Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
uYtea.mpsl.elf

Overview

General Information

Sample name:uYtea.mpsl.elf
Analysis ID:1586054
MD5:a2d136b494b26c43bf3df8af3e9c899d
SHA1:c85948b663595680d8f8a27560303d131e22466e
SHA256:c65de05ba9a20d85c9e9f2d4d22e1c7d7df058f6efa49c97375f65639ab3d65d
Tags:user-elfdigest
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586054
Start date and time:2025-01-08 17:05:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:uYtea.mpsl.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
  • VT rate limit hit for: uYtea.mpsl.elf
Command:/tmp/uYtea.mpsl.elf
PID:6230
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
connecterror
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
uYtea.mpsl.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x10030:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10044:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1006c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1010c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1015c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x101ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x101c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
6230.1.00007fef44400000.00007fef44413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x10030:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10044:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1006c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1010c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1015c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x101ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x101c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6234.1.00007fef44400000.00007fef44413000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x10030:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10044:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10058:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1006c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10080:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10094:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x100f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1010c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10120:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10134:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10148:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1015c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10170:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10184:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10198:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x101ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x101c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.mpsl.elf PID: 6230Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x589:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x59d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5b1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5c5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5d9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x5ed:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x601:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x615:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x629:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x63d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x651:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x665:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x679:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x68d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6a1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6b5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6c9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6dd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6f1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x705:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x719:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.mpsl.elf PID: 6234Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x6269:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x627d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6291:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x62a5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x62b9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x62cd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x62e1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x62f5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6309:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x631d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6331:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6345:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6359:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x636d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6381:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x6395:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x63a9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x63bd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x63d1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x63e5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x63f9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: uYtea.mpsl.elfAvira: detected
Source: uYtea.mpsl.elfReversingLabs: Detection: 63%
Source: global trafficTCP traffic: 192.168.2.23:51398 -> 141.98.10.115:1302
Source: /tmp/uYtea.mpsl.elf (PID: 6230)Socket: 127.0.0.1:9473Jump to behavior
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: uYtea.mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6230.1.00007fef44400000.00007fef44413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6234.1.00007fef44400000.00007fef44413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.mpsl.elf PID: 6230, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.mpsl.elf PID: 6234, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: uYtea.mpsl.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6230.1.00007fef44400000.00007fef44413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6234.1.00007fef44400000.00007fef44413000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.mpsl.elf PID: 6230, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.mpsl.elf PID: 6234, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
Source: /tmp/uYtea.mpsl.elf (PID: 6232)Directory: /tmp/.Jump to behavior
Source: /tmp/uYtea.mpsl.elf (PID: 6232)Directory: /tmp/..Jump to behavior
Source: /tmp/uYtea.mpsl.elf (PID: 6230)Queries kernel information via 'uname': Jump to behavior
Source: uYtea.mpsl.elf, 6230.1.000055e920912000.000055e920999000.rw-.sdmp, uYtea.mpsl.elf, 6234.1.000055e920912000.000055e920999000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: uYtea.mpsl.elf, 6230.1.00007ffe88d13000.00007ffe88d34000.rw-.sdmp, uYtea.mpsl.elf, 6234.1.00007ffe88d13000.00007ffe88d34000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/uYtea.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/uYtea.mpsl.elf
Source: uYtea.mpsl.elf, 6230.1.000055e920912000.000055e920999000.rw-.sdmp, uYtea.mpsl.elf, 6234.1.000055e920912000.000055e920999000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/mipsel
Source: uYtea.mpsl.elf, 6230.1.00007ffe88d13000.00007ffe88d34000.rw-.sdmp, uYtea.mpsl.elf, 6234.1.00007ffe88d13000.00007ffe88d34000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
uYtea.mpsl.elf63%ReversingLabsLinux.Trojan.Mirai
uYtea.mpsl.elf100%AviraEXP/ELF.Mirai.Z.D
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
141.98.10.115
unknownLithuania
209605HOSTBALTICLTfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
141.98.10.115uYtea.arm7.elfGet hashmaliciousMiraiBrowse
    109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
    • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
    91.189.91.43uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
      main_x86_64.elfGet hashmaliciousMiraiBrowse
        Aqua.arm5.elfGet hashmaliciousUnknownBrowse
          main_m68k.elfGet hashmaliciousMiraiBrowse
            main_arm5.elfGet hashmaliciousMiraiBrowse
              mips64.elfGet hashmaliciousUnknownBrowse
                mips64el.elfGet hashmaliciousUnknownBrowse
                  main_arm.elfGet hashmaliciousMiraiBrowse
                    mips.elfGet hashmaliciousMiraiBrowse
                      main_sh4.elfGet hashmaliciousMiraiBrowse
                        91.189.91.42uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                          main_x86_64.elfGet hashmaliciousMiraiBrowse
                            Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                main_arm5.elfGet hashmaliciousMiraiBrowse
                                  mips64.elfGet hashmaliciousUnknownBrowse
                                    mips64el.elfGet hashmaliciousUnknownBrowse
                                      main_arm.elfGet hashmaliciousMiraiBrowse
