Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.mpsl.elf

Overview

General Information

Sample name:dlr.mpsl.elf
Analysis ID:1582178
MD5:9c9ac80ea8741a896f4efea0be51fcb2
SHA1:3b0525e66b3045fb492ac183367d1f52dd71b9e9
SHA256:9a076e55a638997f9e83677fa47539c788b3904231da51425341be59fb52a97a
Tags:elfMiraiuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
HTTP GET or POST without a user agent
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582178
Start date and time:2024-12-30 03:30:18 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 27s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.mpsl.elf
Detection:MAL
Classification:mal48.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Command:/tmp/dlr.mpsl.elf
PID:5435
Exit Code:5
Exit Code Info:
Killed:False
Standard Output:
NIGGY
RAY
Standard Error:
  • system is lnxubuntu20
  • dlr.mpsl.elf (PID: 5435, Parent: 5356, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/dlr.mpsl.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: dlr.mpsl.elfVirustotal: Detection: 31%Perma Link
Source: dlr.mpsl.elfReversingLabs: Detection: 39%
Source: global trafficHTTP traffic detected: GET /mpsl HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: unknownTCP traffic detected without corresponding DNS query: 103.188.82.218
Source: global trafficHTTP traffic detected: GET /mpsl HTTP/1.0Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00 Data Ascii: RAY
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/1@0/0
Source: /tmp/dlr.mpsl.elf (PID: 5435)File written: /tmp/GalaxyJump to dropped file
Source: /tmp/dlr.mpsl.elf (PID: 5435)Queries kernel information via 'uname': Jump to behavior
Source: dlr.mpsl.elf, 5435.1.000055e37735e000.000055e3773e5000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: dlr.mpsl.elf, 5435.1.000055e37735e000.000055e3773e5000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: dlr.mpsl.elf, 5435.1.00007ffcd79e6000.00007ffcd7a07000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/dlr.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.mpsl.elf
Source: dlr.mpsl.elf, 5435.1.00007ffcd79e6000.00007ffcd7a07000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
dlr.mpsl.elf32%VirustotalBrowse
dlr.mpsl.elf39%ReversingLabsLinux.Backdoor.Mirai
SourceDetectionScannerLabelLink
/tmp/Galaxy11%ReversingLabsLinux.Trojan.Mirai
/tmp/Galaxy54%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
103.188.82.218
unknownunknown
7575AARNET-AS-APAustralianAcademicandResearchNetworkAARNefalse
185.125.190.26
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
103.188.82.218dlr.mips.elfGet hashmaliciousUnknownBrowse
  • /mips
dlr.arm7.elfGet hashmaliciousUnknownBrowse
  • /arm7
dlr.arm6.elfGet hashmaliciousUnknownBrowse
  • /arm6
185.125.190.26debug.dbg.elfGet hashmaliciousMirai, MoobotBrowse
    x86.elfGet hashmaliciousUnknownBrowse
      dlr.arm6.elfGet hashmaliciousUnknownBrowse
        Aqua.arm6.elfGet hashmaliciousUnknownBrowse
          Aqua.arm4.elfGet hashmaliciousUnknownBrowse
            Aqua.ppc.elfGet hashmaliciousUnknownBrowse
              arm5.elfGet hashmaliciousUnknownBrowse
                x86_64.elfGet hashmaliciousUnknownBrowse
                  bot.x86.elfGet hashmaliciousMirai, OkiruBrowse
                    armv6l.elfGet hashmaliciousMiraiBrowse
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      CANONICAL-ASGB.Sarm5.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      arm5.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      zmap.arm6.elfGet hashmaliciousMirai, OkiruBrowse
                      • 91.189.91.42
                      debug.dbg.elfGet hashmaliciousMirai, MoobotBrowse
                      • 185.125.190.26
                      .Smpsl.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      arm.elfGet hashmaliciousMirai, MoobotBrowse
                      • 91.189.91.42
                      rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                      • 91.189.91.42
                      dlr.arm7.elfGet hashmaliciousMiraiBrowse
                      • 91.189.91.42
                      .Sm68k.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      m68k.elfGet hashmaliciousUnknownBrowse
                      • 91.189.91.42
                      AARNET-AS-APAustralianAcademicandResearchNetworkAARNedlr.mips.elfGet hashmaliciousUnknownBrowse
