Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
uYtea.mips.elf

Overview

General Information

Sample name:uYtea.mips.elf
Analysis ID:1586055
MD5:f1b1fd4e7d87ee3295b6910bda417e84
SHA1:8ae0a41216cd7ee4e200f50324ddeda7cf8cbd33
SHA256:d045b60fb22bef2a0a2073d5a36d38c1e72ef5e9e9c93f6a1555ac83d53d5feb
Tags:user-elfdigest
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586055
Start date and time:2025-01-08 17:05:12 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 33s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:uYtea.mips.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
  • VT rate limit hit for: uYtea.mips.elf
Command:/tmp/uYtea.mips.elf
PID:5492
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
connecterror
Standard Error:
  • system is lnxubuntu20
  • cleanup
SourceRuleDescriptionAuthorStrings
uYtea.mips.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xf6c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf724:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf738:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf74c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf760:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf774:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf788:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf79c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf800:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf814:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf828:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf83c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf850:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5492.1.00007f4304400000.00007f4304412000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xf6c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf724:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf738:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf74c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf760:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf774:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf788:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf79c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf800:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf814:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf828:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf83c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf850:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5496.1.00007f4304400000.00007f4304412000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xf6c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf6fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf724:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf738:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf74c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf760:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf774:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf788:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf79c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf7ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf800:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf814:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf828:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf83c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf850:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.mips.elf PID: 5492Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x116:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x12a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x13e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x152:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x166:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1a2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1b6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1ca:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1de:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1f2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x206:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x21a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x22e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x242:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x256:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x26a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x27e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x292:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x2a6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.mips.elf PID: 5496Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x787a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x788e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78a2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78b6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78ca:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78de:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x78f2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7906:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x791a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x792e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7942:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7956:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x796a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x797e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7992:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x79a6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x79ba:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x79ce:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x79e2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x79f6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x7a0a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: uYtea.mips.elfAvira: detected
Source: uYtea.mips.elfReversingLabs: Detection: 65%
Source: global trafficTCP traffic: 192.168.2.14:40160 -> 141.98.10.115:1302
Source: /tmp/uYtea.mips.elf (PID: 5492)Socket: 127.0.0.1:9473Jump to behavior

System Summary

barindex
Source: uYtea.mips.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5492.1.00007f4304400000.00007f4304412000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5496.1.00007f4304400000.00007f4304412000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.mips.elf PID: 5492, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.mips.elf PID: 5496, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: uYtea.mips.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5492.1.00007f4304400000.00007f4304412000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5496.1.00007f4304400000.00007f4304412000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.mips.elf PID: 5492, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.mips.elf PID: 5496, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
Source: /tmp/uYtea.mips.elf (PID: 5494)Directory: /tmp/.Jump to behavior
Source: /tmp/uYtea.mips.elf (PID: 5494)Directory: /tmp/..Jump to behavior
Source: /tmp/uYtea.mips.elf (PID: 5492)Queries kernel information via 'uname': Jump to behavior
Source: uYtea.mips.elf, 5492.1.000056428d58f000.000056428d616000.rw-.sdmp, uYtea.mips.elf, 5496.1.000056428d58f000.000056428d616000.rw-.sdmpBinary or memory string: BV!/etc/qemu-binfmt/mips
Source: uYtea.mips.elf, 5492.1.00007ffdde4d6000.00007ffdde4f7000.rw-.sdmp, uYtea.mips.elf, 5496.1.00007ffdde4d6000.00007ffdde4f7000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mips/tmp/uYtea.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/uYtea.mips.elf
Source: uYtea.mips.elf, 5492.1.000056428d58f000.000056428d616000.rw-.sdmp, uYtea.mips.elf, 5496.1.000056428d58f000.000056428d616000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: uYtea.mips.elf, 5492.1.00007ffdde4d6000.00007ffdde4f7000.rw-.sdmp, uYtea.mips.elf, 5496.1.00007ffdde4d6000.00007ffdde4f7000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
uYtea.mips.elf66%ReversingLabsLinux.Trojan.Mirai
uYtea.mips.elf100%AviraEXP/ELF.Mirai.Z.D
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
