Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
mips.elf

Overview

General Information

Sample name:mips.elf
Analysis ID:1583603
MD5:8114962499a4fb37d15a636e3676d572
SHA1:edf095bad33e88bd9d21a1690a601232317ce351
SHA256:afe1cc80e06d92bbe16070b220541a5edad0a767c9cf8aa566dc914a6ab66d60
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583603
Start date and time:2025-01-03 07:52:10 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 32s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:mips.elf
Detection:MAL
Classification:mal48.linELF@0/0@0/0
Command:/tmp/mips.elf
PID:6228
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • mips.elf (PID: 6228, Parent: 6151, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/mips.elf
    • mips.elf New Fork (PID: 6230, Parent: 6228)
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: mips.elfReversingLabs: Detection: 15%
Source: global trafficTCP traffic: 192.168.2.23:50742 -> 85.239.34.134:31337
Source: /tmp/mips.elf (PID: 6228)Socket: 0.0.0.0:3142Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.34.134
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/0@0/0
Source: /tmp/mips.elf (PID: 6228)Queries kernel information via 'uname': Jump to behavior
Source: mips.elf, 6228.1.000055d69f144000.000055d69f1cb000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mips
Source: mips.elf, 6228.1.000055d69f144000.000055d69f1cb000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: mips.elf, 6228.1.00007ffdc2fff000.00007ffdc3020000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/mips.elf
Source: mips.elf, 6228.1.00007ffdc2fff000.00007ffdc3020000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
mips.elf16%ReversingLabsLinux.Backdoor.Gafgyt
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
85.239.34.134
unknownRussian Federation
134121RAINBOW-HKRainbownetworklimitedHKfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
85.239.34.134arm7.elfGet hashmaliciousUnknownBrowse
    arm.elfGet hashmaliciousUnknownBrowse
      arm7.elfGet hashmaliciousUnknownBrowse
        mpsl.elfGet hashmaliciousUnknownBrowse
          arm5.elfGet hashmaliciousUnknownBrowse
            ppc.elfGet hashmaliciousUnknownBrowse
              mips.elfGet hashmaliciousUnknownBrowse
                arm6.elfGet hashmaliciousUnknownBrowse
                  m68k.elfGet hashmaliciousUnknownBrowse
                    sh4.elfGet hashmaliciousUnknownBrowse
                      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                      91.189.91.43arm7.elfGet hashmaliciousUnknownBrowse
                        x86_64.elfGet hashmaliciousMiraiBrowse
                          arm5.elfGet hashmaliciousUnknownBrowse
                            141.11.33.73-boatnet.arm-2025-01-03T05_39_17.elfGet hashmaliciousMiraiBrowse
                              arm5.elfGet hashmaliciousMiraiBrowse
                                i.elfGet hashmaliciousUnknownBrowse
                                  mpsl.elfGet hashmaliciousMiraiBrowse
                                    ARMV6L.elfGet hashmaliciousUnknownBrowse
                                      MIPS.elfGet hashmaliciousUnknownBrowse
                                        arm5.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.42arm7.elfGet hashmaliciousUnknownBrowse
                                            x86_64.elfGet hashmaliciousMiraiBrowse
                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                141.11.33.73-boatnet.arm-2025-01-03T05_39_17.elfGet hashmaliciousMiraiBrowse
                                                  arm5.elfGet hashmaliciousMiraiBrowse
                                                    i.elfGet hashmaliciousUnknownBrowse
                                                      mpsl.elfGet hashmaliciousMiraiBrowse
                                                        ARMV6L.elfGet hashmaliciousUnknownBrowse
                                                          MIPS.elfGet hashmaliciousUnknownBrowse
                                                            arm5.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              RAINBOW-HKRainbownetworklimitedHKarm7.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              arm.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              https://klickskydd.skolverket.org/?url=https%3A%2F%2Fwww.gazeta.ru%2Fpolitics%2Fnews%2F2024%2F12%2F22%2F24684722.shtml&id=71de&rcpt=upplysningstjansten@skolverket.se&tss=1735469857&msgid=b53e7603-c5d3-11ef-8a2e-0050569b0508&html=1&h=ded85c63Get hashmaliciousHTMLPhisherBrowse
                                                              • 45.138.161.76
                                                              https://www.gazeta.ru/politics/news/2024/12/22/24684722.shtmlGet hashmaliciousHTMLPhisherBrowse
                                                              • 45.138.161.75
                                                              https://www.gazeta.ru/politics/news/2024/12/22/24684854.shtmlGet hashmaliciousHTMLPhisherBrowse
                                                              • 45.138.161.71
                                                              arm7.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              mpsl.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              mips.elfGet hashmaliciousUnknownBrowse
                                                              • 85.239.34.134
                                                              CANONICAL-ASGBarm7.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              x86_64.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              141.11.33.73-boatnet.arm-2025-01-03T05_39_17.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              i.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              ARMV6L.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              MIPS.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              INIT7CHarm7.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              x86_64.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              141.11.33.73-boatnet.arm-2025-01-03T05_39_17.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              i.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              mpsl.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              ARMV6L.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              MIPS.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              arm5.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                                              Entropy (8bit):5.236046755299733
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:mips.elf
                                                              File size:31'008 bytes
                                                              MD5:8114962499a4fb37d15a636e3676d572
                                                              SHA1:edf095bad33e88bd9d21a1690a601232317ce351
                                                              SHA256:afe1cc80e06d92bbe16070b220541a5edad0a767c9cf8aa566dc914a6ab66d60
                                                              SHA512:d26126c76be19a3459fb1d50e4b4de18d9fe32ff2b2f82e85a0d314608bbe335a2d720a16ccf56e2c8c91e79d5dbf0d1f31367c9d3e724253f4a99b30ae87ec3
                                                              SSDEEP:768:i0EYhmzU2uGP/C4iMsWJ+LT7KmnO4djH/mNwM:nhmz9uGC4iZKDk/mp
                                                              TLSH:07D2725A6F228BECF75DC1380BB30A258269329522E5D5C4E27CE5051F3464FA84FFE8
                                                              File Content Preview:.ELF.....................@.....4..vx.....4. ...(.............@...@....n...n...............p..@p..@p.......3...............pD.@pD.@pD................dt.Q............................<...'......!'.......................<...'......!........'9... .............

