Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
uYtea.sh4.elf

Overview

General Information

Sample name:uYtea.sh4.elf
Analysis ID:1586063
MD5:069fbbf0a4cdd68fab6c0733445fb034
SHA1:5da4773140d7fc9647f6e242cdac7326d616a441
SHA256:e5f39f8e23c8c9e3aabb9e28e0fee0c95eb016ffba00eafaab422005031ea94b
Tags:elfuser-abuse_ch
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Executes the "rm" command used to delete files or directories
Sample has stripped symbol table
Sample listens on a socket
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586063
Start date and time:2025-01-08 17:11:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 18s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:uYtea.sh4.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
  • VT rate limit hit for: uYtea.sh4.elf
Command:/tmp/uYtea.sh4.elf
PID:5420
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
connecterror
Standard Error:
  • system is lnxubuntu20
  • dash New Fork (PID: 5409, Parent: 3584)
  • rm (PID: 5409, Parent: 3584, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.7DwfFfjEOn /tmp/tmp.x5ACcSxd2f /tmp/tmp.igA6F5YGUY
  • dash New Fork (PID: 5410, Parent: 3584)
  • rm (PID: 5410, Parent: 3584, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.7DwfFfjEOn /tmp/tmp.x5ACcSxd2f /tmp/tmp.igA6F5YGUY
  • uYtea.sh4.elf (PID: 5420, Parent: 5343, MD5: 8943e5f8f8c280467b4472c15ae93ba9) Arguments: /tmp/uYtea.sh4.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
uYtea.sh4.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xaa24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaab0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaac4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaad8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaaec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaba0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xabb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5424.1.00007fec40400000.00007fec4040d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xaa24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaab0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaac4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaad8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaaec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaba0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xabb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5420.1.00007fec40400000.00007fec4040d000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xaa24:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa38:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa4c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa60:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa74:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa88:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaa9c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaab0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaac4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaad8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaaec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab00:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab14:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab28:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab3c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab50:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab64:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab78:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xab8c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xaba0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xabb4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.sh4.elf PID: 5420Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x17b0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17c4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17d8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x17ec:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1800:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1814:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1828:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x183c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1850:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1864:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1878:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x188c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1904:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1918:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x192c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1940:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.sh4.elf PID: 5424Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x18ce:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18e2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x18f6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x190a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x191e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1932:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1946:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x195a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x196e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1982:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1996:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x19aa:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x19be:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x19d2:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x19e6:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x19fa:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1a0e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1a22:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1a36:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1a4a:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x1a5e:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: uYtea.sh4.elfAvira: detected
Source: uYtea.sh4.elfReversingLabs: Detection: 63%
Source: global trafficTCP traffic: 192.168.2.13:57668 -> 141.98.10.115:1302
Source: /tmp/uYtea.sh4.elf (PID: 5420)Socket: 127.0.0.1:9473Jump to behavior
Source: global trafficTCP traffic: 192.168.2.13:48202 -> 185.125.190.26:443
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownTCP traffic detected without corresponding DNS query: 185.125.190.26
Source: unknownNetwork traffic detected: HTTP traffic on port 48202 -> 443

System Summary

barindex
Source: uYtea.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5424.1.00007fec40400000.00007fec4040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5420.1.00007fec40400000.00007fec4040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.sh4.elf PID: 5420, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.sh4.elf PID: 5424, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: uYtea.sh4.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5424.1.00007fec40400000.00007fec4040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5420.1.00007fec40400000.00007fec4040d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.sh4.elf PID: 5420, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.sh4.elf PID: 5424, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
Source: /tmp/uYtea.sh4.elf (PID: 5422)Directory: /tmp/.Jump to behavior
Source: /tmp/uYtea.sh4.elf (PID: 5422)Directory: /tmp/..Jump to behavior
Source: /usr/bin/dash (PID: 5409)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.7DwfFfjEOn /tmp/tmp.x5ACcSxd2f /tmp/tmp.igA6F5YGUYJump to behavior
Source: /usr/bin/dash (PID: 5410)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.7DwfFfjEOn /tmp/tmp.x5ACcSxd2f /tmp/tmp.igA6F5YGUYJump to behavior
Source: /tmp/uYtea.sh4.elf (PID: 5420)Queries kernel information via 'uname': Jump to behavior
