Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
uYtea.x86.elf

Overview

General Information

Sample name:uYtea.x86.elf
Analysis ID:1586056
MD5:9ed024fe6506128c62fc2434d7e06c6a
SHA1:dcf9b2fca59bb8d190330c75f130f95ac57c3de8
SHA256:bceb944ffd744e6f98b786e6da277aa79ae2c6cb0c593a2797670eb9cf21b60b
Tags:user-elfdigest
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586056
Start date and time:2025-01-08 17:09:02 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:uYtea.x86.elf
Detection:MAL
Classification:mal68.linELF@0/0@0/0
  • VT rate limit hit for: uYtea.x86.elf
Command:/tmp/uYtea.x86.elf
PID:6297
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
connecterror
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 6276, Parent: 4339)
  • rm (PID: 6276, Parent: 4339, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.OCPiImhQ4o /tmp/tmp.CBhFXvNVT1 /tmp/tmp.vqeyH1qRj2
  • dash New Fork (PID: 6277, Parent: 4339)
  • cat (PID: 6277, Parent: 4339, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.OCPiImhQ4o
  • dash New Fork (PID: 6278, Parent: 4339)
  • head (PID: 6278, Parent: 4339, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6279, Parent: 4339)
  • tr (PID: 6279, Parent: 4339, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6280, Parent: 4339)
  • cut (PID: 6280, Parent: 4339, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6281, Parent: 4339)
  • cat (PID: 6281, Parent: 4339, MD5: 7e9d213e404ad3bb82e4ebb2e1f2c1b3) Arguments: cat /tmp/tmp.OCPiImhQ4o
  • dash New Fork (PID: 6282, Parent: 4339)
  • head (PID: 6282, Parent: 4339, MD5: fd96a67145172477dd57131396fc9608) Arguments: head -n 10
  • dash New Fork (PID: 6283, Parent: 4339)
  • tr (PID: 6283, Parent: 4339, MD5: fbd1402dd9f72d8ebfff00ce7c3a7bb5) Arguments: tr -d \\000-\\011\\013\\014\\016-\\037
  • dash New Fork (PID: 6284, Parent: 4339)
  • cut (PID: 6284, Parent: 4339, MD5: d8ed0ea8f22c0de0f8692d4d9f1759d3) Arguments: cut -c -80
  • dash New Fork (PID: 6285, Parent: 4339)
  • rm (PID: 6285, Parent: 4339, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.OCPiImhQ4o /tmp/tmp.CBhFXvNVT1 /tmp/tmp.vqeyH1qRj2
  • uYtea.x86.elf (PID: 6297, Parent: 6212, MD5: 9ed024fe6506128c62fc2434d7e06c6a) Arguments: /tmp/uYtea.x86.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
uYtea.x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xa580:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa594:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa60c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa620:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa634:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa648:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa65c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa670:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa684:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa698:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
uYtea.x86.elfLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x56d0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
uYtea.x86.elfLinux_Trojan_Mirai_88de437funknownunknown
  • 0x76b2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
uYtea.x86.elfLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x961d:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
uYtea.x86.elfLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x7ffd:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 1 entries
SourceRuleDescriptionAuthorStrings
6299.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xa580:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa594:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa5f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa60c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa620:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa634:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa648:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa65c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa670:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa684:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa698:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6ac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6c0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6d4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6e8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa6fc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xa710:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
6299.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_b14f4c5dunknownunknown
  • 0x56d0:$a: 53 31 DB 8B 4C 24 0C 8B 54 24 08 83 F9 01 76 15 66 8B 02 83 E9 02 25 FF FF 00 00 83 C2 02 01 C3 83 F9 01 77 EB 49 75 05 0F BE 02 01 C3
6299.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_88de437funknownunknown
  • 0x76b2:$a: 24 08 8B 4C 24 04 85 D2 74 0D 31 C0 89 F6 C6 04 08 00 40 39 D0
6299.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_389ee3e9unknownunknown
  • 0x961d:$a: 89 45 00 EB 2C 8B 4B 04 8B 13 8B 7B 18 8B 01 01 02 8B 02 83
6299.1.0000000008048000.0000000008055000.r-x.sdmpLinux_Trojan_Mirai_cc93863bunknownunknown
  • 0x7ffd:$a: C3 57 8B 44 24 0C 8B 4C 24 10 8B 7C 24 08 F3 AA 8B 44 24 08
Click to see the 9 entries