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, big endian
                                                              Version:1 (current)
                                                              Machine:MIPS R3000
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:UNIX - System V
                                                              ABI Version:0
                                                              Entry Point Address:0x400290
                                                              Flags:0x1007
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:4
                                                              Section Header Offset:30328
                                                              Section Header Size:40
                                                              Number of Section Headers:17
                                                              Header String Table Index:16
                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                              NULL0x00x00x00x00x0000
                                                              .initPROGBITS0x4000b40xb40x8c0x00x6AX004
                                                              .textPROGBITS0x4001400x1400x69600x00x6AX0016
                                                              .finiPROGBITS0x406aa00x6aa00x5c0x00x6AX004
                                                              .rodataPROGBITS0x406b000x6b000x3f00x00x2A0016
                                                              .eh_framePROGBITS0x4070000x70000x440x00x3WA004
                                                              .tbssNOBITS0x4070440x70440x80x00x403WAT004
                                                              .ctorsPROGBITS0x4070440x70440x80x00x3WA004
                                                              .dtorsPROGBITS0x40704c0x704c0x80x00x3WA004
                                                              .jcrPROGBITS0x4070540x70540x40x00x3WA004
                                                              .data.rel.roPROGBITS0x4070580x70580x40x00x3WA004
                                                              .dataPROGBITS0x4070600x70600x1480x00x3WA0016
                                                              .gotPROGBITS0x4071b00x71b00x44c0x40x10000003WAp0016
                                                              .sbssNOBITS0x4075fc0x75fc0x280x00x10000003WAp004
                                                              .bssNOBITS0x4076300x75fc0x2dcc0x00x3WA0016
                                                              .mdebug.abi32PROGBITS0x7bc0x75fc0x00x00x0001
                                                              .shstrtabSTRTAB0x00x75fc0x790x00x0001
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x4000000x4000000x6ef00x6ef05.37250x5R E0x1000.init .text .fini .rodata
                                                              LOAD0x70000x4070000x4070000x5fc0x33fc2.71810x6RW 0x1000.eh_frame .tbss .ctors .dtors .jcr .data.rel.ro .data .got .sbss .bss
                                                              TLS0x70440x4070440x4070440x00x80.00000x4R 0x4.tbss
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Jan 3, 2025 07:52:52.519531965 CET5074231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:52.524486065 CET313375074285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:52:52.524557114 CET5074231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:52.524909019 CET5074231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:52.529690027 CET313375074285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:52:53.236615896 CET313375074285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:52:53.237188101 CET5074231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:53.237246037 CET5074231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:53.242005110 CET313375074285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:52:55.105034113 CET43928443192.168.2.2391.189.91.42
                                                              Jan 3, 2025 07:52:59.238343954 CET5074431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:59.243212938 CET313375074485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:52:59.243295908 CET5074431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:59.243319035 CET5074431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:59.248037100 CET313375074485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:52:59.959348917 CET313375074485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:52:59.959609985 CET5074431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:52:59.964406013 CET313375074485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:00.480077028 CET42836443192.168.2.2391.189.91.43
                                                              Jan 3, 2025 07:53:02.271920919 CET4251680192.168.2.23109.202.202.202
                                                              Jan 3, 2025 07:53:06.960490942 CET5074631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:06.965415001 CET313375074685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:06.965511084 CET5074631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:06.965533972 CET5074631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:06.970309973 CET313375074685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:07.657396078 CET313375074685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:07.657840967 CET5074631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:07.662643909 CET313375074685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:12.659307003 CET5074831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:12.664176941 CET313375074885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:12.664273024 CET5074831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:12.664316893 CET5074831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:12.669044971 CET313375074885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:13.363527060 CET313375074885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:13.363806009 CET5074831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:13.368581057 CET313375074885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:15.581989050 CET43928443192.168.2.2391.189.91.42
                                                              Jan 3, 2025 07:53:19.364360094 CET5075031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:19.369105101 CET313375075085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:19.369179964 CET5075031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:19.369196892 CET5075031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:19.373948097 CET313375075085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:20.096026897 CET313375075085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:20.096230030 CET5075031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:20.100959063 CET313375075085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:27.097207069 CET5075231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:27.273047924 CET313375075285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:27.273108006 CET5075231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:27.273124933 CET5075231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:27.277870893 CET313375075285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:27.868266106 CET42836443192.168.2.2391.189.91.43
                                                              Jan 3, 2025 07:53:27.980261087 CET313375075285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:27.980345964 CET5075231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:27.985148907 CET313375075285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:31.963613987 CET4251680192.168.2.23109.202.202.202