141.98.10.115
unknownLithuania
209605HOSTBALTICLTfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
141.98.10.115uYtea.arm7.elfGet hashmaliciousMiraiBrowse
    No context
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    HOSTBALTICLTuYtea.arm7.elfGet hashmaliciousMiraiBrowse
    • 141.98.10.115
    Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
    • 141.98.10.88
    Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
    • 141.98.10.88
    Scan112024.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
    • 141.98.10.88
    173127133603e75602cf90c03b229cc07ec4f5c026cad2909c809b767b293bf800a0e9ade9674.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
    • 141.98.10.88
    ConfirmaciXnXdeXfacturaXPedidoXadicional.docGet hashmaliciousUnknownBrowse
    • 141.98.10.88
    DOC11042024.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
    • 141.98.10.40
    Contract #U2116 KB #U2013 08152024 - 1.pif.exeGet hashmaliciousRedLineBrowse
    • 141.98.10.33
    PRODUCT OVERVIEW.docGet hashmaliciousUnknownBrowse
    • 141.98.10.11
    tppc.elfGet hashmaliciousUnknownBrowse
    • 141.98.10.95
    No context
    No context
    No created / dropped files found
    File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
    Entropy (8bit):5.493130227777573
    TrID:
    • ELF Executable and Linkable format (generic) (4004/1) 100.00%
    File name:uYtea.mips.elf
    File size:77'288 bytes
    MD5:f1b1fd4e7d87ee3295b6910bda417e84
    SHA1:8ae0a41216cd7ee4e200f50324ddeda7cf8cbd33
    SHA256:d045b60fb22bef2a0a2073d5a36d38c1e72ef5e9e9c93f6a1555ac83d53d5feb
    SHA512:894ffd2f738d386b6dea92982a6b49a4e0c1eaf19656657726fe840120075e15251bc89b9d1114d5c4e37d8076db34f17253dd46d3b7ec301ba4b4ea503e4f9f
    SSDEEP:1536:bpxe5qoct9fdlQBI6rAEnUFndlBotYG9CJa101Dv:Fx3oANdTrndvomgC4S
    TLSH:9573C70A7E229FBCFB9846354BB78F159A5833D627D1D641E2ACDA001D7024E341FFA9
    File Content Preview:.ELF.....................@.`...4..+......4. ...(.............@...@........................ ..E ..E ....T..N.........dt.Q............................<...'......!'.......................<...'......!... ....'9... ......................<...'......!........'9.

    ELF header

    Class:ELF32
    Data:2's complement, big endian
    Version:1 (current)
    Machine:MIPS R3000
    Version Number:0x1
    Type:EXEC (Executable file)
    OS/ABI:UNIX - System V
    ABI Version:0
    Entry Point Address:0x400260
    Flags:0x1007
    ELF Header Size:52
    Program Header Offset:52
    Program Header Size:32
    Number of Program Headers:3
    Section Header Offset:76728
    Section Header Size:40
    Number of Section Headers:14
    Header String Table Index:13
    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
    NULL0x00x00x00x00x0000
    .initPROGBITS0x4000940x940x8c0x00x6AX004
    .textPROGBITS0x4001200x1200xf5400x00x6AX0016
    .finiPROGBITS0x40f6600xf6600x5c0x00x6AX004
    .rodataPROGBITS0x40f6c00xf6c00x1fe00x00x2A0016
    .ctorsPROGBITS0x4520000x120000x80x00x3WA004
    .dtorsPROGBITS0x4520080x120080x80x00x3WA004
    .data.rel.roPROGBITS0x4520140x120140x40x00x3WA004
    .dataPROGBITS0x4520200x120200x7700x00x3WA0016
    .gotPROGBITS0x4527900x127900x3c40x40x10000003WAp0016
    .sbssNOBITS0x452b540x12b540x280x00x10000003WAp004
    .bssNOBITS0x452b800x12b540x43140x00x3WA0016
    .mdebug.abi32PROGBITS0x6e40x12b540x00x00x0001
    .shstrtabSTRTAB0x00x12b540x640x00x0001
    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
    LOAD0x00x4000000x4000000x116a00x116a05.62850x5R E0x10000.init .text .fini .rodata
    LOAD0x120000x4520000x4520000xb540x4e944.41420x6RW 0x10000.ctors .dtors .data.rel.ro .data .got .sbss .bss
    GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
    TimestampSource PortDest PortSource IPDest IP
    Jan 8, 2025 17:06:13.518125057 CET401601302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:13.523040056 CET130240160141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:13.523125887 CET401601302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:13.524404049 CET401601302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:13.529160023 CET130240160141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:13.529236078 CET401601302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:13.534043074 CET130240160141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:15.229046106 CET130240160141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:15.229377985 CET401601302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:15.234205961 CET130240160141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:16.231033087 CET401621302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:16.237451077 CET130240162141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:16.237509012 CET401621302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:16.238146067 CET401621302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:16.242927074 CET130240162141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:16.243009090 CET401621302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:16.248030901 CET130240162141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:17.933134079 CET130240162141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:17.933459997 CET401621302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:17.938824892 CET130240162141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:18.935247898 CET401641302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:18.940155983 CET130240164141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:18.940217972 CET401641302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:18.940895081 CET401641302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:18.945692062 CET130240164141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:18.945735931 CET401641302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:18.950579882 CET130240164141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:20.654752970 CET130240164141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:20.655067921 CET401641302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:20.655067921 CET401641302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:20.659862041 CET130240164141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:21.657784939 CET401661302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:21.662560940 CET130240166141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:21.662626028 CET401661302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:21.663310051 CET401661302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:21.668071032 CET130240166141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:21.668118954 CET401661302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:21.672864914 CET130240166141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:23.374619961 CET130240166141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:23.374815941 CET401661302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:23.379616976 CET130240166141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:24.376533031 CET401681302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:24.381392002 CET130240168141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:24.381453037 CET401681302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:24.382086992 CET401681302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:24.386919022 CET130240168141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:24.386967897 CET401681302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:24.391751051 CET130240168141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:26.090179920 CET130240168141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:26.090357065 CET401681302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:26.095868111 CET130240168141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:27.091734886 CET401701302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:27.096548080 CET130240170141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:27.096604109 CET401701302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:27.097239971 