                      • 103.188.82.218
                      dlr.arm7.elfGet hashmaliciousUnknownBrowse
                      • 103.188.82.218
                      dlr.arm6.elfGet hashmaliciousUnknownBrowse
                      • 103.188.82.218
                      arm7.elfGet hashmaliciousMirai, MoobotBrowse
                      • 103.187.127.118
                      star.ppc.elfGet hashmaliciousMirai, MoobotBrowse
                      • 103.187.81.199
                      mips.elfGet hashmaliciousMirai, MoobotBrowse
                      • 157.85.109.58
                      db0fa4b8db0333367e9bda3ab68b8042.sh4.elfGet hashmaliciousMirai, GafgytBrowse
                      • 103.177.151.232
                      db0fa4b8db0333367e9bda3ab68b8042.spc.elfGet hashmaliciousMirai, GafgytBrowse
                      • 103.183.119.78
                      4qOTcmSTSq.exeGet hashmaliciousUnknownBrowse
                      • 103.8.70.183
                      https://fsharetv.co/Get hashmaliciousUnknownBrowse
                      • 103.67.200.64
                      No context
                      No context
                      Process:/tmp/dlr.mpsl.elf
                      File Type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                      Category:dropped
                      Size (bytes):89592
                      Entropy (8bit):5.5067875693022295
                      Encrypted:false
                      SSDEEP:1536:xfiTTxk17uiHT15IKODOH0lstOk+guZBZq387JSJNgcfEMnpS:ViTdkFuSTTOlBg+BecwnpS
                      MD5:525D304E17F85BF01A6394C78B4D3E26
                      SHA1:723EDEECC90990BE009CFA2732AD3F088BEAC5F0
                      SHA-256:36B4F8C1C40E347F5FF188DFB7807A04772EE591E881C8F2A9C4F6DAEF19D230
                      SHA-512:F5AE3E8E9EF2D57B6FEC9E037344FDC8E89779497B3FC04623373891B14F6433D2C4922FB608BF1E60BC81EE31C623D7D183F4EA8C353B3CB1FC328188459B6E
                      Malicious:true
                      Antivirus:
                      • Antivirus: ReversingLabs, Detection: 11%
                      • Antivirus: Virustotal, Detection: 54%, Browse
                      Reputation:low
                      Preview:.ELF....................`.@.4....[......4. ...(...............@...@..Q...Q...............Q...QE..QE.p...4Z..........Q.td...............................<<.'!......'.......................<..'!... .........9'.. ........................<..'!............99'.. ......................... ..'...<..'!......' ........................[".......@..............R........Y....... ...B$.. ..R...R........Y....... ...B$.........@....$............. ..Q.$.......$.[". ...............(..'...<..'!......'.........................Q.$..@..[.$.. ......................R........@..R.$.. ........... . ..'............ ..'....!..............<d.'!...!..............'...$$.....'H....................... ......... ............................<..'!......'0...,...(...$... ...............P...!...!......0...0H..... ....$......P.......@.....0...,...(...$... ...............8..'P......... ...........P.......@.........L..... ...................... .........! @........... ....$.................. .! ............ .........
                      File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                      Entropy (8bit):4.716905446595837
                      TrID:
                      • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                      File name:dlr.mpsl.elf
                      File size:2'016 bytes
                      MD5:9c9ac80ea8741a896f4efea0be51fcb2
                      SHA1:3b0525e66b3045fb492ac183367d1f52dd71b9e9
                      SHA256:9a076e55a638997f9e83677fa47539c788b3904231da51425341be59fb52a97a
                      SHA512:efcc5e6740122cf12ee460d0e5578dc624f2cd0ec584e048054c8920a1223ed941285ea0e20cb4cdaa233451ba6adcbeb714e5ef9992021ff258b6f94807d9a2
                      SSDEEP:48:kff2nNnuDW3B6df9HOScTLmPkOTNFSXZ:kffUnuqYf9uS4LmrT+J
                      TLSH:F841121E6F801F37DD66CC36058B275139CC842BA16A63926334ED60BD3E605E7D38A8
                      File Content Preview:.ELF......................@.4...........4. ...(...............@...@.@...@...............@...@.D.@.D.T...p...........Q.td...........................................0.,...&..% .....0...0% ...2..%0...".....0.......0.....6..%.C.%0......%.F....<D..'!...\...!(.