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: uYtea.x86.elfAvira: detected
Source: uYtea.x86.elfReversingLabs: Detection: 68%
Source: uYtea.x86.elfJoe Sandbox ML: detected
Source: global trafficTCP traffic: 192.168.2.23:51410 -> 141.98.10.115:1302
Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f Author: unknown
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b Author: unknown
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown
Source: Process Memory Space: uYtea.x86.elf PID: 6297, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.x86.elf PID: 6299, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: uYtea.x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6299.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_88de437f reference_sample = 8dc745a6de6f319cd6021c3e147597315cc1be02099d78fc8aae94de0e1e4bc6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = c19eb595c2b444a809bef8500c20342c9f46694d3018e268833f9b884133a1ea, id = 88de437f-9c98-4e1d-96c0-7b433c99886a, last_modified = 2021-09-16
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26
Source: 6297.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26
Source: Process Memory Space: uYtea.x86.elf PID: 6297, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.x86.elf PID: 6299, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal68.linELF@0/0@0/0
Source: /tmp/uYtea.x86.elf (PID: 6298)Directory: /tmp/.Jump to behavior
Source: /tmp/uYtea.x86.elf (PID: 6298)Directory: /tmp/..Jump to behavior
Source: /usr/bin/dash (PID: 6276)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.OCPiImhQ4o /tmp/tmp.CBhFXvNVT1 /tmp/tmp.vqeyH1qRj2Jump to behavior
Source: /usr/bin/dash (PID: 6285)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.OCPiImhQ4o /tmp/tmp.CBhFXvNVT1 /tmp/tmp.vqeyH1qRj2Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1586056 Sample: uYtea.x86.elf Startdate: 08/01/2025 Architecture: LINUX Score: 68 20 109.202.202.202, 80 INIT7CH Switzerland 2->20 22 141.98.10.115, 1302, 51410, 51412 HOSTBALTICLT Lithuania 2->22 24 2 other IPs or domains 2->24 26 Malicious sample detected (through community Yara rule) 2->26 28 Antivirus / Scanner detection for submitted sample 2->28 30 Multi AV Scanner detection for submitted file 2->30 32 Machine Learning detection for sample 2->32 8 dash rm uYtea.x86.elf 2->8         started        10 dash rm 2->10         started        12 dash cut 2->12         started        14 7 other processes 2->14 signatures3 process4 process5 16 uYtea.x86.elf 8->16         started        process6 18 uYtea.x86.elf 16->18         started       
SourceDetectionScannerLabelLink
uYtea.x86.elf68%ReversingLabsLinux.Trojan.LnxMirai
uYtea.x86.elf100%AviraEXP/ELF.Mirai.Z.D
uYtea.x86.elf100%Joe Sandbox ML
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
141.98.10.115
unknownLithuania
209605HOSTBALTICLTfalse
109.202.202.202
unknownSwitzerland
13030INIT7CHfalse
91.189.91.43
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
91.189.91.42
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
141.98.10.115uYtea.arm.elfGet hashmaliciousUnknownBrowse
    uYtea.mips.elfGet hashmaliciousUnknownBrowse
      uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
        uYtea.arm7.elfGet hashmaliciousMiraiBrowse
          109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
          • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
          91.189.91.43uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
            uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
              main_x86_64.elfGet hashmaliciousMiraiBrowse
                Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                  main_m68k.elfGet hashmaliciousMiraiBrowse
                    main_arm5.elfGet hashmaliciousMiraiBrowse
                      mips64.elfGet hashmaliciousUnknownBrowse
                        mips64el.elfGet hashmaliciousUnknownBrowse
                          main_arm.elfGet hashmaliciousMiraiBrowse
                            mips.elfGet hashmaliciousMiraiBrowse
                              91.189.91.42uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                  main_x86_64.elfGet hashmaliciousMiraiBrowse
                                    Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                      main_m68k.elfGet hashmaliciousMiraiBrowse
                                        main_arm5.elfGet hashmaliciousMiraiBrowse
                                          mips64.elfGet hashmaliciousUnknownBrowse
                                            mips64el.elfGet hashmaliciousUnknownBrowse
                                              main_arm.elfGet hashmaliciousMiraiBrowse
                                                mips.elfGet hashmaliciousMiraiBrowse
                                                  No context
                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                  CANONICAL-ASGBuYtea.arc.elfGet hashmaliciousMiraiBrowse
                                                  • 185.125.190.26
                                                  uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  main_x86_64.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  main_m68k.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  main_arm5.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  mips64.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  386.elfGet hashmaliciousUnknownBrowse