CET401701302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:27.101999998 CET130240170141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:27.102046967 CET401701302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:27.106839895 CET130240170141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:28.808191061 CET130240170141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:28.808300972 CET401701302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:28.813060999 CET130240170141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:29.809708118 CET401721302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:29.814496040 CET130240172141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:29.814558029 CET401721302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:29.815257072 CET401721302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:29.820030928 CET130240172141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:29.820087910 CET401721302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:29.824899912 CET130240172141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:31.509160042 CET130240172141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:31.509402037 CET401721302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:31.514170885 CET130240172141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:32.511049986 CET401741302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:32.515863895 CET130240174141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:32.515930891 CET401741302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:32.516581059 CET401741302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:32.521388054 CET130240174141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:32.521456003 CET401741302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:32.526279926 CET130240174141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:34.215883970 CET130240174141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:34.216152906 CET401741302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:34.222237110 CET130240174141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:35.217880964 CET401761302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:35.222693920 CET130240176141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:35.222755909 CET401761302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:35.223404884 CET401761302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:35.228171110 CET130240176141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:35.228216887 CET401761302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:35.233031988 CET130240176141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:36.982611895 CET130240176141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:36.982759953 CET401761302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:36.987632036 CET130240176141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:37.984129906 CET401781302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:37.989106894 CET130240178141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:37.989166975 CET401781302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:37.989820004 CET401781302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:37.994606972 CET130240178141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:37.994685888 CET401781302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:37.999492884 CET130240178141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:39.733697891 CET130240178141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:39.733967066 CET401781302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:39.739905119 CET130240178141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:40.735869884 CET401801302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:40.741954088 CET130240180141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:40.742027998 CET401801302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:40.743083954 CET401801302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:40.747853041 CET130240180141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:40.747919083 CET401801302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:40.752700090 CET130240180141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:42.447813034 CET130240180141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:42.448013067 CET401801302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:42.452797890 CET130240180141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:43.449516058 CET401821302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:43.454319954 CET130240182141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:43.454371929 CET401821302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:43.455014944 CET401821302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:43.459836006 CET130240182141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:43.459882975 CET401821302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:43.464634895 CET130240182141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:45.215050936 CET130240182141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:45.215265036 CET401821302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:45.221487045 CET130240182141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:46.217112064 CET401841302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:46.221869946 CET130240184141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:46.221976042 CET401841302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:46.222985983 CET401841302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:46.227730036 CET130240184141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:46.227799892 CET401841302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:46.232573032 CET130240184141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:47.899116993 CET130240184141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:47.899293900 CET401841302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:47.904078007 CET130240184141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:48.901086092 CET401861302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:48.905946970 CET130240186141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:48.906009912 CET401861302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:48.906773090 CET401861302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:48.911580086 CET130240186141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:48.911618948 CET401861302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:48.916383982 CET130240186141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:50.605686903 CET130240186141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:50.605875969 CET401861302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:50.605910063 CET401861302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:50.610680103 CET130240186141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:51.607441902 CET401881302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:51.612241030 CET130240188141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:51.612312078 CET401881302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:51.613024950 CET401881302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:51.617821932 CET130240188141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:51.617882967 CET401881302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:51.622657061 CET130240188141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:53.291176081 CET130240188141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:53.291445017 CET401881302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:53.296226978 CET130240188141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:54.293179989 CET401901302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:54.297986984 CET130240190141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:54.298075914 CET401901302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:54.298773050 