                      ELF header

                      Class:ELF32
                      Data:2's complement, little endian
                      Version:1 (current)
                      Machine:MIPS R3000
                      Version Number:0x1
                      Type:EXEC (Executable file)
                      OS/ABI:UNIX - System V
                      ABI Version:0
                      Entry Point Address:0x4004e4
                      Flags:0x1007
                      ELF Header Size:52
                      Program Header Offset:52
                      Program Header Size:32
                      Number of Program Headers:3
                      Section Header Offset:1736
                      Section Header Size:40
                      Number of Section Headers:7
                      Header String Table Index:6
                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                      NULL0x00x00x00x00x0000
                      .textPROGBITS0x4000a00xa00x5600x00x6AX0016
                      .rodataPROGBITS0x4006000x6000x400x10x32AMS004
                      .gotPROGBITS0x4406400x6400x540x40x10000003WAp0016
                      .bssNOBITS0x4406a00x6940x100x00x3WA0016
                      .mdebug.abi32PROGBITS0x480x6940x00x00x0001
                      .shstrtabSTRTAB0x00x6940x310x00x0001
                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                      LOAD0x00x4000000x4000000x6400x6405.01030x5R E0x10000.text .rodata
                      LOAD0x6400x4406400x4406400x540x702.61250x6RW 0x10000.got .bss
                      GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                      TimestampSource PortDest PortSource IPDest IP
                      Dec 30, 2024 03:30:59.214306116 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:30:59.219233036 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:30:59.219286919 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:30:59.220451117 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:30:59.225265980 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156136036 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156157970 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156169891 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156181097 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156192064 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156203985 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156215906 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156220913 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156234026 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156245947 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.156253099 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156253099 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.156285048 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.161113024 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.161127090 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.161145926 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.161145926 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.409912109 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.409928083 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.409939051 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.409967899 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.409967899 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.409986019 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.418833971 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.418844938 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.418854952 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.418873072 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.418873072 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.418884039 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.436723948 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.436737061 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.436747074 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.436758995 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.436758995 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.436770916 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.454381943 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.454397917 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.454406977 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.454417944 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.454417944 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.454433918 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.472206116 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.472218037 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.472228050 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.472242117 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.472253084 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.472258091 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.489835024 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.489845037 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.489855051 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.489892006 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.490902901 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.507781029 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.507791996 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.507802010 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.509289026 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.525465012 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.525475979 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.525487900 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.526218891 