Source: uYtea.sh4.elf, 5420.1.00007ffd328fa000.00007ffd3291b000.rw-.sdmp, uYtea.sh4.elf, 5424.1.00007ffd328fa000.00007ffd3291b000.rw-.sdmpBinary or memory string: /usr/bin/qemu-sh4
Source: uYtea.sh4.elf, 5420.1.0000564f8ff5f000.0000564f8ffc2000.rw-.sdmp, uYtea.sh4.elf, 5424.1.0000564f8ff5f000.0000564f8ffc2000.rw-.sdmpBinary or memory string: OV5!/etc/qemu-binfmt/sh4
Source: uYtea.sh4.elf, 5420.1.0000564f8ff5f000.0000564f8ffc2000.rw-.sdmp, uYtea.sh4.elf, 5424.1.0000564f8ff5f000.0000564f8ffc2000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/sh4
Source: uYtea.sh4.elf, 5420.1.00007ffd328fa000.00007ffd3291b000.rw-.sdmp, uYtea.sh4.elf, 5424.1.00007ffd328fa000.00007ffd3291b000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-sh4/tmp/uYtea.sh4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/uYtea.sh4.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
File Deletion
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Standard Port
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1586063 Sample: uYtea.sh4.elf Startdate: 08/01/2025 Architecture: LINUX Score: 64 16 141.98.10.115, 1302, 57668, 57670 HOSTBALTICLT Lithuania 2->16 18 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->18 20 Malicious sample detected (through community Yara rule) 2->20 22 Antivirus / Scanner detection for submitted sample 2->22 24 Multi AV Scanner detection for submitted file 2->24 8 dash rm uYtea.sh4.elf 2->8         started        10 dash rm 2->10         started        signatures3 process4 process5 12 uYtea.sh4.elf 8->12         started        process6 14 uYtea.sh4.elf 12->14         started       
SourceDetectionScannerLabelLink
uYtea.sh4.elf63%ReversingLabsLinux.Trojan.Mirai
uYtea.sh4.elf100%AviraEXP/ELF.Mirai.Z.D
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
141.98.10.115
unknownLithuania
209605HOSTBALTICLTfalse
185.125.190.26
unknownUnited Kingdom
41231CANONICAL-ASGBfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
141.98.10.115uYtea.ppc.elfGet hashmaliciousUnknownBrowse
    uYtea.x86.elfGet hashmaliciousUnknownBrowse
      uYtea.arm.elfGet hashmaliciousUnknownBrowse
        uYtea.mips.elfGet hashmaliciousUnknownBrowse
          uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
            uYtea.arm7.elfGet hashmaliciousMiraiBrowse
              185.125.190.26uYtea.arc.elfGet hashmaliciousMiraiBrowse
                386.elfGet hashmaliciousUnknownBrowse
                  main_arm5.elfGet hashmaliciousMiraiBrowse
                    gigops.mpsl.elfGet hashmaliciousGafgytBrowse
                      94.156.227.153-sora.arm5-2025-01-07T16_09_13.elfGet hashmaliciousMiraiBrowse
                        94.156.227.153-sora.m68k-2025-01-07T16_09_14.elfGet hashmaliciousMiraiBrowse
                          la.bot.powerpc.elfGet hashmaliciousMiraiBrowse
                            arm.elfGet hashmaliciousMiraiBrowse
                              arm7.elfGet hashmaliciousMiraiBrowse
                                arm6.elfGet hashmaliciousMiraiBrowse
                                  No context
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  CANONICAL-ASGBuYtea.x86.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  uYtea.arc.elfGet hashmaliciousMiraiBrowse
                                  • 185.125.190.26
                                  uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  main_x86_64.elfGet hashmaliciousMiraiBrowse
                                  • 91.189.91.42
                                  Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  main_m68k.elfGet hashmaliciousMiraiBrowse
                                  • 91.189.91.42
                                  main_arm5.elfGet hashmaliciousMiraiBrowse
                                  • 91.189.91.42
                                  mips64.elfGet hashmaliciousUnknownBrowse
                                  • 91.189.91.42
                                  386.elfGet hashmaliciousUnknownBrowse
                                  • 185.125.190.26
                                  HOSTBALTICLTuYtea.ppc.elfGet hashmaliciousUnknownBrowse
                                  • 141.98.10.115
                                  uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                  • 141.98.10.115
                                  uYtea.arm.elfGet hashmaliciousUnknownBrowse
                                  • 141.98.10.115
                                  uYtea.mips.elfGet hashmaliciousUnknownBrowse
                                  • 141.98.10.115
                                  uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                  • 141.98.10.115
                                  uYtea.arm7.elfGet hashmaliciousMiraiBrowse
                                  • 141.98.10.115
                                  Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                  • 141.98.10.88
                                  Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                  • 141.98.10.88
                                  Scan112024.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                  • 141.98.10.88
                                  173127133603e75602cf90c03b229cc07ec4f5c026cad2909c809b767b293bf800a0e9ade9674.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                  • 141.98.10.88
                                  No context
                                  No context
                                  No created / dropped files found
                                  File type:ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
                                  Entropy (8bit):6.702592652266525
                                  TrID:
                                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                  File name:uYtea.sh4.elf
                                  File size:55'568 bytes
                                  MD5:069fbbf0a4cdd68fab6c0733445fb034
                                  SHA1:5da4773140d7fc9647f6e242cdac7326d616a441
                                  SHA256:e5f39f8e23c8c9e3aabb9e28e0fee0c95eb016ffba00eafaab422005031ea94b
                                  SHA512:b9e7229c87efd48504431a163bff5ebc37aa56b566db880f629671552bb03d4d38a5b268c12c3c867099db2d3ecdbe67a11daaf3a12465ca1844262b9cf73b9a
                                  SSDEEP:768:f3Dm+BLr3pN3b3xMmWQZ7YnYhJ2wGQDmhMOfIA1eCHo1Y4dbC2WwJZY10U:bm+JDpP/Z7VrGQDvA1eb1dbC2PJa10
                                  TLSH:5D438EB4E42A9D54D0850174A8748F750FA3F2C883621DF73BAA46B1540BEB9F60DFE5
                                  File Content Preview:.ELF..............*.......@.4...........4. ...(...............@...@...........................A...A.@...,J..........Q.td............................././"O.n........#.*@........#.*@.....o&O.n...l..............................././.../.a"O.!...n...a.b("...q.

                                  ELF header

                                  Class:ELF32
                                  Data:2's complement, little endian
                                  Version:1 (current)
                                  Machine:<unknown>
                                  Version Number:0x1
                                  Type:EXEC (Executable file)
                                  OS/ABI:UNIX - System V
                                  ABI Version:0
                                  Entry Point Address:0x4001a0
                                  Flags:0x9
                                  ELF Header Size:52
                                  Program Header Offset:52
                                  Program Header Size:32
                                  Number of Program Headers:3
                                  Section Header Offset:55168
                                  Section Header Size:40
                                  Number of Section Headers:10
