Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
uYtea.ppc.elf

Overview

General Information

Sample name:uYtea.ppc.elf
Analysis ID:1586062
MD5:41ac5881c526563558a9b1141d71d092
SHA1:4a410ffd83c414289dd0a6c27eb92cd0f3a39111
SHA256:55dceb79ff0e327ad2bb77f730e03d7e287fc141aba09481d0e67c09b185faab
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586062
Start date and time:2025-01-08 17:09:57 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 30s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:uYtea.ppc.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
  • VT rate limit hit for: uYtea.ppc.elf
Command:/tmp/uYtea.ppc.elf
PID:5552
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
connecterror
Standard Error:
  • system is lnxubuntu20
  • uYtea.ppc.elf (PID: 5552, Parent: 5473, MD5: ae65271c943d3451b7f026d1fadccea6) Arguments: /tmp/uYtea.ppc.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
uYtea.ppc.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xba98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbafc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5560.1.00007fbd94001000.00007fbd9400f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xba98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbafc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5552.1.00007fbd94001000.00007fbd9400f000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xba98:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbaac:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbac0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbad4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbae8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbafc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb10:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbb9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbb0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbc4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbd8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbbec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xbc28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.ppc.elf PID: 5552Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x112f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1143:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1157:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x117f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1193:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11a7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11bb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11cf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11e3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x11f7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x120b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x121f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1233:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1247:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x125b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x126f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1283:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1297:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x12ab:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x12bf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.ppc.elf PID: 5560Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x1007:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x101b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x102f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1043:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1057:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x106b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x107f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1093:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10a7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10bb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10cf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10e3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x10f7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x110b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x111f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1133:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1147:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x115b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x116f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1183:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1197:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: uYtea.ppc.elfAvira: detected
Source: uYtea.ppc.elfReversingLabs: Detection: 65%
Source: global trafficTCP traffic: 192.168.2.15:35658 -> 141.98.10.115:1302
Source: /tmp/uYtea.ppc.elf (PID: 5552)Socket: 127.0.0.1:9473Jump to behavior