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.543127060 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.543139935 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.543150902 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.545362949 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.561078072 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.561088085 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.561099052 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.561682940 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.663563967 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.663578033 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.663590908 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.663609982 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.672641039 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.672653913 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.672663927 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.674993038 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.690386057 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.690398932 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.690408945 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.690942049 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.708002090 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.708012104 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.708023071 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.710436106 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.725989103 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.726001024 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.726011038 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.727106094 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.743546963 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.743558884 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.743568897 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.743788004 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.761415958 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.761426926 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.761497974 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.761512995 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.762947083 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.779495955 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.779508114 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.779520035 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.781723976 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.798242092 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.798250914 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.798255920 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.798266888 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.799412966 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.812947989 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.812958956 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.812974930 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.814048052 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.827966928 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.827975988 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.828548908 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.834861040 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.834871054 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.834882021 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.837093115 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.849282026 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.849292040 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.849302053 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.849793911 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.863445044 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.863456011 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.863466024 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.865039110 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.877691031 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.877701998 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.877711058 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.877768040 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.891808987 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.891824961 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.893102884 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.939229965 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:00.944122076 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.944134951 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.944147110 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:00.945511103 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:02.129395008 CET4103080192.168.2.13103.188.82.218
                      Dec 30, 2024 03:31:02.134290934 CET8041030103.188.82.218192.168.2.13
                      Dec 30, 2024 03:31:11.053858042 CET48202443192.168.2.13185.125.190.26
                      Dec 30, 2024 03:31:43.309909105 CET48202443192.168.2.13185.125.190.26
                      Session IDSource IPSource PortDestination IPDestination Port
                      0192.168.2.1341030103.188.82.21880
                      TimestampBytes transferredDirectionData
                      Dec 30, 2024 03:30:59.220451117 CET46OUTGET /mpsl HTTP/1.0
                      Data Raw: 00 00 52 41 59 0a 00 00 00 00 00 00
                      Data Ascii: RAY
                      Dec 30, 2024 03:31:00.156136036 CET1236INHTTP/1.0 200 OK
                      Accept-Ranges: bytes
