Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
boatnet.spc.elf

Overview

General Information

Sample name:boatnet.spc.elf
Analysis ID:1582571
MD5:ef909ca9e0048c2502cc8dcd1adfe080
SHA1:e0d15dc499778090a93147e341f78fec7d34e04e
SHA256:24f31a07bba5d0b50288287893a01d7f5f3520a37ba960b88805ce95bb527b88
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Mirai
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582571
Start date and time:2024-12-30 22:32:34 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 5m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:boatnet.spc.elf
Detection:MAL
Classification:mal76.spre.troj.linELF@0/0@0/0
  • VT rate limit hit for: boatnet.spc.elf
Command:/tmp/boatnet.spc.elf
PID:6265
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
lzrd cock fest"/proc/"/exe
Standard Error:
  • system is lnxubuntu20
  • wrapper-2.0 (PID: 6276, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
  • wrapper-2.0 (PID: 6277, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
  • wrapper-2.0 (PID: 6278, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
  • wrapper-2.0 (PID: 6279, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
  • wrapper-2.0 (PID: 6280, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
  • wrapper-2.0 (PID: 6281, Parent: 2063, MD5: ac0b8a906f359a8ae102244738682e76) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
  • xfconfd (PID: 6289, Parent: 6288, MD5: 4c7a0d6d258bb970905b19b84abcd8e9) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
  • xfconfd (PID: 6291, Parent: 6290, MD5: 4c7a0d6d258bb970905b19b84abcd8e9) Arguments: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
boatnet.spc.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    boatnet.spc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
    • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
    boatnet.spc.elfLinux_Trojan_Gafgyt_ea92cca8unknownunknown
    • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
    SourceRuleDescriptionAuthorStrings
    6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmpLinux_Trojan_Gafgyt_ea92cca8unknownunknown
      • 0xceb8:$a: 53 65 6C 66 20 52 65 70 20 46 75 63 6B 69 6E 67 20 4E 65 54 69 53 20 61 6E 64
      6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0xc958:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc96c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc980:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc994:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xc9f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca0c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca20:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca34:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca48:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca5c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca70:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca84:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xca98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0xcae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        Click to see the 7 entries
        No Suricata rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: boatnet.spc.elfAvira: detected
        Source: boatnet.spc.elfReversingLabs: Detection: 65%
        Source: global trafficTCP traffic: 192.168.2.23:46572 -> 104.168.45.33:3778
        Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
        Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
        Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownTCP traffic detected without corresponding DNS query: 104.168.45.33
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

        System Summary

        barindex
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: 6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: 6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 6270, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
        Source: Process Memory Space: boatnet.spc.elf PID: 6270, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2018, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2077, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2078, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2079, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2080, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2083, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2084, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2114, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2156, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6278, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6279, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6280, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6281, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6289, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6291, result: successfulJump to behavior
        Source: ELF static info symbol of initial sample.symtab present: no
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2018, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2077, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2078, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2079, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2080, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2083, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2084, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2114, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 2156, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6278, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6279, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6280, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6281, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6289, result: successfulJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)SIGKILL sent: pid: 6291, result: successfulJump to behavior
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: boatnet.spc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: 6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: 6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 6265, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 6270, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
        Source: Process Memory Space: boatnet.spc.elf PID: 6270, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
        Source: classification engineClassification label: mal76.spre.troj.linELF@0/0@0/0
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6276)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /home/saturnino/.Xdefaults-galassiaJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/local/share/fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /home/saturnino/.local/share/fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /home/saturnino/.fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/X11/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/cMap/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/cmap/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/opentype/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/type1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/X11/Type1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/X11/encodings/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/X11/misc/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/X11/util/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/cmap/adobe-cns1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/cmap/adobe-gb1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/cmap/adobe-japan1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/cmap/adobe-japan2/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/cmap/adobe-korea1/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/opentype/malayalam/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/opentype/mathjax/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/opentype/noto/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/opentype/urw-base35/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/Gargi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/Gubbi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/Nakula/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/Navilu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/Sahadeva/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/Sarai/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/abyssinica/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/ancient-scripts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/dejavu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/droid/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/freefont/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/kacst/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/kacst-one/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lao/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lato/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/liberation/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/liberation2/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-assamese/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-bengali/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-kannada/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-oriya/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-tamil/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/lohit-telugu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/malayalam/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/noto/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/openoffice/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/padauk/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/pagul/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/samyak/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/samyak-fonts/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/sinhala/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/tibetan-machine/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/tlwg/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/truetype/ubuntu/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/type1/urw-base35/.uuidJump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Directory: /usr/share/fonts/X11/encodings/large/.uuidJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1582/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2033/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2275/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/3088/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1612/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1579/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1699/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1335/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1698/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2028/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1334/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1576/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2302/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/3236/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2025/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2146/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/910/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/4444/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/4445/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/912/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/4446/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/517/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/759/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/4723/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2307/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/918/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1594/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2285/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2281/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1349/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1623/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/761/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1622/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/884/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1983/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2038/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1344/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1465/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1586/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1463/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2156/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/800/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/801/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1629/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1627/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1900/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6098/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/3021/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/491/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2294/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2050/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6250/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1877/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/772/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1633/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1599/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1632/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/774/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1477/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/654/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/896/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1476/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1872/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2048/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/655/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1475/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2289/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/656/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/777/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/657/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6249/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/658/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/419/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/936/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1639/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1638/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2208/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2180/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1809/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1494/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1890/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2063/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2062/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1888/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/4519/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1886/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/420/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1489/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/785/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1642/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/788/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/667/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/789/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/1648/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6276/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6278/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6277/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6279/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2078/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2077/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2074/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2195/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/670/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/6271/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6268)File opened: /proc/2746/cmdlineJump to behavior
        Source: /tmp/boatnet.spc.elf (PID: 6265)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6276)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 6277)Queries kernel information via 'uname': Jump to behavior
        Source: boatnet.spc.elf, 6265.1.000055c6a2b10000.000055c6a2b95000.rw-.sdmp, boatnet.spc.elf, 6270.1.000055c6a2b10000.000055c6a2b95000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sparc
        Source: boatnet.spc.elf, 6265.1.000055c6a2b10000.000055c6a2b95000.rw-.sdmp, boatnet.spc.elf, 6270.1.000055c6a2b10000.000055c6a2b95000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/sparc
        Source: boatnet.spc.elf, 6265.1.00007ffd4136e000.00007ffd4138f000.rw-.sdmp, boatnet.spc.elf, 6270.1.00007ffd4136e000.00007ffd4138f000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sparc/tmp/boatnet.spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.spc.elf
        Source: boatnet.spc.elf, 6265.1.00007ffd4136e000.00007ffd4138f000.rw-.sdmp, boatnet.spc.elf, 6270.1.00007ffd4136e000.00007ffd4138f000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sparc

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 6265, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 6270, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: boatnet.spc.elf, type: SAMPLE
        Source: Yara matchFile source: 6270.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6265.1.00007fbdd0011000.00007fbdd001f000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 6265, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: boatnet.spc.elf PID: 6270, type: MEMORYSTR
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
        Hidden Files and Directories
        1
        OS Credential Dumping
        11
        Security Software Discovery
        Remote ServicesData from Local System1
        Encrypted Channel
        Exfiltration Over Other Network Medium1
        Service Stop
        CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
        Non-Standard Port
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
        Application Layer Protocol
        Automated ExfiltrationData Encrypted for Impact
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1582571 Sample: boatnet.spc.elf Startdate: 30/12/2024 Architecture: LINUX Score: 76 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->24 26 2 other IPs or domains 2->26 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 Yara detected Mirai 2->34 7 boatnet.spc.elf 2->7         started        9 xfce4-panel wrapper-2.0 2->9         started        11 xfce4-panel wrapper-2.0 2->11         started        13 6 other processes 2->13 signatures3 process4 process5 15 boatnet.spc.elf 7->15         started        18 boatnet.spc.elf 7->18         started        20 boatnet.spc.elf 7->20         started        signatures6 36 Sample tries to kill multiple processes (SIGKILL) 15->36

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        boatnet.spc.elf66%ReversingLabsLinux.Backdoor.Mirai
        boatnet.spc.elf100%AviraEXP/ELF.Gafgyt.D
        No Antivirus matches
        No Antivirus matches
        No Antivirus matches
        No contacted domains info
        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs
        IPDomainCountryFlagASNASN NameMalicious
        109.202.202.202
        unknownSwitzerland
        13030INIT7CHfalse
        104.168.45.33
        unknownUnited States
        36352AS-COLOCROSSINGUSfalse
        91.189.91.43
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        91.189.91.42
        unknownUnited Kingdom
        41231CANONICAL-ASGBfalse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
        • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
        104.168.45.33boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
          boatnet.arm.elfGet hashmaliciousMiraiBrowse
            boatnet.x86.elfGet hashmaliciousMiraiBrowse
              boatnet.mips.elfGet hashmaliciousMiraiBrowse
                91.189.91.43boatnet.x86.elfGet hashmaliciousMiraiBrowse
                  i.elfGet hashmaliciousUnknownBrowse
                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                      boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                        boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                          kwari.m68k.elfGet hashmaliciousUnknownBrowse
                            fenty.arm5.elfGet hashmaliciousMiraiBrowse
                              boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                  boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                    91.189.91.42boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                      i.elfGet hashmaliciousUnknownBrowse
                                        boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                            boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                              kwari.m68k.elfGet hashmaliciousUnknownBrowse
                                                fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                  boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                    fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                      boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                                        No context
