835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:58.016015053 CET4199835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:58.135520935 CET353424199883.222.191.146192.168.2.13
          Dec 29, 2024 02:11:58.135612965 CET4199835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:11:58.255398989 CET353424199883.222.191.146192.168.2.13
          Dec 29, 2024 02:12:00.296461105 CET353424199883.222.191.146192.168.2.13
          Dec 29, 2024 02:12:00.296920061 CET4199835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:00.416618109 CET353424199883.222.191.146192.168.2.13
          Dec 29, 2024 02:12:01.528938055 CET4200035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:01.648653984 CET353424200083.222.191.146192.168.2.13
          Dec 29, 2024 02:12:01.648806095 CET4200035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:01.648917913 CET4200035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:01.768496990 CET353424200083.222.191.146192.168.2.13
          Dec 29, 2024 02:12:01.768693924 CET4200035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:01.888552904 CET353424200083.222.191.146192.168.2.13
          Dec 29, 2024 02:12:03.896425009 CET353424200083.222.191.146192.168.2.13
          Dec 29, 2024 02:12:03.896923065 CET4200035342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:04.016701937 CET353424200083.222.191.146192.168.2.13
          Dec 29, 2024 02:12:18.099004030 CET4200235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:18.218878984 CET353424200283.222.191.146192.168.2.13
          Dec 29, 2024 02:12:18.219012976 CET4200235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:18.219083071 CET4200235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:18.338651896 CET353424200283.222.191.146192.168.2.13
          Dec 29, 2024 02:12:18.338732958 CET4200235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:18.458374977 CET353424200283.222.191.146192.168.2.13
          Dec 29, 2024 02:12:20.475038052 CET353424200283.222.191.146192.168.2.13
          Dec 29, 2024 02:12:20.475249052 CET4200235342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:20.594963074 CET353424200283.222.191.146192.168.2.13
          Dec 29, 2024 02:12:46.503654957 CET4200435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:46.623456001 CET353424200483.222.191.146192.168.2.13
          Dec 29, 2024 02:12:46.623581886 CET4200435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:46.623626947 CET4200435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:46.743240118 CET353424200483.222.191.146192.168.2.13
          Dec 29, 2024 02:12:46.743331909 CET4200435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:46.863029003 CET353424200483.222.191.146192.168.2.13
          Dec 29, 2024 02:12:48.887895107 CET353424200483.222.191.146192.168.2.13
          Dec 29, 2024 02:12:48.888051033 CET4200435342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:49.007637024 CET353424200483.222.191.146192.168.2.13
          Dec 29, 2024 02:12:49.889616966 CET4200635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:50.009454966 CET353424200683.222.191.146192.168.2.13
          Dec 29, 2024 02:12:50.009531975 CET4200635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:50.009557962 CET4200635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:50.129385948 CET353424200683.222.191.146192.168.2.13
          Dec 29, 2024 02:12:50.129451990 CET4200635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:50.249077082 CET353424200683.222.191.146192.168.2.13
          Dec 29, 2024 02:12:52.293901920 CET353424200683.222.191.146192.168.2.13
          Dec 29, 2024 02:12:52.294148922 CET4200635342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:52.413863897 CET353424200683.222.191.146192.168.2.13
          Dec 29, 2024 02:12:53.295357943 CET4200835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:53.415237904 CET353424200883.222.191.146192.168.2.13
          Dec 29, 2024 02:12:53.415323019 CET4200835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:53.415357113 CET4200835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:53.535026073 CET353424200883.222.191.146192.168.2.13
          Dec 29, 2024 02:12:53.535120010 CET4200835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:53.654709101 CET353424200883.222.191.146192.168.2.13
          Dec 29, 2024 02:12:55.675334930 CET353424200883.222.191.146192.168.2.13
          Dec 29, 2024 02:12:55.675445080 CET4200835342192.168.2.1383.222.191.146
          Dec 29, 2024 02:12:55.795088053 CET353424200883.222.191.146192.168.2.13
          TimestampSource PortDest PortSource IPDest IP
          Dec 29, 2024 02:10:57.995721102 CET3316553192.168.2.13194.36.144.87
          Dec 29, 2024 02:10:58.240596056 CET5333165194.36.144.87192.168.2.13
          Dec 29, 2024 02:11:08.348295927 CET4315153192.168.2.1351.158.108.203
          Dec 29, 2024 02:11:08.594934940 CET534315151.158.108.203192.168.2.13
          Dec 29, 2024 02:11:18.765136003 CET4726453192.168.2.1351.158.108.203
          Dec 29, 2024 02:11:19.015228987 CET534726451.158.108.203192.168.2.13
          Dec 29, 2024 02:11:22.454236984 CET5691953192.168.2.13178.254.22.166
          Dec 29, 2024 02:11:27.460922003 CET4143053192.168.2.13178.254.22.166
          Dec 29, 2024 02:11:32.467212915 CET4416753192.168.2.13178.254.22.166
          Dec 29, 2024 02:11:37.473124981 CET5307453192.168.2.13178.254.22.166
          Dec 29, 2024 02:11:42.479147911 CET5123053192.168.2.13178.254.22.166
          Dec 29, 2024 02:11:50.924520016 CET5065453192.168.2.1351.77.149.139
          Dec 29, 2024 02:11:54.300889015 CET535065451.77.149.139192.168.2.13
          Dec 29, 2024 02:11:57.665663004 CET3465653192.168.2.13195.10.195.195
          Dec 29, 2024 02:11:57.894932032 CET5334656195.10.195.195192.168.2.13
          Dec 29, 2024 02:12:01.299707890 CET5627653192.168.2.13195.10.195.195
          Dec 29, 2024 02:12:01.528115034 CET5356276195.10.195.195192.168.2.13