                                                  • 185.125.190.26
                                                  mips64el.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  CANONICAL-ASGBuYtea.arc.elfGet hashmaliciousMiraiBrowse
                                                  • 185.125.190.26
                                                  uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  main_x86_64.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  main_m68k.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  main_arm5.elfGet hashmaliciousMiraiBrowse
                                                  • 91.189.91.42
                                                  mips64.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  386.elfGet hashmaliciousUnknownBrowse
                                                  • 185.125.190.26
                                                  mips64el.elfGet hashmaliciousUnknownBrowse
                                                  • 91.189.91.42
                                                  HOSTBALTICLTuYtea.arm.elfGet hashmaliciousUnknownBrowse
                                                  • 141.98.10.115
                                                  uYtea.mips.elfGet hashmaliciousUnknownBrowse
                                                  • 141.98.10.115
                                                  uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                                  • 141.98.10.115
                                                  uYtea.arm7.elfGet hashmaliciousMiraiBrowse
                                                  • 141.98.10.115
                                                  Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                  • 141.98.10.88
                                                  Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                  • 141.98.10.88
                                                  Scan112024.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                  • 141.98.10.88
                                                  173127133603e75602cf90c03b229cc07ec4f5c026cad2909c809b767b293bf800a0e9ade9674.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                  • 141.98.10.88
                                                  ConfirmaciXnXdeXfacturaXPedidoXadicional.docGet hashmaliciousUnknownBrowse
                                                  • 141.98.10.88
                                                  DOC11042024.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                  • 141.98.10.40
                                                  INIT7CHuYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  main_x86_64.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  main_m68k.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  main_arm5.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  mips64.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  mips64el.elfGet hashmaliciousUnknownBrowse
                                                  • 109.202.202.202
                                                  main_arm.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  mips.elfGet hashmaliciousMiraiBrowse
                                                  • 109.202.202.202
                                                  No context
                                                  No context
                                                  No created / dropped files found
                                                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
                                                  Entropy (8bit):6.337312856633209
                                                  TrID:
                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                  File name:uYtea.x86.elf
                                                  File size:55'348 bytes
                                                  MD5:9ed024fe6506128c62fc2434d7e06c6a
                                                  SHA1:dcf9b2fca59bb8d190330c75f130f95ac57c3de8
                                                  SHA256:bceb944ffd744e6f98b786e6da277aa79ae2c6cb0c593a2797670eb9cf21b60b
                                                  SHA512:f0707c0c0196cb867addd35c6253debb137bec2f2a8d0ccfc280d4d79b87950ddfa2f34c6b6d9b9e5c93e8ff6f422f21930b476020fdba2f5b82b213b95b3a71
                                                  SSDEEP:768:FmnthEsW5qnF15RY1dhPe7oXTmcFDj5gk9vWnTI4eBH+4sToQLDLFv:Yn/EsW5qhSh6amalWnU4GH+dNLt
                                                  TLSH:93434AC4F143E9F5E85301741026EF379F72F2EA115CDD93D3A9EA226C92A12E446D8D
                                                  File Content Preview:.ELF....................d...4...........4. ...(..............................................P...P..d....M..........Q.td............................U..S.......w....h........[]...$.............U......=.V...t..5....$P.....$P......u........t....h.D..........