                                        mips.elfGet hashmaliciousMiraiBrowse
                                          main_sh4.elfGet hashmaliciousMiraiBrowse
                                            No context
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CANONICAL-ASGBuYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_x86_64.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_m68k.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            mips64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            386.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            mips64el.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            CANONICAL-ASGBuYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_x86_64.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_m68k.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            mips64.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            386.elfGet hashmaliciousUnknownBrowse
                                            • 185.125.190.26
                                            mips64el.elfGet hashmaliciousUnknownBrowse
                                            • 91.189.91.42
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 185.125.190.26
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                            • 91.189.91.42
                                            HOSTBALTICLTuYtea.arm7.elfGet hashmaliciousMiraiBrowse
                                            • 141.98.10.115
                                            Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                            • 141.98.10.88
                                            Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                            • 141.98.10.88
                                            Scan112024.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                            • 141.98.10.88
                                            173127133603e75602cf90c03b229cc07ec4f5c026cad2909c809b767b293bf800a0e9ade9674.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                            • 141.98.10.88
                                            ConfirmaciXnXdeXfacturaXPedidoXadicional.docGet hashmaliciousUnknownBrowse
                                            • 141.98.10.88
                                            DOC11042024.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                            • 141.98.10.40
                                            Contract #U2116 KB #U2013 08152024 - 1.pif.exeGet hashmaliciousRedLineBrowse
                                            • 141.98.10.33
                                            PRODUCT OVERVIEW.docGet hashmaliciousUnknownBrowse
                                            • 141.98.10.11
                                            tppc.elfGet hashmaliciousUnknownBrowse
                                            • 141.98.10.95
                                            INIT7CHuYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            main_x86_64.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            main_m68k.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            main_arm5.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            mips64.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            mips64el.elfGet hashmaliciousUnknownBrowse
                                            • 109.202.202.202
                                            main_arm.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            mips.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            main_sh4.elfGet hashmaliciousMiraiBrowse
                                            • 109.202.202.202
                                            No context
                                            No context
                                            No created / dropped files found
                                            File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                            Entropy (8bit):5.639881046271277
                                            TrID:
                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                            File name:uYtea.mpsl.elf
                                            File size:77'320 bytes
                                            MD5:a2d136b494b26c43bf3df8af3e9c899d
                                            SHA1:c85948b663595680d8f8a27560303d131e22466e
                                            SHA256:c65de05ba9a20d85c9e9f2d4d22e1c7d7df058f6efa49c97375f65639ab3d65d
                                            SHA512:71e2eced88e612995cfac25d3b4c0302eee94e256a71ef1661fa57186cf4c4f9cc2a395af7a5a00493e7e1829acd1dcfd093a5e801ce09c70c13d6f3340b02d3
                                            SSDEEP:1536:7J5dbFB4x92nKoINa98M26ofWU+UZ9CYXzdJa10N:7J5dxBu9uKooIUXd4u
                                            TLSH:3973F819BF610F77EC6BCC370AA92B0129CC954B22E57B367934C528B60B61B19E3C74
                                            File Content Preview:.ELF....................`.@.4....+......4. ...(...............@...@. .. ..............$ ..$ E.$ E.P....N..........Q.td...............................<...'!......'.......................<...'!... .........9'.. ........................<...'!...........`.9

                                            ELF header

                                            Class:ELF32
                                            Data:2's complement, little endian
                                            Version:1 (current)
                                            Machine:MIPS R3000
                                            Version Number:0x1
                                            Type:EXEC (Executable file)
                                            OS/ABI:UNIX - System V
                                            ABI Version:0
                                            Entry Point Address:0x400260
                                            Flags:0x1007
                                            ELF Header Size:52
                                            Program Header Offset:52
                                            Program Header Size:32
                                            Number of Program Headers:3
                                            Section Header Offset:76760
                                            Section Header Size:40
                                            Number of Section Headers:14
                                            Header String Table Index:13
                                            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                            NULL0x00x00x00x00x0000
                                            .initPROGBITS0x4000940x940x8c0x00x6AX004
                                            .textPROGBITS0x4001200x1200xfeb00x00x6AX0016
                                            .finiPROGBITS0x40ffd00xffd00x5c0x00x6AX004
                                            .rodataPROGBITS0x4100300x100300x1ff00x00x2A0016
                                            .ctorsPROGBITS0x4520240x120240x80x00x3WA004
                                            .dtorsPROGBITS0x45202c0x1202c0x80x00x3WA004
                                            .data.rel.roPROGBITS0x4520380x120380x40x00x3WA004
                                            .dataPROGBITS0x4520400x120400x7700x00x3WA0016
                                            .gotPROGBITS0x4527b00x127b00x3c40x40x10000003WAp0016
                                            .sbssNOBITS0x452b740x12b740x280x00x10000003WAp004
                                            .bssNOBITS0x452ba00x12b740x43140x00x3WA0016
                                            .mdebug.abi32PROGBITS0x6e40x12b740x00x00x0001
                                            .shstrtabSTRTAB0x00x12b740x640x00x0001
                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                            LOAD0x00x4000000x4000000x120200x120205.64980x5R E0x10000.init .text .fini .rodata
                                            LOAD0x120240x4520240x4520240xb500x4e904.49840x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
                                            GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                            TimestampSource PortDest PortSource IPDest IP
                                            Jan 8, 2025 17:05:53.947760105 CET43928443192.168.2.2391.189.91.42
                                            Jan 8, 2025 17:05:59.322977066 CET42836443192.168.2.2391.189.91.43
                                            Jan 8, 2025 17:06:00.413846016 CET513981302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:00.418818951 CET130251398141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:00.419009924 CET513981302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:00.420021057 CET513981302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:00.424853086 CET130251398141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:00.424894094 CET513981302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:00.429732084 CET130251398141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:00.858913898 CET4251680192.168.2.23109.202.202.202