CET401901302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:54.303560972 CET130240190141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:54.303612947 CET401901302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:54.308337927 CET130240190141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:56.014801979 CET130240190141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:56.015149117 CET401901302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:56.019927979 CET130240190141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:57.017501116 CET401921302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:57.022384882 CET130240192141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:57.022475958 CET401921302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:57.023680925 CET401921302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:57.028528929 CET130240192141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:57.028592110 CET401921302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:57.033401012 CET130240192141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:59.392314911 CET130240192141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:59.392443895 CET130240192141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:59.392515898 CET401921302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:59.392565012 CET130240192141.98.10.115192.168.2.14
    Jan 8, 2025 17:06:59.392601967 CET401921302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:59.392615080 CET401921302192.168.2.14141.98.10.115
    Jan 8, 2025 17:06:59.401726961 CET130240192141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:00.395021915 CET401941302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:00.399890900 CET130240194141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:00.399959087 CET401941302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:00.400809050 CET401941302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:00.405575991 CET130240194141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:00.405622005 CET401941302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:00.411389112 CET130240194141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:02.115782976 CET130240194141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:02.116142988 CET401941302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:02.121020079 CET130240194141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:03.118243933 CET401961302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:03.123039007 CET130240196141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:03.123097897 CET401961302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:03.124098063 CET401961302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:03.128854036 CET130240196141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:03.128902912 CET401961302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:03.133676052 CET130240196141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:04.824839115 CET130240196141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:04.825037003 CET401961302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:04.829835892 CET130240196141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:05.826545954 CET401981302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:05.831413031 CET130240198141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:05.831471920 CET401981302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:05.832190990 CET401981302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:05.836936951 CET130240198141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:05.836977005 CET401981302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:05.841742039 CET130240198141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:07.544405937 CET130240198141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:07.544567108 CET401981302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:07.549364090 CET130240198141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:08.546407938 CET402001302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:08.551414013 CET130240200141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:08.551490068 CET402001302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:08.552444935 CET402001302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:08.557219028 CET130240200141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:08.557272911 CET402001302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:08.562145948 CET130240200141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:10.245798111 CET130240200141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:10.246001005 CET402001302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:10.250782013 CET130240200141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:11.248330116 CET402021302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:11.253175974 CET130240202141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:11.253251076 CET402021302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:11.254489899 CET402021302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:11.259232998 CET130240202141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:11.259287119 CET402021302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:11.264018059 CET130240202141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:12.968192101 CET130240202141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:12.968417883 CET402021302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:12.973232031 CET130240202141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:13.970230103 CET402041302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:13.975028038 CET130240204141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:13.975116968 CET402041302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:13.975979090 CET402041302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:13.980804920 CET130240204141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:13.980874062 CET402041302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:13.985672951 CET130240204141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:15.670485973 CET130240204141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:15.670708895 CET402041302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:15.675484896 CET130240204141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:16.672554970 CET402061302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:16.677392006 CET130240206141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:16.677464008 CET402061302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:16.678291082 CET402061302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:16.683064938 CET130240206141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:16.683120966 CET402061302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:16.687956095 CET130240206141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:18.369076014 CET130240206141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:18.369200945 CET402061302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:18.373970032 CET130240206141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:19.371150970 CET402081302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:19.376036882 CET130240208141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:19.376106977 CET402081302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:19.376822948 CET402081302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:19.381671906 CET130240208141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:19.381746054 CET402081302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:19.386491060 CET130240208141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:21.058121920 CET130240208141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:21.058324099 CET402081302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:21.063170910 CET130240208141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:22.059987068 CET402101302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:22.064893961 