                                  Header String Table Index:9
                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                  NULL0x00x00x00x00x0000
                                  .initPROGBITS0x4000940x940x300x00x6AX004
                                  .textPROGBITS0x4000e00xe00xa9200x00x6AX0032
                                  .finiPROGBITS0x40aa000xaa000x240x00x6AX004
                                  .rodataPROGBITS0x40aa240xaa240x1f8c0x00x2A004
                                  .ctorsPROGBITS0x41d0000xd0000x80x00x3WA004
                                  .dtorsPROGBITS0x41d0080xd0080x80x00x3WA004
                                  .dataPROGBITS0x41d0140xd0140x72c0x00x3WA004
                                  .bssNOBITS0x41d7400xd7400x42ec0x00x3WA004
                                  .shstrtabSTRTAB0x00xd7400x3e0x00x0001
                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                  LOAD0x00x4000000x4000000xc9b00xc9b06.86590x5R E0x10000.init .text .fini .rodata
                                  LOAD0xd0000x41d0000x41d0000x7400x4a2c4.35250x6RW 0x10000.ctors .dtors .data .bss
                                  GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                  TimestampSource PortDest PortSource IPDest IP
                                  Jan 8, 2025 17:11:53.281183958 CET576681302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:53.286077976 CET130257668141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:53.286170006 CET576681302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:53.287164927 CET576681302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:53.291944981 CET130257668141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:53.292016983 CET576681302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:53.296824932 CET130257668141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:55.053713083 CET130257668141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:55.054069996 CET576681302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:55.058861017 CET130257668141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:56.055903912 CET576701302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:56.060739994 CET130257670141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:56.060837030 CET576701302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:56.061635971 CET576701302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:56.066380978 CET130257670141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:56.066478968 CET576701302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:56.074959040 CET130257670141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:57.823518991 CET130257670141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:57.823684931 CET576701302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:57.828572989 CET130257670141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:58.170223951 CET48202443192.168.2.13185.125.190.26
                                  Jan 8, 2025 17:11:58.825404882 CET576721302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:58.830275059 CET130257672141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:58.830343962 CET576721302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:58.831175089 CET576721302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:58.835952044 CET130257672141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:11:58.836004972 CET576721302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:11:58.840801001 CET130257672141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:00.533278942 CET130257672141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:00.533458948 CET576721302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:00.538305998 CET130257672141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:01.535151005 CET576741302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:01.540446043 CET130257674141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:01.540508986 CET576741302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:01.541356087 CET576741302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:01.546747923 CET130257674141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:01.546796083 CET576741302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:01.551561117 CET130257674141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:03.235670090 CET130257674141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:03.236042023 CET576741302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:03.240812063 CET130257674141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:04.238147020 CET576761302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:04.242921114 CET130257676141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:04.243036985 CET576761302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:04.244206905 CET576761302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:04.248960972 CET130257676141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:04.249026060 CET576761302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:04.253835917 CET130257676141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:06.051486015 CET130257676141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:06.051650047 CET576761302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:06.056446075 CET130257676141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:07.053304911 CET576781302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:07.058131933 CET130257678141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:07.058186054 CET576781302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:07.058916092 CET576781302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:07.063657999 CET130257678141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:07.063699961 CET576781302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:07.068475008 CET130257678141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:08.759243011 CET130257678141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:08.759396076 CET576781302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:08.764796972 CET130257678141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:09.761362076 CET576801302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:09.766153097 CET130257680141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:09.766227961 CET576801302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:09.767379999 CET576801302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:09.772161007 CET130257680141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:09.772218943 CET576801302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:09.777014971 CET130257680141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:11.645770073 CET130257680141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:11.645978928 CET576801302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:11.650747061 CET130257680141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:12.648367882 CET576821302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:12.653167009 CET130257682141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:12.653263092 CET576821302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:12.654459953 CET576821302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:12.659234047 CET130257682141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:12.659281015 CET576821302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:12.664037943 CET130257682141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:14.359055042 CET130257682141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:14.359502077 CET576821302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:14.364433050 CET130257682141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:15.361965895 