                                                  ELF header

                                                  Class:ELF32
                                                  Data:2's complement, little endian
                                                  Version:1 (current)
                                                  Machine:Intel 80386
                                                  Version Number:0x1
                                                  Type:EXEC (Executable file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x8048164
                                                  Flags:0x0
                                                  ELF Header Size:52
                                                  Program Header Offset:52
                                                  Program Header Size:32
                                                  Number of Program Headers:3
                                                  Section Header Offset:54948
                                                  Section Header Size:40
                                                  Number of Section Headers:10
                                                  Header String Table Index:9
                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                  NULL0x00x00x00x00x0000
                                                  .initPROGBITS0x80480940x940x1c0x00x6AX001
                                                  .textPROGBITS0x80480b00xb00xa4b60x00x6AX0016
                                                  .finiPROGBITS0x80525660xa5660x170x00x6AX001
                                                  .rodataPROGBITS0x80525800xa5800x1f600x00x2A0032
                                                  .ctorsPROGBITS0x80550000xd0000x80x00x3WA004
                                                  .dtorsPROGBITS0x80550080xd0080x80x00x3WA004
                                                  .dataPROGBITS0x80550200xd0200x6440x00x3WA0032
                                                  .bssNOBITS0x80556800xd6640x46800x00x3WA0032
                                                  .shstrtabSTRTAB0x00xd6640x3e0x00x0001
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  LOAD0x00x80480000x80480000xc4e00xc4e06.55270x5R E0x1000.init .text .fini .rodata
                                                  LOAD0xd0000x80550000x80550000x6640x4d005.14750x6RW 0x1000.ctors .dtors .data .bss
                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                  TimestampSource PortDest PortSource IPDest IP
                                                  Jan 8, 2025 17:09:59.882635117 CET43928443192.168.2.2391.189.91.42
                                                  Jan 8, 2025 17:10:04.057323933 CET514101302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:04.062349081 CET130251410141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:04.062417984 CET514101302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:04.062450886 CET514101302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:04.067260027 CET130251410141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:04.067322016 CET514101302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:04.072139025 CET130251410141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:04.490106106 CET4251680192.168.2.23109.202.202.202
                                                  Jan 8, 2025 17:10:05.514023066 CET42836443192.168.2.2391.189.91.43
                                                  Jan 8, 2025 17:10:05.759278059 CET130251410141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:05.759416103 CET514101302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:05.764293909 CET130251410141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:06.760339022 CET514121302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:06.765227079 CET130251412141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:06.765291929 CET514121302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:06.765314102 CET514121302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:06.771087885 CET130251412141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:06.771138906 CET514121302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:06.776119947 CET130251412141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:08.453057051 CET130251412141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:08.453634977 CET514121302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:08.458528042 CET130251412141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:09.454797029 CET514141302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:09.459759951 CET130251414141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:09.459827900 CET514141302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:09.459880114 CET514141302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:09.464610100 CET130251414141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:09.464653015 CET514141302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:09.469439030 CET130251414141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:11.179698944 CET130251414141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:11.179958105 CET514141302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:11.184750080 CET130251414141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:12.181092024 CET514161302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:12.186011076 CET130251416141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:12.186072111 CET514161302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:12.186105967 CET514161302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:12.190903902 CET130251416141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:12.191102028 CET514161302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:12.195921898 CET130251416141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:13.891290903 CET130251416141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:13.891666889 CET514161302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:13.896469116 CET130251416141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:14.892851114 CET514181302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:14.897748947 CET130251418141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:14.897819042 CET514181302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:14.897844076 CET514181302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:14.902602911 CET130251418141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:14.902653933 CET514181302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:14.907500982 CET130251418141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:16.612315893 CET130251418141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:16.612708092 CET514181302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:16.617563009 CET130251418141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:17.613869905 CET514201302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:17.618782043 CET130251420141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:17.618834972 CET514201302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:17.618859053 CET514201302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:17.623583078 CET130251420141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:17.623629093 CET514201302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:17.628376007 CET130251420141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:19.309876919 CET130251420141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:19.310163021 CET514201302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:19.316211939 CET130251420141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:20.103867054 CET43928443192.168.2.2391.189.91.42