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        CANONICAL-ASGBboatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        i.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        kwari.m68k.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                        • 185.125.190.26
                                                        CANONICAL-ASGBboatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        i.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        kwari.m68k.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                        • 185.125.190.26
                                                        AS-COLOCROSSINGUSboatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                        • 104.168.45.33
                                                        boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                        • 104.168.45.33
                                                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 104.168.45.33
                                                        boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                        • 104.168.45.33
                                                        rebirth.m68.elfGet hashmaliciousGafgytBrowse
                                                        • 23.95.72.235
                                                        rebirth.mips.elfGet hashmaliciousGafgytBrowse
                                                        • 23.95.72.235
                                                        rebirth.arm6.elfGet hashmaliciousGafgytBrowse
                                                        • 23.95.72.235
                                                        rebirth.ppc.elfGet hashmaliciousGafgytBrowse
                                                        • 23.95.72.235
                                                        rebirth.arm4t.elfGet hashmaliciousGafgytBrowse
                                                        • 23.95.72.235
                                                        rebirth.x86.elfGet hashmaliciousGafgytBrowse
                                                        • 23.95.72.235
                                                        INIT7CHboatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        i.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        kwari.m68k.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        boatnet.x86.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        boatnet.arc.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        No context
                                                        No context
                                                        No created / dropped files found
                                                        File type:ELF 32-bit MSB executable, SPARC, version 1 (SYSV), statically linked, stripped
                                                        Entropy (8bit):6.066372228461725
                                                        TrID:
                                                        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                        File name:boatnet.spc.elf
                                                        File size:58'376 bytes
                                                        MD5:ef909ca9e0048c2502cc8dcd1adfe080
                                                        SHA1:e0d15dc499778090a93147e341f78fec7d34e04e
                                                        SHA256:24f31a07bba5d0b50288287893a01d7f5f3520a37ba960b88805ce95bb527b88
                                                        SHA512:c8d8b1c7e5a9033bbc6c73f2cad71de869fff6e2b24fafcfc5b1f1181412d9f1b6dfa59fa2198cd5a189c6053bb54795579acb8a544078557f980fef8634bafc
                                                        SSDEEP:768:RqowmZPu9wtnfbltWgC6BSJsBcfDSTFIuQKqgESnmC/xO+KpAwJ:RqtmZPuutfbltZFBSJsBcfDSTFI+BEJ
                                                        TLSH:58432921B63A1F13D0E0A47D21FB4B59B1A15ADE26A4C64E7D720F4FFF11680A943DB8
                                                        File Content Preview:.ELF...........................4...x.....4. ...(.......................................................8...P........dt.Q................................@..(....@.2.................#.....b8..`.....!..... ...@.....".........`......$ ... ...@...........`....

                                                        ELF header

                                                        Class:ELF32
                                                        Data:2's complement, big endian
                                                        Version:1 (current)
                                                        Machine:Sparc
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:UNIX - System V
                                                        ABI Version:0
                                                        Entry Point Address:0x101a4
                                                        Flags:0x0
                                                        ELF Header Size:52
                                                        Program Header Offset:52
                                                        Program Header Size:32
                                                        Number of Program Headers:3
                                                        Section Header Offset:57976
                                                        Section Header Size:40
                                                        Number of Section Headers:10
                                                        Header String Table Index:9
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .initPROGBITS0x100940x940x1c0x00x6AX004
                                                        .textPROGBITS0x100b00xb00xc8880x00x6AX004
                                                        .finiPROGBITS0x1c9380xc9380x140x00x6AX004
                                                        .rodataPROGBITS0x1c9500xc9500x11b00x00x2A008
                                                        .ctorsPROGBITS0x2e0000xe0000x80x00x3WA004
                                                        .dtorsPROGBITS0x2e0080xe0080x80x00x3WA004
                                                        .dataPROGBITS0x2e0180xe0180x2200x00x3WA008
                                                        .bssNOBITS0x2e2380xe2380x3180x00x3WA004
                                                        .shstrtabSTRTAB0x00xe2380x3e0x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x100000x100000xdb000xdb006.17290x5R E0x10000.init .text .fini .rodata
                                                        LOAD0xe0000x2e0000x2e0000x2380x5502.92290x6RW 0x10000.ctors .dtors .data .bss
                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Dec 30, 2024 22:33:40.419565916 CET465723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.424451113 CET377846572104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:40.424526930 CET465723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.485646963 CET465723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.490425110 CET377846572104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:40.490467072 CET465723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.495275974 CET377846572104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:40.905299902 CET377846572104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:40.905364990 CET465723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.906349897 CET465723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.923953056 CET465743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.934995890 CET377846574104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:40.935070038 CET465743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.937844992 CET465743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.942642927 CET377846574104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:40.942692041 CET465743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:40.947534084 CET377846574104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.151751995 CET43928443192.168.2.2391.189.91.42
                                                        Dec 30, 2024 22:33:41.433073044 CET377846574104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.433156013 CET465743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.433156013 CET465743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.435034990 CET465763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.439819098 CET377846576104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.439857006 CET465763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.442751884 CET465763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.447576046 CET377846576104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.447614908 CET465763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.452409983 CET377846576104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.921664953 CET377846576104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.921714067 CET465763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.921766996 CET465763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.923449039 CET465783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.928236008 CET377846578104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.928281069 CET465783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.931282997 CET465783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.936047077 CET377846578104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:41.936084986 CET465783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:41.940840960 CET377846578104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.395003080 CET377846578104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.395083904 CET465783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.395083904 CET465783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.437792063 CET465803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.442598104 CET377846580104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.442763090 CET465803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.550463915 CET465803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.555361032 CET377846580104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.555416107 CET465803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.560312986 CET377846580104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.904012918 CET377846580104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.904118061 CET465803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.904118061 CET465803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.906126022 CET465823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.910980940 CET377846582104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.911034107 