CET576841302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:15.366847038 CET130257684141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:15.366924047 CET576841302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:15.368015051 CET576841302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:15.372823954 CET130257684141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:15.372880936 CET576841302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:15.377649069 CET130257684141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:17.047647953 CET130257684141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:17.047821045 CET576841302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:17.052647114 CET130257684141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:18.049315929 CET576861302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:18.055116892 CET130257686141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:18.055203915 CET576861302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:18.056065083 CET576861302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:18.061796904 CET130257686141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:18.061841011 CET576861302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:18.067358971 CET130257686141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:19.784120083 CET130257686141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:19.784401894 CET576861302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:19.789320946 CET130257686141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:20.786773920 CET576881302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:20.791591883 CET130257688141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:20.791644096 CET576881302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:20.792363882 CET576881302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:20.797076941 CET130257688141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:20.797125101 CET576881302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:20.801848888 CET130257688141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:22.522120953 CET130257688141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:22.522319078 CET576881302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:22.527118921 CET130257688141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:23.523853064 CET576901302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:23.528722048 CET130257690141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:23.528778076 CET576901302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:23.529508114 CET576901302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:23.534271002 CET130257690141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:23.534313917 CET576901302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:23.539083958 CET130257690141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:25.218249083 CET130257690141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:25.218410969 CET576901302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:25.223278046 CET130257690141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:26.220141888 CET576921302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:26.224951029 CET130257692141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:26.225028992 CET576921302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:26.226125956 CET576921302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:26.230875015 CET130257692141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:26.230935097 CET576921302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:26.235718966 CET130257692141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:27.922929049 CET130257692141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:27.923085928 CET576921302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:27.927891016 CET130257692141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:28.924988031 CET576941302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:28.929826975 CET130257694141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:28.929896116 CET576941302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:28.930876017 CET576941302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:28.935697079 CET130257694141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:28.935750961 CET576941302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:28.940498114 CET130257694141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:29.146106005 CET48202443192.168.2.13185.125.190.26
                                  Jan 8, 2025 17:12:30.657321930 CET130257694141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:30.657474995 CET576941302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:30.662328005 CET130257694141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:31.659360886 CET576961302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:31.664288998 CET130257696141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:31.664339066 CET576961302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:31.665067911 CET576961302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:31.669925928 CET130257696141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:31.669977903 CET576961302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:31.878117085 CET576961302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:31.964704990 CET130257696141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:31.964711905 CET130257696141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:33.363214970 CET130257696141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:33.363631964 CET576961302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:33.368463039 CET130257696141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:34.365963936 CET576981302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:34.370800972 CET130257698141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:34.370863914 CET576981302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:34.371619940 CET576981302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:34.376419067 CET130257698141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:34.376468897 CET576981302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:34.381200075 CET130257698141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:36.153367043 CET130257698141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:36.153546095 CET576981302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:36.158298969 CET130257698141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:37.155805111 CET577001302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:37.160665989 CET130257700141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:37.160721064 CET577001302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:37.161431074 CET577001302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:37.166224957 CET130257700141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:37.166289091 CET577001302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:37.171041965 CET130257700141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:38.864902020 CET130257700141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:38.865165949 CET577001302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:38.869983912 CET130257700141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:39.867748022 CET577021302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:39.872560024 CET130257702141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:39.872615099 CET577021302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:39.873486042 CET577021302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:39.878268003 CET130257702141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:39.878310919 