                                                  Jan 8, 2025 17:10:20.311559916 CET514221302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:20.316456079 CET130251422141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:20.316536903 CET514221302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:20.316607952 CET514221302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:20.321322918 CET130251422141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:20.321397066 CET514221302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:20.326252937 CET130251422141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:22.034858942 CET130251422141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:22.035089970 CET514221302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:22.039943933 CET130251422141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:23.036390066 CET514241302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:23.041424036 CET130251424141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:23.041707039 CET514241302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:23.041707039 CET514241302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:23.046530008 CET130251424141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:23.046586990 CET514241302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:23.051377058 CET130251424141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:24.801588058 CET130251424141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:24.802092075 CET514241302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:24.806988001 CET130251424141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:25.803409100 CET514261302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:25.808392048 CET130251426141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:25.808522940 CET514261302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:25.808548927 CET514261302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:25.813312054 CET130251426141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:25.813363075 CET514261302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:25.818136930 CET130251426141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:27.498476982 CET130251426141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:27.498755932 CET514261302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:27.503586054 CET130251426141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:28.499948025 CET514281302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:28.504842997 CET130251428141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:28.504973888 CET514281302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:28.504987955 CET514281302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:28.509754896 CET130251428141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:28.509823084 CET514281302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:28.515058041 CET130251428141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:30.221040964 CET130251428141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:30.221205950 CET514281302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:30.226007938 CET130251428141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:31.222495079 CET514301302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:31.227380991 CET130251430141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:31.227502108 CET514301302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:31.227543116 CET514301302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:31.232423067 CET130251430141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:31.232486963 CET514301302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:31.237397909 CET130251430141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:32.390153885 CET42836443192.168.2.2391.189.91.43
                                                  Jan 8, 2025 17:10:32.935857058 CET130251430141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:32.936069012 CET514301302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:32.941272974 CET130251430141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:33.937052011 CET514321302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:33.942018986 CET130251432141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:33.942122936 CET514321302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:33.942151070 CET514321302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:33.946867943 CET130251432141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:33.946914911 CET514321302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:33.951664925 CET130251432141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:34.437869072 CET4251680192.168.2.23109.202.202.202
                                                  Jan 8, 2025 17:10:35.641156912 CET130251432141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:35.641374111 CET514321302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:35.646612883 CET130251432141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:36.642442942 CET514341302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:36.647336960 CET130251434141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:36.647464037 CET514341302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:36.647480965 CET514341302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:36.652244091 CET130251434141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:36.652309895 CET514341302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:36.659090996 CET130251434141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:38.368837118 CET130251434141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:38.369281054 CET514341302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:38.374161959 CET130251434141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:39.370635986 CET514361302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:39.375616074 CET130251436141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:39.375734091 CET514361302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:39.375749111 CET514361302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:39.380556107 CET130251436141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:39.380628109 CET514361302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:39.385452986 CET130251436141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:41.060991049 CET130251436141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:41.061446905 CET514361302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:41.066342115 CET130251436141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:42.062915087 CET514381302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:42.067893028 CET130251438141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:42.067985058 CET514381302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:42.068020105 CET514381302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:42.072805882 CET130251438141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:42.072863102 CET514381302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:42.077660084 CET130251438141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:43.770240068 CET130251438141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:43.770440102 CET514381302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:43.775300980 CET130251438141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:44.771768093 CET514401302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:44.776643038 CET130251440141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:44.776711941 CET514401302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:44.776747942 CET514401302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:44.781529903 CET130251440141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:44.781574011 CET514401302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:44.786360979 CET130251440141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:46.468317032 CET130251440141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:46.468584061 CET514401302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:46.473440886 CET130251440141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:47.470454931 CET514421302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:47.475452900 CET130251442141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:47.475538969 CET514421302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:47.475631952 CET514421302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:47.480432987 CET130251442141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:47.480493069 CET514421302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:47.485264063 CET130251442141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:49.202327013 CET130251442141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:49.202675104 CET514421302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:49.207516909 CET130251442141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:50.203887939 CET514441302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:50.208722115 CET130251444141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:50.208770990 CET514441302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:50.208796978 CET514441302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:50.213552952 