CET130240210141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:22.064955950 CET402101302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:22.065711975 CET402101302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:22.070493937 CET130240210141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:22.070548058 CET402101302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:22.075309038 CET130240210141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:23.765407085 CET130240210141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:23.765608072 CET402101302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:23.770426035 CET130240210141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:24.767659903 CET402121302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:24.772682905 CET130240212141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:24.772773027 CET402121302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:24.773720980 CET402121302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:24.778537989 CET130240212141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:24.778603077 CET402121302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:24.783368111 CET130240212141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:26.468070984 CET130240212141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:26.468506098 CET402121302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:26.468605995 CET402121302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:26.473371983 CET130240212141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:27.470923901 CET402141302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:27.475895882 CET130240214141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:27.475990057 CET402141302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:27.477154016 CET402141302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:27.481914043 CET130240214141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:27.481976032 CET402141302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:27.486737013 CET130240214141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:29.296876907 CET130240214141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:29.297131062 CET402141302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:29.301995039 CET130240214141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:30.298814058 CET402161302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:30.303826094 CET130240216141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:30.303973913 CET402161302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:30.304554939 CET402161302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:30.309324026 CET130240216141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:30.309387922 CET402161302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:30.314181089 CET130240216141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:32.026351929 CET130240216141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:32.026516914 CET402161302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:32.031369925 CET130240216141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:33.027903080 CET402181302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:33.032915115 CET130240218141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:33.032965899 CET402181302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:33.033561945 CET402181302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:33.038327932 CET130240218141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:33.038372993 CET402181302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:33.043128014 CET130240218141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:34.754688025 CET130240218141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:34.754867077 CET402181302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:34.759751081 CET130240218141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:35.756299019 CET402201302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:35.761277914 CET130240220141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:35.761332989 CET402201302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:35.761868000 CET402201302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:35.766655922 CET130240220141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:35.766700983 CET402201302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:35.771459103 CET130240220141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:37.485270023 CET130240220141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:37.485524893 CET402201302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:37.490289927 CET130240220141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:38.487221003 CET402221302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:38.492014885 CET130240222141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:38.492070913 CET402221302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:38.492670059 CET402221302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:38.497596979 CET130240222141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:38.497642040 CET402221302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:38.502446890 CET130240222141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:40.200182915 CET130240222141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:40.200370073 CET402221302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:40.205176115 CET130240222141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:41.201956034 CET402241302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:41.206959009 CET130240224141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:41.207012892 CET402241302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:41.207676888 CET402241302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:41.212450027 CET130240224141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:41.212491989 CET402241302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:41.217247963 CET130240224141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:42.918972969 CET130240224141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:42.919255018 CET402241302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:42.924073935 CET130240224141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:43.920876980 CET402261302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:43.925633907 CET130240226141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:43.925707102 CET402261302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:43.926301956 CET402261302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:43.931071043 CET130240226141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:43.931118011 CET402261302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:43.935853958 CET130240226141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:45.620668888 CET130240226141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:45.620995045 CET402261302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:45.625803947 CET130240226141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:46.622956991 CET402281302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:46.627933979 CET130240228141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:46.628012896 CET402281302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:46.628545046 CET402281302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:46.633332014 CET130240228141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:46.633416891 CET402281302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:46.638254881 CET130240228141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:48.308032990 CET130240228141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:48.308175087 CET402281302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:48.313004017 CET130240228141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:49.309555054 CET402301302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:49.314546108 