CET577021302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:39.883050919 CET130257702141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:41.582921982 CET130257702141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:41.583235979 CET577021302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:41.588151932 CET130257702141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:42.584841013 CET577041302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:42.589759111 CET130257704141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:42.589812994 CET577041302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:42.590682030 CET577041302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:42.595473051 CET130257704141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:42.595514059 CET577041302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:42.600271940 CET130257704141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:44.318447113 CET130257704141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:44.318697929 CET577041302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:44.323523045 CET130257704141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:45.320456028 CET577061302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:45.325329065 CET130257706141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:45.325377941 CET577061302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:45.326199055 CET577061302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:45.330949068 CET130257706141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:45.330992937 CET577061302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:45.335760117 CET130257706141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:47.033018112 CET130257706141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:47.033262014 CET577061302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:47.038136959 CET130257706141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:48.035294056 CET577081302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:48.040127039 CET130257708141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:48.040179968 CET577081302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:48.040889978 CET577081302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:48.045691013 CET130257708141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:48.045757055 CET577081302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:48.050513983 CET130257708141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:49.736524105 CET130257708141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:49.736749887 CET577081302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:49.742136002 CET130257708141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:50.738276005 CET577101302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:50.743133068 CET130257710141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:50.743180037 CET577101302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:50.743954897 CET577101302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:50.748718023 CET130257710141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:50.748778105 CET577101302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:50.753604889 CET130257710141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:52.438649893 CET130257710141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:52.438808918 CET577101302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:52.443598986 CET130257710141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:53.440321922 CET577121302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:53.445137024 CET130257712141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:53.445183039 CET577121302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:53.445966005 CET577121302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:53.450728893 CET130257712141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:53.450771093 CET577121302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:53.455600977 CET130257712141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:55.160346985 CET130257712141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:55.160572052 CET577121302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:55.165370941 CET130257712141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:56.162476063 CET577141302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:56.167241096 CET130257714141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:56.167288065 CET577141302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:56.168011904 CET577141302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:56.172766924 CET130257714141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:56.172808886 CET577141302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:56.177603960 CET130257714141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:57.937045097 CET130257714141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:57.937176943 CET577141302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:57.941963911 CET130257714141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:58.938711882 CET577161302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:58.943598986 CET130257716141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:58.943653107 CET577161302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:58.944425106 CET577161302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:58.949208021 CET130257716141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:12:58.949291945 CET577161302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:12:58.954061031 CET130257716141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:00.766927004 CET130257716141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:00.767075062 CET577161302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:00.771908045 CET130257716141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:01.768894911 CET577181302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:01.773708105 CET130257718141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:01.773787975 CET577181302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:01.774482965 CET577181302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:01.779196978 CET130257718141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:01.779264927 CET577181302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:01.784048080 CET130257718141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:03.486877918 CET130257718141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:03.487147093 CET577181302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:03.491936922 CET130257718141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:04.488986015 CET577201302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:04.493819952 CET130257720141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:04.493865967 CET577201302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:04.494582891 CET577201302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:04.499342918 CET130257720141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:04.499380112 CET577201302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:04.504117012 CET130257720141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:06.192898035 CET130257720141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:06.193206072 CET577201302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:06.198065996 CET130257720141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:07.195063114 CET577221302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:07.199887991 CET130257722141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:07.199942112 CET577221302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:07.200608015 