CET465823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.916042089 CET465823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.920860052 CET377846582104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:42.920901060 CET465823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:42.925645113 CET377846582104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.403693914 CET377846582104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.403739929 CET465823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.403775930 CET465823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.405648947 CET465843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.410554886 CET377846584104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.410810947 CET465843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.415510893 CET465843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.420320034 CET377846584104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.420409918 CET465843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.425203085 CET377846584104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.881247044 CET377846584104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.881352901 CET465843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.881352901 CET465843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.882584095 CET465863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.887373924 CET377846586104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.887450933 CET465863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.890739918 CET465863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.895503044 CET377846586104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:43.895590067 CET465863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:43.900338888 CET377846586104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.380029917 CET377846586104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.380096912 CET465863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.380167961 CET465863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.381927013 CET465883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.386734962 CET377846588104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.386825085 CET465883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.390454054 CET465883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.395220995 CET377846588104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.395266056 CET465883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.400024891 CET377846588104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.846065044 CET377846588104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.846153021 CET465883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.846225977 CET465883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.848526001 CET465903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.853334904 CET377846590104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.853398085 CET465903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.859170914 CET465903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.863946915 CET377846590104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:44.863986969 CET465903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:44.868881941 CET377846590104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.315922976 CET377846590104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.315999985 CET465903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.315999985 CET465903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.317238092 CET465923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.322024107 CET377846592104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.322072983 CET465923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.324842930 CET465923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.329592943 CET377846592104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.329672098 CET465923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.334431887 CET377846592104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.795286894 CET377846592104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.795340061 CET465923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.795386076 CET465923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.796737909 CET465943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.802661896 CET377846594104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.802736998 CET465943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.805757999 CET465943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.811275959 CET377846594104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:45.811326027 CET465943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:45.816982031 CET377846594104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.315367937 CET377846594104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.315773010 CET465943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.315773010 CET465943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.316824913 CET465963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.321656942 CET377846596104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.321857929 CET465963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.324425936 CET465963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.329247952 CET377846596104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.329293013 CET465963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.334156990 CET377846596104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.785763979 CET42836443192.168.2.2391.189.91.43
                                                        Dec 30, 2024 22:33:46.814846992 CET377846596104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.814934015 CET465963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.815022945 CET465963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.868474960 CET465983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.874113083 CET377846598104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.874162912 CET465983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.882026911 CET465983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.886898994 CET377846598104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:46.886938095 CET465983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:46.891748905 CET377846598104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:47.546586037 CET377846598104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:47.546933889 CET465983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:47.546972990 CET465983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:47.548186064 CET466003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:47.553096056 CET377846600104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:47.553163052 CET466003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:47.555948019 CET466003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:47.560784101 CET377846600104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:47.560883045 CET466003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:47.565663099 CET377846600104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.199265957 CET377846600104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.199361086 CET466003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.199361086 CET466003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.200954914 CET466023778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.205878973 CET377846602104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.205981970 CET466023778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.208659887 CET466023778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.213443995 CET377846602104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.213494062 CET466023778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.218281031 CET377846602104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.669487953 CET377846602104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.669608116 CET466023778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.669609070 CET466023778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.670902967 CET466043778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.675720930 CET377846604104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.675853968 CET466043778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.678451061 CET466043778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.683212996 CET377846604104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:48.683391094 CET466043778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:48.688184977 CET377846604104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:49.154294968 CET377846604104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:49.154407978 CET466043778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:49.154407978 CET466043778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:49.155780077 CET466063778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:49.163841963 CET377846606104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:49.163888931 CET466063778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:49.166799068 CET466063778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:49.174839973 CET377846606104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:49.174957037 CET466063778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:49.183104992 CET377846606104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.149302006 CET377846606104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.149360895 CET466063778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.149473906 CET466063778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.177809954 CET466083778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.182728052 CET377846608104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.182943106 CET466083778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.239171982 CET466083778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.243977070 CET377846608104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.244023085 CET466083778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.248840094 CET377846608104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.922646046 CET377846608104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.922749996 CET466083778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.922790051 CET466083778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.923217058 CET466103778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.928026915 CET377846610104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.928085089 CET466103778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.928805113 CET466103778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.933641911 