System Summary

barindex
Source: uYtea.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5560.1.00007fbd94001000.00007fbd9400f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5552.1.00007fbd94001000.00007fbd9400f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.ppc.elf PID: 5552, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.ppc.elf PID: 5560, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: uYtea.ppc.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5560.1.00007fbd94001000.00007fbd9400f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5552.1.00007fbd94001000.00007fbd9400f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.ppc.elf PID: 5552, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.ppc.elf PID: 5560, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
Source: /tmp/uYtea.ppc.elf (PID: 5554)Directory: /tmp/.Jump to behavior
Source: /tmp/uYtea.ppc.elf (PID: 5554)Directory: /tmp/..Jump to behavior
Source: /tmp/uYtea.ppc.elf (PID: 5552)Queries kernel information via 'uname': Jump to behavior
Source: uYtea.ppc.elf, 5552.1.00007ffc7e24a000.00007ffc7e26b000.rw-.sdmp, uYtea.ppc.elf, 5560.1.00007ffc7e24a000.00007ffc7e26b000.rw-.sdmpBinary or memory string: :x86_64/usr/bin/qemu-ppc/tmp/uYtea.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/uYtea.ppc.elf
Source: uYtea.ppc.elf, 5552.1.000056228440c000.00005622844bc000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq
Source: uYtea.ppc.elf, 5560.1.000056228440c000.00005622844bc000.rw-.sdmpBinary or memory string: !/etc/qemu-binfmt/ppc1
Source: uYtea.ppc.elf, 5552.1.000056228440c000.00005622844bc000.rw-.sdmp, uYtea.ppc.elf, 5560.1.000056228440c000.00005622844bc000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/ppc
Source: uYtea.ppc.elf, 5552.1.00007ffc7e24a000.00007ffc7e26b000.rw-.sdmp, uYtea.ppc.elf, 5560.1.00007ffc7e24a000.00007ffc7e26b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-ppc
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
uYtea.ppc.elf66%ReversingLabsLinux.Trojan.Mirai
uYtea.ppc.elf100%AviraEXP/ELF.Mirai.Z.D
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
141.98.10.115
unknownLithuania
209605HOSTBALTICLTfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
141.98.10.115uYtea.x86.elfGet hashmaliciousUnknownBrowse
    uYtea.arm.elfGet hashmaliciousUnknownBrowse
      uYtea.mips.elfGet hashmaliciousUnknownBrowse
        uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
          uYtea.arm7.elfGet hashmaliciousMiraiBrowse
            No context
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            HOSTBALTICLTuYtea.x86.elfGet hashmaliciousUnknownBrowse
            • 141.98.10.115
            uYtea.arm.elfGet hashmaliciousUnknownBrowse
            • 141.98.10.115
            uYtea.mips.elfGet hashmaliciousUnknownBrowse
            • 141.98.10.115
            uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
            • 141.98.10.115
            uYtea.arm7.elfGet hashmaliciousMiraiBrowse
            • 141.98.10.115
            Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
            • 141.98.10.88
            Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
            • 141.98.10.88
            Scan112024.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
            • 141.98.10.88
            173127133603e75602cf90c03b229cc07ec4f5c026cad2909c809b767b293bf800a0e9ade9674.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
            • 141.98.10.88
            ConfirmaciXnXdeXfacturaXPedidoXadicional.docGet hashmaliciousUnknownBrowse
            • 141.98.10.88
            No context
            No context
            No created / dropped files found
            File type:ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
            Entropy (8bit):6.201326888275538
            TrID:
            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
            File name:uYtea.ppc.elf
            File size:59'764 bytes
            MD5:41ac5881c526563558a9b1141d71d092
            SHA1:4a410ffd83c414289dd0a6c27eb92cd0f3a39111
            SHA256:55dceb79ff0e327ad2bb77f730e03d7e287fc141aba09481d0e67c09b185faab
            SHA512:168a5070478d4b51d754c308ea8e5f6942a4d057db1609e61fd61235ad625bac6a58af9882f8538309b154524ce5b2ff7feff4c471ded3fdd9ecb1e0b88a1f7b
            SSDEEP:1536:eF6QcATQdskHosl9k1dP9iT0bI666hJa108:tqgtJHk1dP4gbI6x4f
            TLSH:99435B52721C0E17C4A31A70263F5BE08BFBEAE021E4B685695F5F968935D331486FCD
            File Content Preview:.ELF...........................4.........4. ...(.......................(...(...........................H..J4........dt.Q.............................!..|......$H...H..i...$8!. |...N.. .!..|.......?.............../...@..\?........+../...A..$8...})......N..