                                            Jan 8, 2025 17:06:02.123779058 CET130251398141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:02.124223948 CET513981302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:02.129030943 CET130251398141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:03.125829935 CET514001302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:03.130817890 CET130251400141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:03.130877972 CET514001302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:03.131736994 CET514001302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:03.136570930 CET130251400141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:03.136653900 CET514001302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:03.141408920 CET130251400141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:04.820919991 CET130251400141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:04.821295023 CET514001302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:04.826191902 CET130251400141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:05.822689056 CET514021302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:05.827588081 CET130251402141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:05.827646971 CET514021302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:05.828366995 CET514021302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:05.833142042 CET130251402141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:05.833187103 CET514021302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:05.838027954 CET130251402141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:07.507952929 CET130251402141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:07.508148909 CET514021302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:07.514254093 CET130251402141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:08.509701967 CET514041302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:08.514501095 CET130251404141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:08.514552116 CET514041302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:08.515122890 CET514041302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:08.519850969 CET130251404141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:08.519893885 CET514041302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:08.524653912 CET130251404141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:10.231741905 CET130251404141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:10.231939077 CET514041302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:10.236686945 CET130251404141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:11.233253002 CET514061302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:11.238126040 CET130251406141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:11.238182068 CET514061302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:11.238804102 CET514061302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:11.243552923 CET130251406141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:11.243593931 CET514061302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:11.248323917 CET130251406141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:12.931364059 CET130251406141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:12.931529999 CET514061302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:12.936345100 CET130251406141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:13.932817936 CET514081302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:13.937700033 CET130251408141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:13.937849998 CET514081302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:13.938416004 CET514081302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:13.943201065 CET130251408141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:13.943264008 CET514081302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:13.948005915 CET130251408141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:15.192821980 CET43928443192.168.2.2391.189.91.42
                                            Jan 8, 2025 17:06:15.649112940 CET130251408141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:15.649410963 CET514081302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:15.654191017 CET130251408141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:16.651283979 CET514101302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:16.656124115 CET130251410141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:16.656219959 CET514101302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:16.657275915 CET514101302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:16.662005901 CET130251410141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:16.662050962 CET514101302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:16.666791916 CET130251410141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:18.374485016 CET130251410141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:18.374993086 CET514101302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:18.379793882 CET130251410141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:19.377182961 CET514121302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:19.382098913 CET130251412141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:19.382185936 CET514121302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:19.383295059 CET514121302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:19.388039112 CET130251412141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:19.388097048 CET514121302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:19.392836094 CET130251412141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:21.108127117 CET130251412141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:21.108330011 CET514121302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:21.113112926 CET130251412141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:22.109709024 CET514141302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:22.114546061 CET130251414141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:22.114604950 CET514141302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:22.115232944 CET514141302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:22.119968891 CET130251414141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:22.120059967 CET514141302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:22.124815941 CET130251414141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:23.840908051 CET130251414141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:23.841164112 CET514141302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:23.846029043 CET130251414141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:24.843383074 CET514161302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:24.848237991 CET130251416141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:24.848313093 CET514161302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:24.849576950 CET514161302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:24.854423046 CET130251416141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:24.854523897 CET514161302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:24.859265089 CET130251416141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:25.431375980 CET42836443192.168.2.2391.189.91.43
                                            Jan 8, 2025 17:06:26.576690912 CET130251416141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:26.576931953 CET514161302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:26.581727028 CET130251416141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:27.578191042 CET514181302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:27.583056927 CET130251418141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:27.583111048 CET514181302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:27.583765030 CET514181302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:27.588675022 CET130251418141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:27.588715076 CET514181302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:27.593470097 CET130251418141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:29.279150009 CET130251418141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:29.279401064 CET514181302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:29.284163952 CET130251418141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:30.281296968 CET514201302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:30.286109924 CET130251420141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:30.286183119 CET514201302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:30.287233114 CET514201302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:30.291965008 CET130251420141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:30.292022943 CET514201302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:30.296847105 CET130251420141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:31.574681997 CET4251680192.168.2.23109.202.202.202