CET377846610104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:50.933695078 CET466103778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:50.938534021 CET377846610104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.411122084 CET377846610104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.411237001 CET466103778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.411274910 CET466103778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.411899090 CET466123778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.416737080 CET377846612104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.416821957 CET466123778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.417530060 CET466123778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.422383070 CET377846612104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.422444105 CET466123778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.427261114 CET377846612104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.964065075 CET377846612104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.964148045 CET466123778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.964206934 CET466123778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.964735985 CET466143778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.969651937 CET377846614104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.969748020 CET466143778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.970488071 CET466143778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.975264072 CET377846614104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:51.975341082 CET466143778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:51.980129004 CET377846614104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:52.770744085 CET377846614104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:52.770858049 CET466143778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:52.770858049 CET466143778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:52.771401882 CET466163778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:52.781455040 CET377846616104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:52.781538963 CET466163778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:52.782175064 CET466163778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:52.786973000 CET377846616104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:52.787035942 CET466163778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:52.791969061 CET377846616104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:53.389056921 CET377846616104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:53.389182091 CET466163778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:53.389182091 CET466163778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:53.389646053 CET466183778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:53.394469976 CET377846618104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:53.394551039 CET466183778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:53.395176888 CET466183778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:53.399923086 CET377846618104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:53.400012970 CET466183778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:53.404882908 CET377846618104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.057751894 CET377846618104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.057846069 CET466183778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.057878971 CET466183778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.058361053 CET466203778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.063163042 CET377846620104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.063239098 CET466203778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.063958883 CET466203778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.068782091 CET377846620104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.068825006 CET466203778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.073621988 CET377846620104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.639144897 CET377846620104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.639329910 CET466203778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.639359951 CET466203778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.639735937 CET466223778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.646111012 CET377846622104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.646190882 CET466223778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.646836996 CET466223778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.653245926 CET377846622104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:54.653318882 CET466223778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:54.658613920 CET377846622104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.190047026 CET377846622104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.190167904 CET466223778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.190203905 CET466223778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.190728903 CET466243778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.195492029 CET377846624104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.195571899 CET466243778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.196182966 CET466243778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.201029062 CET377846624104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.201112032 CET466243778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.205897093 CET377846624104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.843879938 CET377846624104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.843997002 CET466243778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.844031096 CET466243778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.844471931 CET466263778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.849348068 CET377846626104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.849406004 CET466263778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.850086927 CET466263778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.854912043 CET377846626104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:55.854978085 CET466263778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:55.859740973 CET377846626104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:56.621784925 CET377846626104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:56.621876001 CET466263778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:56.621921062 CET466263778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:56.622432947 CET466283778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:56.627249002 CET377846628104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:56.627305031 CET466283778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:56.627994061 CET466283778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:56.632826090 CET377846628104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:56.632900000 CET466283778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:56.637725115 CET377846628104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:57.496814013 CET377846628104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:57.496928930 CET466283778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:57.496928930 CET466283778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:57.497375965 CET466303778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:57.502300024 CET377846630104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:57.502470016 CET466303778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:57.503053904 CET466303778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:57.507819891 CET377846630104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:57.507893085 CET466303778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:57.512718916 CET377846630104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.075160027 CET377846630104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.075263977 CET466303778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.075263977 CET466303778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.075654030 CET466323778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.080538034 CET377846632104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.080619097 CET466323778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.081244946 CET466323778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.085978031 CET377846632104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.086028099 CET466323778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.090814114 CET377846632104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.550877094 CET377846632104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.550997972 CET466323778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.551039934 CET466323778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.551537991 CET466343778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.556377888 CET377846634104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.556453943 CET466343778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.557184935 CET466343778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.561999083 CET377846634104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:58.562052011 CET466343778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:58.566953897 CET377846634104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.054949045 CET377846634104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.055082083 CET466343778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.055083036 CET466343778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.055669069 CET466363778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.060564995 CET377846636104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.060611010 CET466363778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.061301947 CET466363778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.066036940 CET377846636104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.066097975 CET466363778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.070875883 CET377846636104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.534689903 CET377846636104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.534804106 CET466363778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.534878016 CET466363778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.535454988 CET466383778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.540249109 CET377846638104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.540319920 CET466383778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.540926933 CET466383778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.545736074 CET377846638104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:33:59.545795918 