CET130251444141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:50.213591099 CET514441302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:50.218384027 CET130251444141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:51.985877037 CET130251444141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:51.986227036 CET514441302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:51.991002083 CET130251444141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:52.987428904 CET514461302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:52.992273092 CET130251446141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:52.992326021 CET514461302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:52.992352962 CET514461302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:52.997124910 CET130251446141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:52.997168064 CET514461302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:53.001921892 CET130251446141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:54.785016060 CET130251446141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:54.785392046 CET514461302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:54.790195942 CET130251446141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:55.786993980 CET514481302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:55.791925907 CET130251448141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:55.792006969 CET514481302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:55.792095900 CET514481302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:55.796876907 CET130251448141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:55.796941042 CET514481302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:55.801696062 CET130251448141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:57.482547998 CET130251448141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:57.482772112 CET514481302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:57.487628937 CET130251448141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:58.484582901 CET514501302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:58.489512920 CET130251450141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:58.489569902 CET514501302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:58.489589930 CET514501302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:58.494409084 CET130251450141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:10:58.494456053 CET514501302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:10:58.499205112 CET130251450141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:00.202056885 CET130251450141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:00.202439070 CET514501302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:00.207262993 CET130251450141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:01.058202028 CET43928443192.168.2.2391.189.91.42
                                                  Jan 8, 2025 17:11:01.204185009 CET514521302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:01.209095955 CET130251452141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:01.209160089 CET514521302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:01.209217072 CET514521302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:01.214090109 CET130251452141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:01.214140892 CET514521302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:01.218997955 CET130251452141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:02.942403078 CET130251452141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:02.942554951 CET514521302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:02.947346926 CET130251452141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:03.943625927 CET514541302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:03.948647022 CET130251454141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:03.948731899 CET514541302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:03.948817015 CET514541302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:03.953598022 CET130251454141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:03.953644037 CET514541302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:03.958399057 CET130251454141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:05.642803907 CET130251454141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:05.643054962 CET514541302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:05.647931099 CET130251454141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:06.644263983 CET514561302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:06.649254084 CET130251456141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:06.649341106 CET514561302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:06.649364948 CET514561302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:06.654115915 CET130251456141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:06.654159069 CET514561302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:06.658941031 CET130251456141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:08.415941000 CET130251456141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:08.416227102 CET514561302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:08.421091080 CET130251456141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:09.417675018 CET514581302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:09.422637939 CET130251458141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:09.422763109 CET514581302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:09.422840118 CET514581302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:09.427599907 CET130251458141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:09.427678108 CET514581302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:09.432471037 CET130251458141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:11.128885984 CET130251458141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:11.129049063 CET514581302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:11.134947062 CET130251458141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:12.130183935 CET514601302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:12.855990887 CET130251460141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:12.856225014 CET514601302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:12.856328011 CET514601302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:12.861148119 CET130251460141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:12.861231089 CET514601302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:12.865991116 CET130251460141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:14.565315962 CET130251460141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:14.565495968 CET514601302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:14.570312977 CET130251460141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:15.566482067 CET514621302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:15.769144058 CET130251462141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:15.769279957 CET514621302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:15.769320965 CET514621302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:15.774158955 CET130251462141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:15.774216890 CET514621302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:15.778994083 CET130251462141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:17.471034050 CET130251462141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:17.471281052 CET514621302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:17.476140022 CET130251462141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:18.473037004 CET514641302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:18.477868080 CET130251464141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:18.477971077 CET514641302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:18.478032112 CET514641302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:18.482764006 CET130251464141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:18.482815981 CET514641302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:18.487582922 CET130251464141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:20.235922098 CET130251464141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:20.236077070 CET514641302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:20.240835905 CET130251464141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:21.237076044 