CET577221302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:07.205400944 CET130257722141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:07.205466986 CET577221302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:07.210201025 CET130257722141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:08.909399986 CET130257722141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:08.909607887 CET577221302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:08.914433956 CET130257722141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:09.911681890 CET577241302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:09.916583061 CET130257724141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:09.916676998 CET577241302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:09.918243885 CET577241302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:09.923059940 CET130257724141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:09.923121929 CET577241302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:09.927923918 CET130257724141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:11.647008896 CET130257724141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:11.647285938 CET577241302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:11.652076960 CET130257724141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:12.649892092 CET577261302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:12.654845953 CET130257726141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:12.654927969 CET577261302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:12.656338930 CET577261302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:12.661143064 CET130257726141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:12.661216974 CET577261302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:12.666049004 CET130257726141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:14.364157915 CET130257726141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:14.364445925 CET577261302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:14.369246006 CET130257726141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:15.368820906 CET577281302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:15.373683929 CET130257728141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:15.373852968 CET577281302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:15.374548912 CET577281302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:15.379400969 CET130257728141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:15.379550934 CET577281302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:15.384346008 CET130257728141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:17.080610037 CET130257728141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:17.080894947 CET577281302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:17.085752964 CET130257728141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:18.083012104 CET577301302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:18.087833881 CET130257730141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:18.087888002 CET577301302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:18.088902950 CET577301302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:18.093679905 CET130257730141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:18.093755007 CET577301302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:18.098526001 CET130257730141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:19.766519070 CET130257730141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:19.766928911 CET577301302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:19.771852970 CET130257730141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:20.769331932 CET577321302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:20.775511980 CET130257732141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:20.775712013 CET577321302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:20.776860952 CET577321302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:20.786520958 CET130257732141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:20.786592007 CET577321302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:20.793824911 CET130257732141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:22.471441984 CET130257732141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:22.471822977 CET577321302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:22.476671934 CET130257732141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:23.474225044 CET577341302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:23.479155064 CET130257734141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:23.479233027 CET577341302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:23.480412960 CET577341302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:23.485199928 CET130257734141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:23.485279083 CET577341302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:23.490075111 CET130257734141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:25.195580959 CET130257734141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:25.195740938 CET577341302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:25.200539112 CET130257734141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:26.197280884 CET577361302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:26.202217102 CET130257736141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:26.202270985 CET577361302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:26.202925920 CET577361302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:26.207725048 CET130257736141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:26.207767963 CET577361302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:26.212606907 CET130257736141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:27.913171053 CET130257736141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:27.913413048 CET577361302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:27.918241978 CET130257736141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:28.915807009 CET577381302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:28.920634985 CET130257738141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:28.920766115 CET577381302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:28.921411037 CET577381302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:28.926172972 CET130257738141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:28.926248074 CET577381302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:28.931061983 CET130257738141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:30.626058102 CET130257738141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:30.626295090 CET577381302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:30.631107092 CET130257738141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:31.628715038 CET577401302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:31.633548021 CET130257740141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:31.633629084 CET577401302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:31.634727955 CET577401302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:31.639554977 CET130257740141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:31.639630079 CET577401302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:31.644427061 CET130257740141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:33.313762903 CET130257740141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:33.313985109 CET577401302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:33.318803072 CET130257740141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:34.316569090 CET577421302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:34.321419001 