CET466383778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:33:59.550672054 CET377846638104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.070168018 CET377846638104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.070297003 CET466383778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.070326090 CET466383778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.070765972 CET466403778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.075651884 CET377846640104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.075717926 CET466403778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.076376915 CET466403778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.081183910 CET377846640104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.081227064 CET466403778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.085990906 CET377846640104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.641062975 CET377846640104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.641145945 CET466403778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.641171932 CET466403778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.641588926 CET466423778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.646450043 CET377846642104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.646512985 CET466423778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.647068977 CET466423778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.651932955 CET377846642104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:00.651976109 CET466423778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:00.656776905 CET377846642104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.121742010 CET377846642104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.121857882 CET466423778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.121898890 CET466423778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.122339010 CET466443778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.127151966 CET377846644104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.127233028 CET466443778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.127799034 CET466443778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.132536888 CET377846644104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.132611036 CET466443778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.137427092 CET377846644104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.603913069 CET377846644104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.604116917 CET466443778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.604116917 CET466443778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.604502916 CET466463778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.609289885 CET377846646104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.609338999 CET466463778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.610016108 CET466463778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.614821911 CET377846646104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.614996910 CET466463778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:01.619791031 CET377846646104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:01.628926039 CET43928443192.168.2.2391.189.91.42
                                                        Dec 30, 2024 22:34:02.113904953 CET377846646104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:02.114167929 CET466463778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.114167929 CET466463778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.114653111 CET466483778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.119455099 CET377846648104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:02.119551897 CET466483778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.120172024 CET466483778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.124938965 CET377846648104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:02.125006914 CET466483778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.129825115 CET377846648104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:02.602958918 CET377846648104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:02.603075981 CET466483778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.603107929 CET466483778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.603565931 CET466503778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.608386040 CET377846650104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:02.608453035 CET466503778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.609019995 CET466503778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.613775969 CET377846650104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:02.613816977 CET466503778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:02.618607044 CET377846650104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.089479923 CET377846650104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.089600086 CET466503778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.089600086 CET466503778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.090078115 CET466523778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.094945908 CET377846652104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.095000982 CET466523778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.095662117 CET466523778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.100433111 CET377846652104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.100480080 CET466523778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.105261087 CET377846652104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.557501078 CET377846652104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.557619095 CET466523778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.557641983 CET466523778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.558090925 CET466543778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.563275099 CET377846654104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.563334942 CET466543778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.564055920 CET466543778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.572362900 CET377846654104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:03.572428942 CET466543778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:03.580770016 CET377846654104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.038220882 CET377846654104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.038358927 CET466543778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.038358927 CET466543778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.038783073 CET466563778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.043550014 CET377846656104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.043620110 CET466563778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.044250965 CET466563778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.049046993 CET377846656104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.049134970 CET466563778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.053881884 CET377846656104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.515851021 CET377846656104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.516020060 CET466563778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.516052961 CET466563778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.516366005 CET466583778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.521680117 CET377846658104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.521743059 CET466583778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.522366047 CET466583778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.527189016 CET377846658104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.527297020 CET466583778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.532094002 CET377846658104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.993725061 CET377846658104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.993861914 CET466583778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.993954897 CET466583778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.994592905 CET466603778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:04.999464989 CET377846660104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:04.999542952 CET466603778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.000540972 CET466603778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.005681038 CET377846660104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.005743980 CET466603778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.011693001 CET377846660104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.508006096 CET377846660104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.508130074 CET466603778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.508157969 CET466603778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.508718967 CET466623778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.513479948 CET377846662104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.513542891 CET466623778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.514113903 CET466623778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.518979073 CET377846662104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.519022942 CET466623778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.524049044 CET377846662104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.724381924 CET4251680192.168.2.23109.202.202.202