            ELF header

            Class:ELF32
            Data:2's complement, big endian
            Version:1 (current)
            Machine:PowerPC
            Version Number:0x1
            Type:EXEC (Executable file)
            OS/ABI:UNIX - System V
            ABI Version:0
            Entry Point Address:0x100001f0
            Flags:0x0
            ELF Header Size:52
            Program Header Offset:52
            Program Header Size:32
            Number of Program Headers:3
            Section Header Offset:59284
            Section Header Size:40
            Number of Section Headers:12
            Header String Table Index:11
            NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
            NULL0x00x00x00x00x0000
            .initPROGBITS0x100000940x940x240x00x6AX004
            .textPROGBITS0x100000b80xb80xb9c00x00x6AX004
            .finiPROGBITS0x1000ba780xba780x200x00x6AX004
            .rodataPROGBITS0x1000ba980xba980x1f900x00x2A004
            .ctorsPROGBITS0x1001e0000xe0000x80x00x3WA004
            .dtorsPROGBITS0x1001e0080xe0080x80x00x3WA004
            .dataPROGBITS0x1001e0180xe0180x7040x00x3WA008
            .sdataPROGBITS0x1001e71c0xe71c0x2c0x00x3WA004
            .sbssNOBITS0x1001e7480xe7480x540x00x3WA004
            .bssNOBITS0x1001e79c0xe7480x42980x00x3WA004
            .shstrtabSTRTAB0x00xe7480x4b0x00x0001
            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
            LOAD0x00x100000000x100000000xda280xda286.33550x5R E0x10000.init .text .fini .rodata
            LOAD0xe0000x1001e0000x1001e0000x7480x4a344.31500x6RW 0x10000.ctors .dtors .data .sdata .sbss .bss
            GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
            TimestampSource PortDest PortSource IPDest IP
            Jan 8, 2025 17:10:57.116444111 CET356581302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:57.121304035 CET130235658141.98.10.115192.168.2.15
            Jan 8, 2025 17:10:57.121357918 CET356581302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:57.122221947 CET356581302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:57.126945019 CET130235658141.98.10.115192.168.2.15
            Jan 8, 2025 17:10:57.127007008 CET356581302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:57.131738901 CET130235658141.98.10.115192.168.2.15
            Jan 8, 2025 17:10:58.831073046 CET130235658141.98.10.115192.168.2.15
            Jan 8, 2025 17:10:58.831351042 CET356581302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:58.836194992 CET130235658141.98.10.115192.168.2.15
            Jan 8, 2025 17:10:59.833266973 CET356601302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:59.840894938 CET130235660141.98.10.115192.168.2.15
            Jan 8, 2025 17:10:59.840970993 CET356601302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:59.841630936 CET356601302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:59.849138975 CET130235660141.98.10.115192.168.2.15
            Jan 8, 2025 17:10:59.849181890 CET356601302192.168.2.15141.98.10.115
            Jan 8, 2025 17:10:59.855492115 CET130235660141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:01.531265020 CET130235660141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:01.531511068 CET356601302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:01.536293983 CET130235660141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:02.533229113 CET356621302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:02.538309097 CET130235662141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:02.538398027 CET356621302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:02.539210081 CET356621302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:02.544312954 CET130235662141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:02.544399023 CET356621302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:02.549288034 CET130235662141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:04.218050003 CET130235662141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:04.218389034 CET356621302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:04.223196030 CET130235662141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:05.220103025 CET356641302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:05.225152969 CET130235664141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:05.225213051 CET356641302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:05.225831985 CET356641302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:05.230612993 CET130235664141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:05.230659962 CET356641302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:05.235662937 CET130235664141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:06.927891016 CET130235664141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:06.928127050 CET356641302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:06.932944059 CET130235664141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:07.929689884 CET356661302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:07.934717894 CET130235666141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:07.934797049 CET356661302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:07.935456991 CET356661302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:07.940210104 CET130235666141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:07.940253019 CET356661302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:07.945070028 CET130235666141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:09.889146090 CET130235666141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:09.889534950 CET356661302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:09.894412041 CET130235666141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:10.891666889 CET356681302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:10.896709919 CET130235668141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:10.896894932 CET356681302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:10.898049116 CET356681302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:10.902823925 CET130235668141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:10.902929068 CET356681302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:10.907759905 CET130235668141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:12.854316950 CET130235668141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:12.854327917 CET130235668141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:12.854753017 CET356681302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:12.854829073 CET356681302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:12.859703064 CET130235668141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:13.856332064 CET356701302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:13.861762047 CET130235670141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:13.861897945 CET356701302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:13.862463951 CET356701302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:13.867957115 CET130235670141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:13.868025064 CET356701302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:13.873399973 CET130235670141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:15.768500090 CET130235670141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:15.768788099 CET356701302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:15.773598909 CET130235670141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:16.770809889 CET356721302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:16.775728941 CET130235672141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:16.775821924 CET356721302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:16.776643991 CET356721302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:16.781449080 CET130235672141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:16.781506062 CET356721302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:16.786382914 CET130235672141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:18.531114101 CET130235672141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:18.531347990 CET356721302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:18.536132097 CET130235672141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:19.532999039 CET356741302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:19.537800074 CET130235674141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:19.537884951 CET356741302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:19.538594007 CET356741302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:19.543389082 CET130235674141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:19.543431044 CET356741302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:19.548178911 CET130235674141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:21.236591101 CET130235674141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:21.236778021 CET356741302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:21.241827965 CET130235674141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:22.238814116 CET356761302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:22.243678093 