CET130257742141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:34.321736097 CET577421302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:34.322438002 CET577421302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:34.327188015 CET130257742141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:34.327280998 CET577421302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:34.332068920 CET130257742141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:36.021244049 CET130257742141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:36.021672964 CET577421302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:36.026462078 CET130257742141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:37.023937941 CET577441302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:37.028815031 CET130257744141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:37.028953075 CET577441302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:37.029669046 CET577441302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:37.034473896 CET130257744141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:37.034547091 CET577441302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:37.039352894 CET130257744141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:38.772559881 CET130257744141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:38.773118019 CET577441302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:38.778004885 CET130257744141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:39.777808905 CET577461302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:39.782780886 CET130257746141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:39.782886982 CET577461302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:39.784240007 CET577461302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:39.789011955 CET130257746141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:39.789083004 CET577461302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:39.793898106 CET130257746141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:41.489691019 CET130257746141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:41.489866018 CET577461302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:41.494720936 CET130257746141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:42.492516994 CET577481302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:42.497416019 CET130257748141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:42.497545958 CET577481302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:42.499486923 CET577481302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:42.504342079 CET130257748141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:42.504410028 CET577481302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:42.509180069 CET130257748141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:44.404148102 CET130257748141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:44.404669046 CET577481302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:44.409486055 CET130257748141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:45.406708956 CET577501302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:45.411623955 CET130257750141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:45.411679029 CET577501302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:45.412377119 CET577501302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:45.417125940 CET130257750141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:45.417171001 CET577501302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:45.421921968 CET130257750141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:47.132925987 CET130257750141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:47.133207083 CET577501302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:47.137993097 CET130257750141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:48.135107994 CET577521302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:48.140052080 CET130257752141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:48.140094042 CET577521302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:48.140650988 CET577521302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:48.145359993 CET130257752141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:48.145392895 CET577521302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:48.150154114 CET130257752141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:49.844919920 CET130257752141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:49.845174074 CET577521302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:49.850008965 CET130257752141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:50.847491026 CET577541302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:50.852365017 CET130257754141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:50.852535009 CET577541302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:50.853650093 CET577541302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:50.858411074 CET130257754141.98.10.115192.168.2.13
                                  Jan 8, 2025 17:13:50.858458996 CET577541302192.168.2.13141.98.10.115
                                  Jan 8, 2025 17:13:50.863311052 CET130257754141.98.10.115192.168.2.13

                                  System Behavior

                                  Start time (UTC):16:11:39
                                  Start date (UTC):08/01/2025
                                  Path:/usr/bin/dash
                                  Arguments:-
                                  File size:129816 bytes
                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                  Start time (UTC):16:11:39
                                  Start date (UTC):08/01/2025
                                  Path:/usr/bin/rm
                                  Arguments:rm -f /tmp/tmp.7DwfFfjEOn /tmp/tmp.x5ACcSxd2f /tmp/tmp.igA6F5YGUY
                                  File size:72056 bytes
                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                  Start time (UTC):16:11:39
                                  Start date (UTC):08/01/2025
                                  Path:/usr/bin/dash
                                  Arguments:-
                                  File size:129816 bytes
                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                  Start time (UTC):16:11:39
                                  Start date (UTC):08/01/2025
                                  Path:/usr/bin/rm
                                  Arguments:rm -f /tmp/tmp.7DwfFfjEOn /tmp/tmp.x5ACcSxd2f /tmp/tmp.igA6F5YGUY
                                  File size:72056 bytes
                                  MD5 hash:aa2b5496fdbfd88e38791ab81f90b95b

                                  Start time (UTC):16:11:45
                                  Start date (UTC):08/01/2025
                                  Path:/tmp/uYtea.sh4.elf
                                  Arguments:/tmp/uYtea.sh4.elf
                                  File size:4139976 bytes
                                  MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                  Start time (UTC):16:11:45
                                  Start date (UTC):08/01/2025
                                  Path:/tmp/uYtea.sh4.elf
                                  Arguments:-
                                  File size:4139976 bytes
                                  MD5 hash:8943e5f8f8c280467b4472c15ae93ba9

                                  Start time (UTC):16:11:45
                                  Start date (UTC):08/01/2025
                                  Path:/tmp/uYtea.sh4.elf
                                  Arguments:-
                                  File size:4139976 bytes
                                  MD5 hash:8943e5f8f8c280467b4472c15ae93ba9