                                            Jan 8, 2025 17:06:32.003225088 CET130251420141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:32.003417015 CET514201302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:32.008171082 CET130251420141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:33.004616976 CET514221302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:33.009449959 CET130251422141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:33.009514093 CET514221302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:33.010087967 CET514221302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:33.014908075 CET130251422141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:33.014962912 CET514221302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:33.019747972 CET130251422141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:34.712831974 CET130251422141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:34.713144064 CET514221302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:34.717994928 CET130251422141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:35.714682102 CET514241302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:35.719590902 CET130251424141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:35.719646931 CET514241302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:35.720242023 CET514241302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:35.725063086 CET130251424141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:35.725115061 CET514241302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:35.730612040 CET130251424141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:37.401983976 CET130251424141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:37.402173042 CET514241302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:37.406964064 CET130251424141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:38.403551102 CET514261302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:38.408463001 CET130251426141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:38.408530951 CET514261302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:38.409251928 CET514261302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:38.414800882 CET130251426141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:38.414845943 CET514261302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:38.420680046 CET130251426141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:40.131407976 CET130251426141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:40.131618977 CET514261302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:40.136791945 CET130251426141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:41.133099079 CET514281302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:41.138691902 CET130251428141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:41.138750076 CET514281302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:41.139342070 CET514281302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:41.144354105 CET130251428141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:41.144402981 CET514281302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:41.150728941 CET130251428141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:42.840859890 CET130251428141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:42.841022968 CET514281302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:42.845849991 CET130251428141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:43.842915058 CET514301302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:43.848607063 CET130251430141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:43.848705053 CET514301302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:43.849695921 CET514301302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:43.855679035 CET130251430141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:43.855743885 CET514301302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:43.861808062 CET130251430141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:45.545274973 CET130251430141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:45.545455933 CET514301302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:45.550177097 CET130251430141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:46.546684027 CET514321302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:46.552431107 CET130251432141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:46.552481890 CET514321302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:46.553119898 CET514321302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:46.557887077 CET130251432141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:46.557935953 CET514321302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:46.562686920 CET130251432141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:48.245379925 CET130251432141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:48.245613098 CET514321302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:48.250402927 CET130251432141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:49.247451067 CET514341302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:49.252217054 CET130251434141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:49.252295971 CET514341302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:49.253407001 CET514341302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:49.258152008 CET130251434141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:49.258219004 CET514341302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:49.263020039 CET130251434141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:51.015357971 CET130251434141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:51.015539885 CET514341302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:51.020370007 CET130251434141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:52.017338991 CET514361302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:52.022217989 CET130251436141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:52.022286892 CET514361302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:52.023303986 CET514361302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:52.028069973 CET130251436141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:52.028130054 CET514361302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:52.032969952 CET130251436141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:53.761281967 CET130251436141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:53.761447906 CET514361302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:53.766268969 CET130251436141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:54.763331890 CET514381302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:54.768141985 CET130251438141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:54.768225908 CET514381302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:54.769242048 CET514381302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:54.775872946 CET130251438141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:54.775937080 CET514381302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:54.780754089 CET130251438141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:56.147136927 CET43928443192.168.2.2391.189.91.42