CET130235676141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:22.243783951 CET356761302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:22.244808912 CET356761302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:22.249629021 CET130235676141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:22.249684095 CET356761302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:22.254462957 CET130235676141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:23.967452049 CET130235676141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:23.967652082 CET356761302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:23.972434998 CET130235676141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:24.969403982 CET356781302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:24.974241972 CET130235678141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:24.974338055 CET356781302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:24.975431919 CET356781302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:24.980159998 CET130235678141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:24.980218887 CET356781302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:24.984968901 CET130235678141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:26.757442951 CET130235678141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:26.757637978 CET356781302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:26.762437105 CET130235678141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:27.759226084 CET356801302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:27.764197111 CET130235680141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:27.764331102 CET356801302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:27.765110970 CET356801302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:27.769922018 CET130235680141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:27.769994020 CET356801302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:27.774791002 CET130235680141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:29.486653090 CET130235680141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:29.487118006 CET356801302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:29.491905928 CET130235680141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:30.488957882 CET356821302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:30.493925095 CET130235682141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:30.494168997 CET356821302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:30.494879961 CET356821302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:30.499686003 CET130235682141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:30.499767065 CET356821302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:30.504576921 CET130235682141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:32.187328100 CET130235682141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:32.187560081 CET356821302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:32.192789078 CET130235682141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:33.189363956 CET356841302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:33.194392920 CET130235684141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:33.194488049 CET356841302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:33.195343971 CET356841302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:33.200067043 CET130235684141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:33.200110912 CET356841302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:33.204883099 CET130235684141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:34.890619040 CET130235684141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:34.890930891 CET356841302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:34.895768881 CET130235684141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:35.892988920 CET356861302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:35.897989035 CET130235686141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:35.898086071 CET356861302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:35.899183035 CET356861302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:35.903955936 CET130235686141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:35.904020071 CET356861302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:35.908761024 CET130235686141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:37.595319033 CET130235686141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:37.595474005 CET356861302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:37.600322008 CET130235686141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:38.596987009 CET356881302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:38.601972103 CET130235688141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:38.602076054 CET356881302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:38.602804899 CET356881302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:38.607562065 CET130235688141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:38.607611895 CET356881302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:38.612358093 CET130235688141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:40.333587885 CET130235688141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:40.333872080 CET356881302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:40.338608027 CET130235688141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:41.335679054 CET356901302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:41.340511084 CET130235690141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:41.340612888 CET356901302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:41.341366053 CET356901302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:41.346129894 CET130235690141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:41.346180916 CET356901302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:41.350999117 CET130235690141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:43.066081047 CET130235690141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:43.066338062 CET356901302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:43.071094036 CET130235690141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:44.067770004 CET356921302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:44.072654009 CET130235692141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:44.072721958 CET356921302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:44.073409081 CET356921302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:44.078207016 CET130235692141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:44.078263998 CET356921302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:44.083053112 CET130235692141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:45.812908888 CET130235692141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:45.813150883 CET356921302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:45.817915916 CET130235692141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:46.814670086 CET356941302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:46.819534063 CET130235694141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:46.819598913 CET356941302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:46.820453882 CET356941302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:46.825300932 CET130235694141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:46.825352907 CET356941302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:46.830192089 CET130235694141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:48.592004061 CET130235694141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:48.592314005 CET356941302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:48.597345114 CET130235694141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:49.594367027 CET356961302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:49.603219986 CET130235696141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:49.603332996 CET356961302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:49.605294943 CET356961302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:49.614032030 CET130235696141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:49.614090919 CET356961302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:49.622664928 CET130235696141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:51.339797020 CET130235696141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:51.340212107 CET356961302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:51.345000982 CET130235696141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:52.342026949 CET356981302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:52.347505093 CET130235698141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:52.347604990 CET356981302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:52.348350048 CET356981302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:52.353158951 CET130235698141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:52.353214025 CET356981302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:52.358541012 CET130235698141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:54.124061108 