          Dec 29, 2024 02:12:04.899559021 CET3656553192.168.2.1351.77.149.139
          Dec 29, 2024 02:12:09.905422926 CET3759853192.168.2.1351.77.149.139
          Dec 29, 2024 02:12:14.911082029 CET3700053192.168.2.1351.77.149.139
          Dec 29, 2024 02:12:18.098251104 CET533700051.77.149.139192.168.2.13
          Dec 29, 2024 02:12:21.476902008 CET5795553192.168.2.1351.254.162.59
          Dec 29, 2024 02:12:26.483335972 CET5790153192.168.2.1351.254.162.59
          Dec 29, 2024 02:12:31.489737988 CET5547653192.168.2.1351.254.162.59
          Dec 29, 2024 02:12:36.496157885 CET3988753192.168.2.1351.254.162.59
          Dec 29, 2024 02:12:41.498141050 CET5471753192.168.2.1351.254.162.59
          Dec 29, 2024 02:12:56.676954985 CET3733553192.168.2.1394.16.114.254
          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
          Dec 29, 2024 02:10:57.995721102 CET192.168.2.13194.36.144.870x50d3Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:08.348295927 CET192.168.2.1351.158.108.2030xf0f9Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:18.765136003 CET192.168.2.1351.158.108.2030x75c9Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:22.454236984 CET192.168.2.13178.254.22.1660xca87Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:27.460922003 CET192.168.2.13178.254.22.1660xca87Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:32.467212915 CET192.168.2.13178.254.22.1660xca87Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:37.473124981 CET192.168.2.13178.254.22.1660xca87Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:42.479147911 CET192.168.2.13178.254.22.1660xca87Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:50.924520016 CET192.168.2.1351.77.149.1390x1eb8Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:57.665663004 CET192.168.2.13195.10.195.1950xe31eStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:01.299707890 CET192.168.2.13195.10.195.1950xa11eStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:04.899559021 CET192.168.2.1351.77.149.1390xbd94Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:09.905422926 CET192.168.2.1351.77.149.1390xbd94Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:14.911082029 CET192.168.2.1351.77.149.1390xbd94Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:21.476902008 CET192.168.2.1351.254.162.590xffbdStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:26.483335972 CET192.168.2.1351.254.162.590xffbdStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:31.489737988 CET192.168.2.1351.254.162.590xffbdStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:36.496157885 CET192.168.2.1351.254.162.590xffbdStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:41.498141050 CET192.168.2.1351.254.162.590xffbdStandard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:56.676954985 CET192.168.2.1394.16.114.2540x58a8Standard query (0)secure-network-rebirthltd.ruA (IP address)IN (0x0001)false
          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
          Dec 29, 2024 02:10:58.240596056 CET194.36.144.87192.168.2.130x50d3No error (0)secure-network-rebirthltd.ru83.222.191.146A (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:08.594934940 CET51.158.108.203192.168.2.130xf0f9No error (0)secure-network-rebirthltd.ru83.222.191.146A (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:19.015228987 CET51.158.108.203192.168.2.130x75c9No error (0)secure-network-rebirthltd.ru83.222.191.146A (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:54.300889015 CET51.77.149.139192.168.2.130x1eb8No error (0)SECURE-NETWORK-REBIRTHLTD.RU83.222.191.146A (IP address)IN (0x0001)false
          Dec 29, 2024 02:11:57.894932032 CET195.10.195.195192.168.2.130xe31eNo error (0)SECURE-NETWORK-REBIRTHLTD.RU83.222.191.146A (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:01.528115034 CET195.10.195.195192.168.2.130xa11eNo error (0)SECURE-NETWORK-REBIRTHLTD.RU83.222.191.146A (IP address)IN (0x0001)false
          Dec 29, 2024 02:12:18.098251104 CET51.77.149.139192.168.2.130xbd94No error (0)SECURE-NETWORK-REBIRTHLTD.RU83.222.191.146A (IP address)IN (0x0001)false

          System Behavior

          Start time (UTC):01:10:52
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:52
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:-
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:-
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:-
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:-
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/usr/sbin/iptables
          Arguments:iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
          File size:99296 bytes
          MD5 hash:1ab05fef765b6342cdfadaa5275b33af

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:-
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:-
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/busybox
          Arguments:/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
          File size:2172376 bytes
          MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:-
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:-
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:-
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:-
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/tmp/83.222.191.146-mips-2024-12-28T00_37_43.elf
          Arguments:-
          File size:5777432 bytes
          MD5 hash:0083f1f0e77be34ad27f849842bbb00c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT"
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/bin/sh
          Arguments:-
          File size:129816 bytes
          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

          Start time (UTC):01:10:54
          Start date (UTC):29/12/2024
          Path:/usr/bin/busybox
          Arguments:busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT
          File size:2172376 bytes
          MD5 hash:70584dffe9cb0309eb22ba78aa54bcdc