                                                              Jan 3, 2025 07:53:36.981278896 CET5075431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:36.986159086 CET313375075485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:36.986217022 CET5075431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:36.986246109 CET5075431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:36.991065025 CET313375075485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:37.678783894 CET313375075485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:37.679122925 CET5075431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:37.683984041 CET313375075485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:43.681031942 CET5075631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:43.686012983 CET313375075685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:43.686069965 CET5075631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:43.686110973 CET5075631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:43.690857887 CET313375075685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:44.428877115 CET313375075685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:44.429131985 CET5075631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:44.433990002 CET313375075685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:52.430845976 CET5075831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:52.435786009 CET313375075885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:52.435870886 CET5075831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:52.435939074 CET5075831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:52.440648079 CET313375075885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:53.147733927 CET313375075885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:53.147861958 CET5075831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:53:53.152802944 CET313375075885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:53:56.536262989 CET43928443192.168.2.2391.189.91.42
                                                              Jan 3, 2025 07:54:01.148855925 CET5076031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:01.153750896 CET313375076085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:01.153803110 CET5076031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:01.153829098 CET5076031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:01.158576012 CET313375076085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:01.873569012 CET313375076085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:01.873687983 CET5076031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:01.878473997 CET313375076085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:06.875524998 CET5076231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:06.880348921 CET313375076285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:06.880393028 CET5076231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:06.880419970 CET5076231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:06.885149002 CET313375076285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:07.592096090 CET313375076285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:07.592206955 CET5076231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:07.596977949 CET313375076285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:13.593527079 CET5076431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:13.598592997 CET313375076485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:13.598649979 CET5076431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:13.598676920 CET5076431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:13.603493929 CET313375076485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:14.327884912 CET313375076485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:14.328068972 CET5076431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:14.332910061 CET313375076485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:19.329523087 CET5076631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:19.334474087 CET313375076685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:19.334522009 CET5076631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:19.334543943 CET5076631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:19.339284897 CET313375076685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:20.035917997 CET313375076685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:20.036055088 CET5076631337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:20.041176081 CET313375076685.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:28.037693977 CET5076831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:28.042552948 CET313375076885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:28.042650938 CET5076831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:28.042731047 CET5076831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:28.047456026 CET313375076885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:28.752939939 CET313375076885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:28.753209114 CET5076831337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:28.758018017 CET313375076885.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:34.754878044 CET5077031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:34.759782076 CET313375077085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:34.759836912 CET5077031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:34.759855986 CET5077031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:34.765788078 CET313375077085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:35.554883003 CET313375077085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:35.555013895 CET5077031337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:35.559865952 CET313375077085.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:43.555771112 CET5077231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:43.561104059 CET313375077285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:43.561187029 CET5077231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:43.561264038 CET5077231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:43.565972090 CET313375077285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:44.280205965 CET313375077285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:44.280311108 CET5077231337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:44.285109043 CET313375077285.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:52.281454086 CET5077431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:52.286412001 CET313375077485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:52.286474943 CET5077431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:52.286514044 CET5077431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:52.291297913 CET313375077485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:52.981475115 CET313375077485.239.34.134192.168.2.23
                                                              Jan 3, 2025 07:54:52.981671095 CET5077431337192.168.2.2385.239.34.134
                                                              Jan 3, 2025 07:54:52.986512899 CET313375077485.239.34.134192.168.2.23

                                                              System Behavior

                                                              Start time (UTC):06:52:51
                                                              Start date (UTC):03/01/2025
                                                              Path:/tmp/mips.elf
                                                              Arguments:/tmp/mips.elf
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c

                                                              Start time (UTC):06:52:51
                                                              Start date (UTC):03/01/2025
                                                              Path:/tmp/mips.elf
                                                              Arguments:-
                                                              File size:5777432 bytes
                                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c