CET130235698141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:54.124248028 CET356981302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:54.129013062 CET130235698141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:55.125678062 CET357001302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:55.130489111 CET130235700141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:55.130575895 CET357001302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:55.131366014 CET357001302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:55.136172056 CET130235700141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:55.136240005 CET357001302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:55.141032934 CET130235700141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:56.876023054 CET130235700141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:56.876274109 CET357001302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:56.881061077 CET130235700141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:57.877696991 CET357021302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:57.882503986 CET130235702141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:57.882561922 CET357021302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:57.883245945 CET357021302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:57.888016939 CET130235702141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:57.888075113 CET357021302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:57.892891884 CET130235702141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:59.692362070 CET130235702141.98.10.115192.168.2.15
            Jan 8, 2025 17:11:59.692550898 CET357021302192.168.2.15141.98.10.115
            Jan 8, 2025 17:11:59.697407961 CET130235702141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:00.693999052 CET357041302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:00.698935986 CET130235704141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:00.699055910 CET357041302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:00.699683905 CET357041302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:00.704427004 CET130235704141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:00.704479933 CET357041302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:00.709237099 CET130235704141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:02.422092915 CET130235704141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:02.422517061 CET357041302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:02.427287102 CET130235704141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:03.424479961 CET357061302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:03.429291964 CET130235706141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:03.429416895 CET357061302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:03.430150032 CET357061302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:03.434937000 CET130235706141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:03.435017109 CET357061302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:03.439800978 CET130235706141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:05.219115973 CET130235706141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:05.219333887 CET357061302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:05.224160910 CET130235706141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:06.221129894 CET357081302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:06.227488995 CET130235708141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:06.227549076 CET357081302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:06.228255033 CET357081302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:06.235697031 CET130235708141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:06.235739946 CET357081302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:06.240475893 CET130235708141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:07.925885916 CET130235708141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:07.926137924 CET357081302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:07.930973053 CET130235708141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:08.928071022 CET357101302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:08.932948112 CET130235710141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:08.933038950 CET357101302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:08.934112072 CET357101302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:08.940201998 CET130235710141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:08.940258980 CET357101302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:08.946073055 CET130235710141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:10.790019989 CET130235710141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:10.790266991 CET357101302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:10.795403004 CET130235710141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:11.792804956 CET357121302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:11.797641039 CET130235712141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:11.797780991 CET357121302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:11.798988104 CET357121302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:11.803734064 CET130235712141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:11.803807020 CET357121302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:11.808557987 CET130235712141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:13.624702930 CET130235712141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:13.624994993 CET357121302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:13.629766941 CET130235712141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:14.626830101 CET357141302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:14.631694078 CET130235714141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:14.631891012 CET357141302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:14.632560015 CET357141302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:14.637325048 CET130235714141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:14.637398958 CET357141302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:14.642189026 CET130235714141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:16.425092936 CET130235714141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:16.425609112 CET357141302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:16.430499077 CET130235714141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:17.427799940 CET357161302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:17.432658911 CET130235716141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:17.432734966 CET357161302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:17.433733940 CET357161302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:17.438494921 CET130235716141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:17.438555956 CET357161302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:17.443344116 CET130235716141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:19.128612041 CET130235716141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:19.128993034 CET357161302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:19.133775949 CET130235716141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:20.130863905 CET357181302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:20.135760069 CET130235718141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:20.135838985 CET357181302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:20.137033939 CET357181302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:20.141819000 CET130235718141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:20.141866922 CET357181302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:20.146691084 CET130235718141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:21.844285011 CET130235718141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:21.844469070 CET357181302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:21.849263906 CET130235718141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:22.846326113 CET357201302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:22.851145029 CET130235720141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:22.851351976 CET357201302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:22.852057934 CET357201302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:22.856820107 CET130235720141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:22.856890917 CET357201302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:22.861650944 CET130235720141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:24.549516916 CET130235720141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:24.549853086 CET357201302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:24.554661036 CET130235720141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:25.551450968 CET357221302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:25.557653904 CET130235722141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:25.557790995 CET357221302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:25.558551073 