                                                        Dec 30, 2024 22:34:05.984493017 CET377846662104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.984595060 CET466623778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.984633923 CET466623778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.985068083 CET466643778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.989908934 CET377846664104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.989954948 CET466643778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.990509987 CET466643778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:05.995244980 CET377846664104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:05.995295048 CET466643778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.000413895 CET377846664104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.470690966 CET377846664104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.470796108 CET466643778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.470820904 CET466643778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.471198082 CET466663778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.475990057 CET377846666104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.476049900 CET466663778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.476660013 CET466663778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.481410027 CET377846666104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.481457949 CET466663778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.486253977 CET377846666104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.938574076 CET377846666104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.938676119 CET466663778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.938695908 CET466663778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.939081907 CET466683778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.943948984 CET377846668104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.944010019 CET466683778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.944552898 CET466683778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.949295044 CET377846668104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:06.949340105 CET466683778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:06.954154968 CET377846668104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.406303883 CET377846668104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.406405926 CET466683778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.406452894 CET466683778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.406861067 CET466703778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.411700010 CET377846670104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.411742926 CET466703778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.412285089 CET466703778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.417001963 CET377846670104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.417042017 CET466703778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.421849012 CET377846670104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.911521912 CET377846670104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.911602974 CET466703778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.911602974 CET466703778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.911979914 CET466723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.916731119 CET377846672104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.916835070 CET466723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.917363882 CET466723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.922184944 CET377846672104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:07.922255039 CET466723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:07.927103996 CET377846672104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.408416033 CET377846672104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.408512115 CET466723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.408512115 CET466723778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.408956051 CET466743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.413712025 CET377846674104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.413760900 CET466743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.414222956 CET466743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.419008970 CET377846674104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.419044971 CET466743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.424084902 CET377846674104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.881731987 CET377846674104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.882018089 CET466743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.882047892 CET466743778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.882421970 CET466763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.889024019 CET377846676104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.889141083 CET466763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.889640093 CET466763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.894491911 CET377846676104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:08.894644976 CET466763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:08.899403095 CET377846676104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.351840019 CET377846676104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.352164030 CET466763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.352164030 CET466763778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.352503061 CET466783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.357244968 CET377846678104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.357319117 CET466783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.357876062 CET466783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.362637043 CET377846678104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.362698078 CET466783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.367460012 CET377846678104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.841770887 CET377846678104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.841937065 CET466783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.841969013 CET466783778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.842418909 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.847240925 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.847331047 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.847876072 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.852638960 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:09.852703094 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:09.857501984 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.320806026 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.320967913 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.321007967 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.321310043 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.321321011 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.321388960 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.321388960 CET466823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.321424961 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.322828054 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.322882891 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.324011087 CET377846680104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.324065924 CET466803778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.326311111 CET377846682104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.326381922 CET466823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.326914072 CET466823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.331666946 CET377846682104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.331727982 CET466823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.336551905 CET377846682104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.797700882 CET377846682104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.797904015 CET466823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.797904015 CET466823778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.798190117 CET466843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.803035021 CET377846684104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.803102970 CET466843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.803627014 CET466843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.808451891 CET377846684104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:11.808510065 CET466843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:11.813319921 CET377846684104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.300201893 CET377846684104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.300321102 CET466843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.300321102 CET466843778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.300674915 CET466863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.305543900 CET377846686104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.305603027 CET466863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.306104898 CET466863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.311049938 CET377846686104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.311109066 CET466863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.315973043 CET377846686104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.777172089 CET377846686104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.777268887 CET466863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.777342081 CET466863778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.777647018 CET466883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.782443047 CET377846688104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.782490015 CET466883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.782999992 CET466883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.787734985 CET377846688104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:12.787774086 CET466883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:12.792524099 CET377846688104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.253475904 CET377846688104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.253577948 CET466883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.253577948 CET466883778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.253917933 CET466903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.258717060 CET377846690104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.258769035 CET466903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.259254932 CET466903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.263993025 CET377846690104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.264030933 CET466903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.268744946 CET377846690104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.723939896 CET377846690104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.724061012 CET466903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.724086046 CET466903778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.724507093 CET466923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.729260921 CET377846692104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.729305029 CET466923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.729820967 CET466923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.734564066 CET377846692104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.734612942 CET466923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:13.739355087 CET377846692104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:13.915275097 CET42836443192.168.2.2391.189.91.43