                                            Jan 8, 2025 17:06:56.483469009 CET130251438141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:56.483683109 CET514381302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:56.488496065 CET130251438141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:57.485420942 CET514401302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:57.490309000 CET130251440141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:57.490358114 CET514401302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:57.491091013 CET514401302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:57.495913982 CET130251440141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:57.495963097 CET514401302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:57.500808001 CET130251440141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:59.392580986 CET130251440141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:06:59.392828941 CET514401302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:06:59.401737928 CET130251440141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:00.395010948 CET514421302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:00.399878979 CET130251442141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:00.399971962 CET514421302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:00.400923014 CET514421302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:00.405644894 CET130251442141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:00.405709028 CET514421302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:00.411398888 CET130251442141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:02.092603922 CET130251442141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:02.092767000 CET514421302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:02.097563982 CET130251442141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:03.094069004 CET514441302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:03.098937035 CET130251444141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:03.098993063 CET514441302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:03.099911928 CET514441302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:03.104660034 CET130251444141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:03.104718924 CET514441302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:03.109582901 CET130251444141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:04.793174028 CET130251444141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:04.793416023 CET514441302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:04.798254013 CET130251444141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:05.794902086 CET514461302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:05.799844027 CET130251446141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:05.799920082 CET514461302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:05.800925016 CET514461302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:05.805794001 CET130251446141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:05.805847883 CET514461302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:05.810585976 CET130251446141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:07.512733936 CET130251446141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:07.513020039 CET514461302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:07.517808914 CET130251446141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:08.514884949 CET514481302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:08.519819975 CET130251448141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:08.519929886 CET514481302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:08.521215916 CET514481302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:08.525964975 CET130251448141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:08.526025057 CET514481302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:08.530755997 CET130251448141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:10.230969906 CET130251448141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:10.231323004 CET514481302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:10.236119986 CET130251448141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:11.233011961 CET514501302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:11.237816095 CET130251450141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:11.238022089 CET514501302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:11.238545895 CET514501302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:11.243305922 CET130251450141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:11.243357897 CET514501302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:11.248171091 CET130251450141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:12.936039925 CET130251450141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:12.936491013 CET514501302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:12.941237926 CET130251450141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:13.938951015 CET514521302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:13.944011927 CET130251452141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:13.944281101 CET514521302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:13.946475983 CET514521302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:13.951371908 CET130251452141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:13.951453924 CET514521302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:13.956315041 CET130251452141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:15.636712074 CET130251452141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:15.637058020 CET514521302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:15.641948938 CET130251452141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:16.624294043 CET42836443192.168.2.2391.189.91.43
                                            Jan 8, 2025 17:07:16.638343096 CET514541302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:16.643198967 CET130251454141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:16.643331051 CET514541302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:16.643891096 CET514541302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:16.648638010 CET130251454141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:16.648734093 CET514541302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:16.653460026 CET130251454141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:18.356769085 CET130251454141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:18.356981039 CET514541302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:18.361773968 CET130251454141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:19.358494043 CET514561302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:19.363351107 CET130251456141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:19.363410950 CET514561302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:19.364097118 CET514561302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:19.368918896 CET130251456141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:19.368982077 CET514561302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:19.373785973 CET130251456141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:21.062289953 CET130251456141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:21.062468052 CET514561302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:21.067348003 CET130251456141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:22.063783884 CET514581302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:22.068723917 CET130251458141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:22.068825960 CET514581302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:22.069531918 CET514581302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:22.074316978 CET130251458141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:22.074388981 CET514581302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:22.079272985 CET130251458141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:23.776272058 CET130251458141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:23.776453972 CET514581302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:23.781286955 CET130251458141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:24.777815104 CET514601302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:24.782660961 CET130251460141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:24.782715082 CET514601302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:24.783334017 CET514601302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:24.788105011 CET130251460141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:24.788153887 CET514601302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:24.792916059 CET130251460141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:26.486191034 CET130251460141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:26.486371994 CET514601302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:26.491206884 CET130251460141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:27.487840891 CET514621302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:27.492712021 CET130251462141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:27.492765903 CET514621302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:27.493422985 CET514621302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:27.498158932 CET130251462141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:27.498203993 CET514621302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:27.502950907 CET130251462141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:29.311857939 CET130251462141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:29.312016964 CET514621302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:29.316766024 CET130251462141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:30.313556910 CET514641302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:30.318331957 CET130251464141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:30.318389893 