CET514661302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:21.242247105 CET130251466141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:21.242378950 CET514661302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:21.242733955 CET514661302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:21.247447968 CET130251466141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:21.247529984 CET514661302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:21.252293110 CET130251466141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:22.973762035 CET130251466141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:22.974056959 CET514661302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:22.978900909 CET130251466141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:23.975234985 CET514681302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:23.980089903 CET130251468141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:23.980165958 CET514681302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:23.980215073 CET514681302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:23.985073090 CET130251468141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:23.985135078 CET514681302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:23.989881992 CET130251468141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:25.674690962 CET130251468141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:25.674946070 CET514681302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:25.680356979 CET130251468141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:26.676693916 CET514701302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:26.681566000 CET130251470141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:26.681653023 CET514701302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:26.681730032 CET514701302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:26.686563015 CET130251470141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:26.686635017 CET514701302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:26.691441059 CET130251470141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:28.485481977 CET130251470141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:28.485779047 CET514701302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:28.490555048 CET130251470141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:29.487387896 CET514721302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:29.492158890 CET130251472141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:29.492260933 CET514721302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:29.492332935 CET514721302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:29.497128010 CET130251472141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:29.497189999 CET514721302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:29.501933098 CET130251472141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:31.205966949 CET130251472141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:31.206229925 CET514721302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:31.211093903 CET130251472141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:32.207134008 CET514741302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:32.212021112 CET130251474141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:32.212084055 CET514741302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:32.212110996 CET514741302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:32.216928005 CET130251474141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:32.216999054 CET514741302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:32.221760988 CET130251474141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:33.908001900 CET130251474141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:33.908185959 CET514741302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:33.913019896 CET130251474141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:34.909249067 CET514761302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:34.914115906 CET130251476141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:34.914186954 CET514761302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:34.914223909 CET514761302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:34.918965101 CET130251476141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:34.919022083 CET514761302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:34.923783064 CET130251476141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:36.616329908 CET130251476141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:36.616739988 CET514761302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:36.621520996 CET130251476141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:37.617906094 CET514781302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:37.622786999 CET130251478141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:37.622845888 CET514781302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:37.622883081 CET514781302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:37.627629995 CET130251478141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:37.627671957 CET514781302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:37.632436037 CET130251478141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:39.312792063 CET130251478141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:39.312963009 CET514781302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:39.318372011 CET130251478141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:40.314037085 CET514801302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:40.319053888 CET130251480141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:40.319120884 CET514801302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:40.319149017 CET514801302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:40.323925018 CET130251480141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:40.323991060 CET514801302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:40.328763962 CET130251480141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:42.064822912 CET130251480141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:42.064965010 CET514801302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:42.069772005 CET130251480141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:43.065867901 CET514821302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:43.070653915 CET130251482141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:43.070704937 CET514821302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:43.070735931 CET514821302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:43.075537920 CET130251482141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:43.075587034 CET514821302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:43.080339909 CET130251482141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:44.770108938 CET130251482141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:44.770313978 CET514821302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:44.775141001 CET130251482141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:45.771991014 CET514841302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:45.776772976 CET130251484141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:45.776858091 CET514841302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:45.776952028 CET514841302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:45.782378912 CET130251484141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:45.782461882 CET514841302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:45.788089037 CET130251484141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:47.503371954 CET130251484141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:47.503602982 CET514841302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:47.510663986 CET130251484141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:48.504571915 CET514861302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:48.509316921 CET130251486141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:48.509368896 CET514861302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:48.509394884 CET514861302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:48.514168978 CET130251486141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:48.514214039 CET514861302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:48.518934011 CET130251486141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:50.422962904 CET130251486141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:50.423094988 