                                                        Dec 30, 2024 22:34:14.219168901 CET377846692104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:14.219240904 CET466923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.219281912 CET466923778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.219578028 CET466943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.224417925 CET377846694104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:14.224462986 CET466943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.224983931 CET466943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.229804039 CET377846694104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:14.229845047 CET466943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.234702110 CET377846694104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:14.706417084 CET377846694104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:14.706522942 CET466943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.706568956 CET466943778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.706952095 CET466963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.711783886 CET377846696104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:14.711827040 CET466963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.712311029 CET466963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.717122078 CET377846696104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:14.717159033 CET466963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:14.721946955 CET377846696104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.176951885 CET377846696104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.177050114 CET466963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.177051067 CET466963778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.177472115 CET466983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.182358980 CET377846698104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.182395935 CET466983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.182928085 CET466983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.187680960 CET377846698104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.187720060 CET466983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.192594051 CET377846698104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.687843084 CET377846698104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.687928915 CET466983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.687928915 CET466983778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.688361883 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.693197966 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.693244934 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.693761110 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.698554039 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:15.698591948 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:15.703316927 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:25.701746941 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:25.706674099 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:25.804912090 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:34:25.804965019 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:34:42.583527088 CET43928443192.168.2.2391.189.91.42
                                                        Dec 30, 2024 22:35:25.845375061 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:35:25.850277901 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:35:25.949348927 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:35:25.949398994 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:36:25.989042997 CET467003778192.168.2.23104.168.45.33
                                                        Dec 30, 2024 22:36:25.993916035 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:36:26.106123924 CET377846700104.168.45.33192.168.2.23
                                                        Dec 30, 2024 22:36:26.106237888 CET467003778192.168.2.23104.168.45.33

                                                        System Behavior

                                                        Start time (UTC):21:33:39
                                                        Start date (UTC):30/12/2024
                                                        Path:/tmp/boatnet.spc.elf
                                                        Arguments:/tmp/boatnet.spc.elf
                                                        File size:4379400 bytes
                                                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                        Start time (UTC):21:33:39
                                                        Start date (UTC):30/12/2024
                                                        Path:/tmp/boatnet.spc.elf
                                                        Arguments:-
                                                        File size:4379400 bytes
                                                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                        Start time (UTC):21:33:39
                                                        Start date (UTC):30/12/2024
                                                        Path:/tmp/boatnet.spc.elf
                                                        Arguments:-
                                                        File size:4379400 bytes
                                                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                        Start time (UTC):21:33:39
                                                        Start date (UTC):30/12/2024
                                                        Path:/tmp/boatnet.spc.elf
                                                        Arguments:-
                                                        File size:4379400 bytes
                                                        MD5 hash:7dc1c0e23cd5e102bb12e5c29403410e

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/xfce4-panel
                                                        Arguments:-
                                                        File size:375768 bytes
                                                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libsystray.so 6 12582920 systray "Notification Area" "Area where notification icons appear"
                                                        File size:35136 bytes
                                                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/xfce4-panel
                                                        Arguments:-
                                                        File size:375768 bytes
                                                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libstatusnotifier.so 7 12582921 statusnotifier "Status Notifier Plugin" "Provides a panel area for status notifier items (application indicators)"
                                                        File size:35136 bytes
                                                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/xfce4-panel
                                                        Arguments:-
                                                        File size:375768 bytes
                                                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libpulseaudio-plugin.so 8 12582922 pulseaudio "PulseAudio Plugin" "Adjust the audio volume of the PulseAudio sound system"
                                                        File size:35136 bytes
                                                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/xfce4-panel
                                                        Arguments:-
                                                        File size:375768 bytes
                                                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libxfce4powermanager.so 9 12582923 power-manager-plugin "Power Manager Plugin" "Display the battery levels of your devices and control the brightness of your display"
                                                        File size:35136 bytes
                                                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/xfce4-panel
                                                        Arguments:-
                                                        File size:375768 bytes
                                                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libnotification-plugin.so 10 12582924 notification-plugin "Notification Plugin" "Notification plugin for the Xfce panel"
                                                        File size:35136 bytes
                                                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/xfce4-panel
                                                        Arguments:-
                                                        File size:375768 bytes
                                                        MD5 hash:a15b657c7d54ac1385f1f15004ea6784

                                                        Start time (UTC):21:33:40
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 /usr/lib/x86_64-linux-gnu/xfce4/panel/plugins/libactions.so 14 12582925 actions "Action Buttons" "Log out, lock or other system actions"
                                                        File size:35136 bytes
                                                        MD5 hash:ac0b8a906f359a8ae102244738682e76

                                                        Start time (UTC):21:33:42
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/dbus-daemon
                                                        Arguments:-
                                                        File size:249032 bytes
                                                        MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                        Start time (UTC):21:33:42
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                                                        File size:112880 bytes
                                                        MD5 hash:4c7a0d6d258bb970905b19b84abcd8e9
                                                        Start time (UTC):21:33:43
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/bin/dbus-daemon
                                                        Arguments:-
                                                        File size:249032 bytes
                                                        MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                        Start time (UTC):21:33:43
                                                        Start date (UTC):30/12/2024
                                                        Path:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                                                        Arguments:/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd
                                                        File size:112880 bytes
                                                        MD5 hash:4c7a0d6d258bb970905b19b84abcd8e9