                      Content-Length: 89592
                      Content-Type: application/octet-stream
                      Last-Modified: Wed, 25 Dec 2024 10:50:34 GMT
                      Date: Mon, 30 Dec 2024 02:30:59 GMT
                      Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 08 00 01 00 00 00 60 02 40 00 34 00 00 00 c8 5b 01 00 07 10 00 00 34 00 20 00 03 00 28 00 0e 00 0d 00 01 00 00 00 00 00 00 00 00 00 40 00 00 00 40 00 f0 51 01 00 f0 51 01 00 05 00 00 00 00 00 01 00 01 00 00 00 f4 51 01 00 f4 51 45 00 f4 51 45 00 70 09 00 00 34 5a 00 00 06 00 00 00 00 00 01 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 06 00 1c 3c 3c d5 9c 27 21 e0 99 03 e0 ff bd 27 10 00 bc af 1c 00 bf af 18 00 bc af 01 00 11 04 00 00 00 00 06 00 1c 3c 18 d5 9c 27 21 e0 9f 03 20 80 99 8f 00 00 00 00 dc 01 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 01 00 11 04 00 00 00 00 06 00 1c 3c e8 d4 9c 27 21 e0 9f 03 1c 80 99 8f 00 00 00 00 90 39 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 1c 00 bf 8f 00 00 00 00 08 00 e0 03 20 00 bd 27 06 00 1c 3c b0 d4 9c 27 21 e0 99 03 d8 ff bd 27 20 00 bf af 1c 00 b1 af 18 00 b0 af 10 00 bc af 18 80 91 8f 00 00 00 00 80 5b 22 92 00 00 00 00 1d 00 [TRUNCATED]
                      Data Ascii: ELF`@4[4 (@@QQQQEQEp4ZQtd<<'!'<'! 9' <'!99' '<'!' ["@RY B$ RRY B$@$ Q$$[" ('<'!'Q$@[$ R@R$ ' '!<d'!!'$$'H <'!'0,($ P!!00H $P@0,($ 8'P P@L ! @ $ ! [TRUNCATED]
                      Dec 30, 2024 03:31:00.156157970 CET1236INData Raw: 00 46 90 00 00 00 00 16 00 c0 18 00 00 00 00 04 84 82 8f 00 00 00 00 00 00 43 8c 00 00 00 00 00 00 64 8c 00 00 00 00 04 00 82 90 00 00 00 00 10 00 51 10 21 28 00 00 08 00 00 10 01 00 a5 24 04 00 64 8c 00 00 00 00 04 00 82 90 00 00 00 00 08 00 51
                      Data Ascii: FCdQ!($dQc$$ ! !(! @!0` !8<,'!000F$!@bc$%!(`!
                      Dec 30, 2024 03:31:00.156169891 CET1236INData Raw: 00 04 a2 08 00 05 24 09 f8 20 03 01 00 04 24 10 00 bc 8f 00 00 05 92 70 82 83 8f 70 83 99 8f 21 88 40 00 00 00 44 8e 02 00 02 24 80 28 05 00 00 00 23 ae 04 00 22 a2 09 f8 20 03 04 00 a5 24 00 00 04 92 10 00 bc 8f 80 18 04 00 24 84 99 8f 21 18 62
                      Data Ascii: $ $pp!@D$(#" $$!b$qB$ $p!@D$(#" $$!b$qB$ $p!@D$(#
                      Dec 30, 2024 03:31:00.156181097 CET1236INData Raw: 00 b1 a3 24 18 50 00 10 00 bc 8f 31 01 60 04 00 ff 02 24 94 83 99 8f 00 00 00 00 09 f8 20 03 29 00 a3 a3 24 18 50 00 10 00 bc 8f 25 01 60 04 00 ff 02 24 94 83 99 8f 00 00 00 00 09 f8 20 03 2a 00 a3 a3 24 18 50 00 10 00 bc 8f 19 01 60 04 00 ff 02
                      Data Ascii: $P1`$ )$P%`$ *$P`$$+,$=$-.0$$/0$$12$D$34{$#$569$$78$$9:$$<=$$>@$
                      Dec 30, 2024 03:31:00.156192064 CET1236INData Raw: 18 62 00 d9 fe 00 10 01 00 63 24 ff ff 63 24 25 18 62 00 cd fe 00 10 01 00 63 24 06 00 1c 3c 50 c3 9c 27 21 e0 99 03 70 ff bd 27 8c 00 bf af 88 00 be af 84 00 b7 af 80 00 b6 af 7c 00 b5 af 78 00 b4 af 74 00 b3 af 70 00 b2 af 6c 00 b1 af 68 00 b0
                      Data Ascii: bc$c$%bc$<P'!p'|xtplh('`:H$!0!0!00%%$ ) 6'
                      Dec 30, 2024 03:31:00.156203985 CET431INData Raw: 00 43 30 00 1a 03 00 02 12 02 00 18 00 bc 8f 25 98 43 00 20 00 b4 27 0b 00 00 10 ff 00 15 3c 10 00 50 8e 60 85 99 8f 28 00 b0 af 21 20 20 02 24 00 a5 27 09 f8 20 03 10 00 06 24 18 00 bc 8f 3e 00 40 04 00 00 00 00 c4 83 99 8f 04 00 03 24 01 00 02
                      Data Ascii: C0%C '<P`(! $' $>@$$!8! 4$ $$ !0H)@!@C$ c,$`&P $ 2F."%e%%!$
                      Dec 30, 2024 03:31:00.156215906 CET1236INData Raw: ff 00 92 30 64 00 a5 af 21 20 40 02 04 00 05 24 21 80 e0 00 09 f8 20 03 ff 00 d1 30 10 00 bc 8f 21 20 40 02 24 84 99 8f 04 00 05 24 09 f8 20 03 21 a8 40 00 10 00 bc 8f 21 20 20 02 84 82 99 8f 21 28 00 02 07 00 06 24 ff ff 07 34 09 f8 20 03 21 a0
                      Data Ascii: 0d! @$! 0! @$$ !@! !($4 !@B0! !($4 0! !(!0$ W0! !($$ S04 $(!2%b
                      Dec 30, 2024 03:31:00.156220913 CET1236INData Raw: ec 83 83 8f 84 82 99 8f 00 00 67 8c 03 16 02 00 19 00 06 24 21 20 20 02 21 28 00 02 09 f8 20 03 28 00 a2 af 18 00 bc 8f 38 00 a2 af 84 82 99 8f 21 20 20 02 21 28 00 02 21 30 00 00 09 f8 20 03 00 02 07 24 21 f0 40 00 79 05 42 28 18 00 bc 8f 02 00
                      Data Ascii: g$! !( (8! !(!0 $!@yB(@$$$ $$P4$$4 !($ 'PW2 '2C02"*%b%!$$
                      Dec 30, 2024 03:31:00.156234026 CET1236INData Raw: 5c 00 a2 af 18 00 bc 8f ff 00 42 30 84 82 99 8f 21 28 00 02 03 00 06 24 ff ff 07 34 21 20 20 02 09 f8 20 03 54 00 a2 af 18 00 bc 8f 21 28 00 02 84 82 99 8f 21 20 20 02 04 00 06 24 40 00 07 24 09 f8 20 03 21 b0 40 00 18 00 bc 8f ff 00 42 30 84 82
                      Data Ascii: \B0!($4! T!(! $@$ !@B0!(! $$ P!($4! L!(! $4 !@!(! !0$ !@!(! $$ H
                      Dec 30, 2024 03:31:00.156245947 CET1236INData Raw: 00 00 00 00 80 00 b0 12 00 00 00 00 40 00 a4 8f 00 00 00 00 84 00 80 10 00 00 00 00 10 00 22 8e 00 00 00 00 10 00 42 ae 44 00 a2 8f 00 00 00 00 87 00 40 14 00 00 00 00 c8 82 99 8f 21 20 20 02 14 00 05 24 09 f8 20 03 0a 00 20 a6 18 00 bc 8f 21 20
                      Data Ascii: @"BD@! $ ! @"$ @Bf`! @!(` ` @!# b! %$t$d@$!( ! d$*
                      Dec 30, 2024 03:31:00.161113024 CET1236INData Raw: 25 10 44 00 25 80 03 02 10 00 bc 8f 25 80 02 02 04 00 30 ae 60 85 99 8f 00 00 44 8e 21 28 20 02 09 f8 20 03 10 00 06 24 04 00 52 26 10 00 bc 8f b4 ff 74 16 18 00 31 26 ff ff 80 1a 00 00 00 00 21 98 00 00 21 90 00 00 54 82 99 8f 21 10 56 02 64 00
                      Data Ascii: %D%%0`D!( $R&t1&!!T!Vd$Q $P0! !(!\D!( !0@$ s&tR&! "TPLHD@<840


                      System Behavior

                      Start time (UTC):02:30:58
                      Start date (UTC):30/12/2024
                      Path:/tmp/dlr.mpsl.elf
                      Arguments:/tmp/dlr.mpsl.elf
                      File size:5773336 bytes
                      MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9