CET130240230141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:49.314666986 CET402301302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:49.315218925 CET402301302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:49.319977999 CET130240230141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:49.320046902 CET402301302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:49.324841022 CET130240230141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:50.996632099 CET130240230141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:50.997090101 CET402301302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:51.001895905 CET130240230141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:51.998467922 CET402321302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:52.003549099 CET130240232141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:52.003612041 CET402321302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:52.004066944 CET402321302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:52.009146929 CET130240232141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:52.009202957 CET402321302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:52.013988972 CET130240232141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:53.702358961 CET130240232141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:53.702567101 CET402321302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:53.707464933 CET130240232141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:54.704207897 CET402341302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:54.709197044 CET130240234141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:54.709312916 CET402341302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:54.709821939 CET402341302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:54.714561939 CET130240234141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:54.714622974 CET402341302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:54.719356060 CET130240234141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:56.406397104 CET130240234141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:56.406702042 CET402341302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:56.411585093 CET130240234141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:57.408410072 CET402361302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:57.413381100 CET130240236141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:57.413443089 CET402361302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:57.414060116 CET402361302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:57.418845892 CET130240236141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:57.418900013 CET402361302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:57.423691034 CET130240236141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:59.125447989 CET130240236141.98.10.115192.168.2.14
    Jan 8, 2025 17:07:59.125716925 CET402361302192.168.2.14141.98.10.115
    Jan 8, 2025 17:07:59.130604982 CET130240236141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:00.127856970 CET402381302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:00.132796049 CET130240238141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:00.132963896 CET402381302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:00.133960962 CET402381302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:00.138711929 CET130240238141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:00.138777018 CET402381302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:00.143562078 CET130240238141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:01.841826916 CET130240238141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:01.842201948 CET402381302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:01.849428892 CET130240238141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:02.844366074 CET402401302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:02.849355936 CET130240240141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:02.849488974 CET402401302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:02.850402117 CET402401302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:02.855137110 CET130240240141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:02.855201960 CET402401302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:02.859962940 CET130240240141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:04.546849966 CET130240240141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:04.547200918 CET402401302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:04.552061081 CET130240240141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:05.549273968 CET402421302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:05.554439068 CET130240242141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:05.554513931 CET402421302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:05.555455923 CET402421302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:05.560226917 CET130240242141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:05.560286999 CET402421302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:05.565067053 CET130240242141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:07.265464067 CET130240242141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:07.265697002 CET402421302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:07.270540953 CET130240242141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:08.267673016 CET402441302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:08.272511005 CET130240244141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:08.272583961 CET402441302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:08.273495913 CET402441302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:08.278235912 CET130240244141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:08.278278112 CET402441302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:08.283041000 CET130240244141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:09.963965893 CET130240244141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:09.964127064 CET402441302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:09.968888998 CET130240244141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:10.965996981 CET402461302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:10.970772982 CET130240246141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:10.970827103 CET402461302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:10.971478939 CET402461302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:10.976221085 CET130240246141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:10.976267099 CET402461302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:10.981169939 CET130240246141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:12.652930021 CET130240246141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:12.653307915 CET402461302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:12.658075094 CET130240246141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:13.654536963 CET402481302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:13.659322977 CET130240248141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:13.659437895 CET402481302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:13.659990072 CET402481302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:13.664705992 CET130240248141.98.10.115192.168.2.14
    Jan 8, 2025 17:08:13.664777040 CET402481302192.168.2.14141.98.10.115
    Jan 8, 2025 17:08:13.669553995 CET130240248141.98.10.115192.168.2.14

    System Behavior

    Start time (UTC):16:06:06
    Start date (UTC):08/01/2025
    Path:/tmp/uYtea.mips.elf
    Arguments:/tmp/uYtea.mips.elf
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):16:06:06
    Start date (UTC):08/01/2025
    Path:/tmp/uYtea.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c

    Start time (UTC):16:06:06
    Start date (UTC):08/01/2025
    Path:/tmp/uYtea.mips.elf
    Arguments:-
    File size:5777432 bytes
    MD5 hash:0083f1f0e77be34ad27f849842bbb00c