CET514641302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:30.318998098 CET514641302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:30.323710918 CET130251464141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:30.323754072 CET514641302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:30.328474045 CET130251464141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:32.042707920 CET130251464141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:32.042861938 CET514641302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:32.047696114 CET130251464141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:33.044171095 CET514661302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:33.048953056 CET130251466141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:33.049012899 CET514661302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:33.049640894 CET514661302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:33.054372072 CET130251466141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:33.054419994 CET514661302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:33.059206009 CET130251466141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:34.765489101 CET130251466141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:34.765661001 CET514661302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:34.770498037 CET130251466141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:35.766972065 CET514681302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:35.771747112 CET130251468141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:35.771794081 CET514681302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:35.772384882 CET514681302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:35.777111053 CET130251468141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:35.777180910 CET514681302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:35.781975985 CET130251468141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:37.483510017 CET130251468141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:37.483882904 CET514681302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:37.488749027 CET130251468141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:38.485975027 CET514701302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:38.490811110 CET130251470141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:38.491111994 CET514701302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:38.491761923 CET514701302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:38.496539116 CET130251470141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:38.496615887 CET514701302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:38.501426935 CET130251470141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:40.199506998 CET130251470141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:40.199918032 CET514701302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:40.204758883 CET130251470141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:41.202014923 CET514721302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:41.206975937 CET130251472141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:41.207132101 CET514721302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:41.208178997 CET514721302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:41.212929010 CET130251472141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:41.212994099 CET514721302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:41.217806101 CET130251472141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:42.904490948 CET130251472141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:42.904685020 CET514721302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:42.909511089 CET130251472141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:43.906447887 CET514741302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:43.911365986 CET130251474141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:43.911612034 CET514741302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:43.912600994 CET514741302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:43.917330027 CET130251474141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:43.917393923 CET514741302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:43.922156096 CET130251474141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:45.641849995 CET130251474141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:45.642456055 CET514741302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:45.647270918 CET130251474141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:46.644503117 CET514761302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:46.649297953 CET130251476141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:46.649434090 CET514761302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:46.650466919 CET514761302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:46.655237913 CET130251476141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:46.655304909 CET514761302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:46.660187960 CET130251476141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:48.356558084 CET130251476141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:48.357095003 CET514761302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:48.361887932 CET130251476141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:49.358918905 CET514781302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:49.363698959 CET130251478141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:49.363830090 CET514781302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:49.364792109 CET514781302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:49.369532108 CET130251478141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:49.369596958 CET514781302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:49.374325991 CET130251478141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:51.059102058 CET130251478141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:51.059645891 CET514781302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:51.064380884 CET130251478141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:52.061592102 CET514801302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:52.066595078 CET130251480141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:52.066735029 CET514801302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:52.067318916 CET514801302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:52.072163105 CET130251480141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:52.072213888 CET514801302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:52.077033043 CET130251480141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:53.765189886 CET130251480141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:53.765506983 CET514801302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:53.770313025 CET130251480141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:54.767036915 CET514821302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:54.771908045 CET130251482141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:54.771980047 CET514821302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:54.772746086 CET514821302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:54.777564049 CET130251482141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:54.777631998 CET514821302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:54.782407999 CET130251482141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:56.463875055 CET130251482141.98.10.115192.168.2.23
                                            Jan 8, 2025 17:07:56.464092016 CET514821302192.168.2.23141.98.10.115
                                            Jan 8, 2025 17:07:56.468952894 CET130251482141.98.10.115192.168.2.23

                                            System Behavior

                                            Start time (UTC):16:05:52
                                            Start date (UTC):08/01/2025
                                            Path:/tmp/uYtea.mpsl.elf
                                            Arguments:/tmp/uYtea.mpsl.elf
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                            Start time (UTC):16:05:52
                                            Start date (UTC):08/01/2025
                                            Path:/tmp/uYtea.mpsl.elf
                                            Arguments:-
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9

                                            Start time (UTC):16:05:52
                                            Start date (UTC):08/01/2025
                                            Path:/tmp/uYtea.mpsl.elf
                                            Arguments:-
                                            File size:5773336 bytes
                                            MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9