CET514861302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:50.429595947 CET130251486141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:51.424566984 CET514881302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:51.429366112 CET130251488141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:51.429464102 CET514881302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:51.429546118 CET514881302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:51.434315920 CET130251488141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:51.434401035 CET514881302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:51.439147949 CET130251488141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:53.142524958 CET130251488141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:53.142725945 CET514881302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:53.149245977 CET130251488141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:54.143990040 CET514901302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:54.148890018 CET130251490141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:54.149007082 CET514901302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:54.149104118 CET514901302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:54.153863907 CET130251490141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:54.153932095 CET514901302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:54.158674955 CET130251490141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:55.827650070 CET130251490141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:55.827931881 CET514901302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:55.832760096 CET130251490141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:56.828942060 CET514921302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:56.833787918 CET130251492141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:56.833857059 CET514921302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:56.833889008 CET514921302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:56.838649988 CET130251492141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:56.838695049 CET514921302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:56.843441010 CET130251492141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:58.570949078 CET130251492141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:58.571297884 CET514921302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:58.576061964 CET130251492141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:59.572768927 CET514941302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:59.577621937 CET130251494141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:59.577717066 CET514941302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:59.577805042 CET514941302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:59.582573891 CET130251494141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:11:59.582655907 CET514941302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:11:59.587466955 CET130251494141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:12:01.328221083 CET130251494141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:12:01.328444958 CET514941302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:12:01.333293915 CET130251494141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:12:02.329802036 CET514961302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:12:02.334686041 CET130251496141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:12:02.334826946 CET514961302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:12:02.334873915 CET514961302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:12:02.340418100 CET130251496141.98.10.115192.168.2.23
                                                  Jan 8, 2025 17:12:02.340521097 CET514961302192.168.2.23141.98.10.115
                                                  Jan 8, 2025 17:12:02.345357895 CET130251496141.98.10.115192.168.2.23

                                                  System Behavior

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/rm
                                                  Arguments:rm -f /tmp/tmp.OCPiImhQ4o /tmp/tmp.CBhFXvNVT1 /tmp/tmp.vqeyH1qRj2
                                                  File size:72056 bytes
                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/cat
                                                  Arguments:cat /tmp/tmp.OCPiImhQ4o
                                                  File size:43416 bytes
                                                  MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/head
                                                  Arguments:head -n 10
                                                  File size:47480 bytes
                                                  MD5 hash:fd96a67145172477dd57131396fc9608

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/tr
                                                  Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                  File size:51544 bytes
                                                  MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/cut
                                                  Arguments:cut -c -80
                                                  File size:47480 bytes
                                                  MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/cat
                                                  Arguments:cat /tmp/tmp.OCPiImhQ4o
                                                  File size:43416 bytes
                                                  MD5 hash:7e9d213e404ad3bb82e4ebb2e1f2c1b3

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/head
                                                  Arguments:head -n 10
                                                  File size:47480 bytes
                                                  MD5 hash:fd96a67145172477dd57131396fc9608

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/tr
                                                  Arguments:tr -d \\000-\\011\\013\\014\\016-\\037
                                                  File size:51544 bytes
                                                  MD5 hash:fbd1402dd9f72d8ebfff00ce7c3a7bb5

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:48
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/cut
                                                  Arguments:cut -c -80
                                                  File size:47480 bytes
                                                  MD5 hash:d8ed0ea8f22c0de0f8692d4d9f1759d3

                                                  Start time (UTC):16:09:49
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/dash
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):16:09:49
                                                  Start date (UTC):08/01/2025
                                                  Path:/usr/bin/rm
                                                  Arguments:rm -f /tmp/tmp.OCPiImhQ4o /tmp/tmp.CBhFXvNVT1 /tmp/tmp.vqeyH1qRj2
                                                  File size:72056 bytes
                                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                                  Start time (UTC):16:09:57
                                                  Start date (UTC):08/01/2025
                                                  Path:/tmp/uYtea.x86.elf
                                                  Arguments:/tmp/uYtea.x86.elf
                                                  File size:55348 bytes
                                                  MD5 hash:9ed024fe6506128c62fc2434d7e06c6a

                                                  Start time (UTC):16:09:57
                                                  Start date (UTC):08/01/2025
                                                  Path:/tmp/uYtea.x86.elf
                                                  Arguments:-
                                                  File size:55348 bytes
                                                  MD5 hash:9ed024fe6506128c62fc2434d7e06c6a

                                                  Start time (UTC):16:09:57
                                                  Start date (UTC):08/01/2025
                                                  Path:/tmp/uYtea.x86.elf
                                                  Arguments:-
                                                  File size:55348 bytes
                                                  MD5 hash:9ed024fe6506128c62fc2434d7e06c6a