CET357221302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:25.563564062 CET130235722141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:25.563623905 CET357221302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:25.568625927 CET130235722141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:27.317337990 CET130235722141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:27.317631960 CET357221302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:27.322402000 CET130235722141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:28.319199085 CET357241302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:28.323995113 CET130235724141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:28.324049950 CET357241302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:28.324970961 CET357241302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:28.329791069 CET130235724141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:28.329840899 CET357241302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:28.334582090 CET130235724141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:30.035007000 CET130235724141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:30.035316944 CET357241302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:30.040162086 CET130235724141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:31.036865950 CET357261302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:31.041718006 CET130235726141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:31.041780949 CET357261302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:31.042463064 CET357261302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:31.047276020 CET130235726141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:31.047342062 CET357261302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:31.052508116 CET130235726141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:32.768388033 CET130235726141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:32.768563986 CET357261302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:32.773379087 CET130235726141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:33.770353079 CET357281302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:33.775162935 CET130235728141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:33.775402069 CET357281302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:33.776563883 CET357281302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:33.781346083 CET130235728141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:33.781419039 CET357281302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:33.786237001 CET130235728141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:35.494029045 CET130235728141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:35.494362116 CET357281302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:35.499216080 CET130235728141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:36.496268988 CET357301302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:36.501255035 CET130235730141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:36.501396894 CET357301302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:36.502178907 CET357301302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:36.506990910 CET130235730141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:36.507067919 CET357301302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:36.511939049 CET130235730141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:38.208621979 CET130235730141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:38.208836079 CET357301302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:38.213597059 CET130235730141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:39.210478067 CET357321302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:39.215255022 CET130235732141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:39.215308905 CET357321302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:39.216047049 CET357321302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:39.220777035 CET130235732141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:39.220820904 CET357321302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:39.225568056 CET130235732141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:40.926245928 CET130235732141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:40.926417112 CET357321302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:40.931813955 CET130235732141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:41.927917957 CET357341302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:41.932821035 CET130235734141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:41.932873964 CET357341302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:41.933681011 CET357341302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:41.938460112 CET130235734141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:41.938503027 CET357341302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:41.943394899 CET130235734141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:43.667428970 CET130235734141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:43.667814970 CET357341302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:43.672643900 CET130235734141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:44.670252085 CET357361302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:44.675064087 CET130235736141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:44.675318003 CET357361302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:44.681385040 CET357361302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:44.686182976 CET130235736141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:44.686253071 CET357361302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:44.691003084 CET130235736141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:46.380573034 CET130235736141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:46.380851030 CET357361302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:46.385701895 CET130235736141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:47.383035898 CET357381302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:47.387839079 CET130235738141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:47.387948036 CET357381302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:47.389082909 CET357381302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:47.393847942 CET130235738141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:47.393908024 CET357381302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:47.398663998 CET130235738141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:49.082031012 CET130235738141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:49.082565069 CET357381302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:49.087487936 CET130235738141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:50.089194059 CET357401302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:50.094150066 CET130235740141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:50.094232082 CET357401302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:50.095438004 CET357401302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:50.100330114 CET130235740141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:50.100399017 CET357401302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:50.105282068 CET130235740141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:51.803163052 CET130235740141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:51.803555012 CET357401302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:51.808418036 CET130235740141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:52.805871010 CET357421302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:52.812226057 CET130235742141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:52.812315941 CET357421302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:52.813039064 CET357421302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:52.820015907 CET130235742141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:52.820065022 CET357421302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:52.826348066 CET130235742141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:54.515391111 CET130235742141.98.10.115192.168.2.15
            Jan 8, 2025 17:12:54.515624046 CET357421302192.168.2.15141.98.10.115
            Jan 8, 2025 17:12:54.520529032 CET130235742141.98.10.115192.168.2.15

            System Behavior

            Start time (UTC):16:10:50
            Start date (UTC):08/01/2025
            Path:/tmp/uYtea.ppc.elf
            Arguments:/tmp/uYtea.ppc.elf
            File size:5388968 bytes
            MD5 hash:ae65271c943d3451b7f026d1fadccea6

            Start time (UTC):16:10:50
            Start date (UTC):08/01/2025
            Path:/tmp/uYtea.ppc.elf
            Arguments:-
            File size:5388968 bytes
            MD5 hash:ae65271c943d3451b7f026d1fadccea6

            Start time (UTC):16:10:50
            Start date (UTC):08/01/2025
            Path:/tmp/uYtea.ppc.elf
            Arguments:-
            File size:5388968 bytes
            MD5 hash:ae65271c943d3451b7f026d1fadccea6