Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.mpsl.elf

Overview

General Information

Sample name:dlr.mpsl.elf
Analysis ID:1586103
MD5:bcd78981c1474e8a11b1ad5d5e93dd10
SHA1:9d3dbeed8388fab8fb12a440cf2e8d811ec87872
SHA256:061c6c1a2ff31f6d639592c9c881e9ce1a10926c1850e3bc1a82c5ae468ae931
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Antivirus detection for dropped file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586103
Start date and time:2025-01-08 18:02:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 22s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.mpsl.elf
Detection:MAL
Classification:mal48.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
  • VT rate limit hit for: dlr.mpsl.elf
Command:/tmp/dlr.mpsl.elf
PID:5429
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
AAA
BAH
Standard Error:
  • system is lnxubuntu20
  • dlr.mpsl.elf (PID: 5429, Parent: 5354, MD5: 0d6f61f82cf2f781c6eb0661071d42d9) Arguments: /tmp/dlr.mpsl.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: /tmp/345Avira: detection malicious, Label: EXP/ELF.Mirai.Hua.a
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: global trafficHTTP traffic detected: GET /2 HTTP/1.1Host: 127.0.0.1Connection: closeUser-Agent: wget (dlr)
Source: 345.12.drString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: 345.12.drString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/1@0/0
Source: /tmp/dlr.mpsl.elf (PID: 5429)File written: /tmp/345Jump to dropped file
Source: /tmp/dlr.mpsl.elf (PID: 5429)Queries kernel information via 'uname': Jump to behavior
Source: dlr.mpsl.elf, 5429.1.0000555f7897d000.0000555f78a04000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mipsel
Source: dlr.mpsl.elf, 5429.1.0000555f7897d000.0000555f78a04000.rw-.sdmpBinary or memory string: x_U!/etc/qemu-binfmt/mipsel
Source: dlr.mpsl.elf, 5429.1.00007fffc2f46000.00007fffc2f67000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/dlr.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.mpsl.elf
Source: dlr.mpsl.elf, 5429.1.00007fffc2f46000.00007fffc2f67000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mipsel
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
dlr.mpsl.elf3%ReversingLabsLinux.Downloader.Generic
SourceDetectionScannerLabelLink
/tmp/345100%AviraEXP/ELF.Mirai.Hua.a
No Antivirus matches
SourceDetectionScannerLabelLink
http://127.0.0.1/20%Avira URL Cloudsafe
No contacted domains info
NameMaliciousAntivirus DetectionReputation
http://127.0.0.1/2false
  • Avira URL Cloud: safe
unknown
NameSourceMaliciousAntivirus DetectionReputation
http://schemas.xmlsoap.org/soap/encoding/345.12.drfalse
    high
    http://schemas.xmlsoap.org/soap/envelope/345.12.drfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      103.136.41.100
      unknownIndia
      139884AGPL-AS-APApeironGlobalPvtLtdINfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      103.136.41.100qkOFMWXZmrGet hashmaliciousUnknownBrowse
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        AGPL-AS-APApeironGlobalPvtLtdIN2461ACFA271F7D477CA53ABE428D6ADDE1F285E115F18.exeGet hashmaliciousFFDroiderBrowse
        • 103.136.41.162
        wYWdigdSjn.exeGet hashmaliciousNeshtaBrowse
        • 103.136.42.153
        38b2c7a1af454d382927f81543d86055886bc02863457.exeGet hashmaliciousUnknownBrowse
        • 103.136.42.153
        l39HA25qjw.exeGet hashmaliciousManusCrypt, SocelarsBrowse
        • 103.136.42.153
        SecuriteInfo.com.Win32.Malware-gen.30674.exeGet hashmaliciousUnknownBrowse
        • 103.136.42.153
        file.exeGet hashmaliciousFFDroiderBrowse
        • 103.136.42.153
        qkOFMWXZmrGet hashmaliciousUnknownBrowse
        • 103.136.41.100
        njE4JoXEp6Get hashmaliciousUnknownBrowse
        • 103.136.41.110
        qICLEK5VROGet hashmaliciousUnknownBrowse
        • 103.136.41.110
        qaE0C9rclbGet hashmaliciousUnknownBrowse
        • 103.136.41.110
        No context
        No context
        Process:/tmp/dlr.mpsl.elf
        File Type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
        Category:dropped
        Size (bytes):104176
        Entropy (8bit):5.530002614237804
        Encrypted:false
        SSDEEP:1536:CsKiAkifLt/sGgxKYbaKO3rYcaYGgikBNPYnj06e0Qo8jb:CsKiAkizRsGSKYbqYMd
        MD5:90D45B5ED746C7F1624D0461562C33A6
        SHA1:F339F2356808C11BD29EEC24F743AB29E4B8A16B
        SHA-256:50BF892BF688AED713FFD21B3CAC7A2A35E543CDAC3CC0B083EFB47C14E03794
        SHA-512:C02575EF1463A00FF62F4A5FBD331FF6D562E42E3E767F74D3CF821015C8D9046F1A5A3DC2DAD754F51958C2535AD8EF726EC0FC8D29650FD6D8BA821A23819F
        Malicious:true
        Antivirus:
        • Antivirus: Avira, Detection: 100%
        Reputation:low
        Preview:.ELF....................p.@.4...........4. ...(...............@...@.`...`...............`...`.E.`.E.....83..........Q.td...............................<...'!......'.......................<h..'!.............9'.. ........................<8..'!... ........q9'.. ......................... ..'...<...'!......' .......................@.".......@.......................Y....... ...B$.. ...............Y....... ...B$..........@....$.............. .`..$.......$@.". ...............(..'...<D..'!......'........h.........@.............h...`..$.. .D..$................t.........@.....|......... .t..$...... . ..'............ ..'........!..............<...'!...!............'...$$.....'.................................. ............................<@..'!......'............................Y.@.! ......!(.... ....$........_.@............&!(.... ....$ .......d.@......... ..&!(.... ....$0.......i.@.........0..&!(.... ....$@.......n.@.........@..&!(.... ....$P.......s.@.........P..&!(.... ....$`.......x.@.....
        File type:ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
        Entropy (8bit):4.567140512903918
        TrID:
        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
        File name:dlr.mpsl.elf
        File size:11'676 bytes
        MD5:bcd78981c1474e8a11b1ad5d5e93dd10
        SHA1:9d3dbeed8388fab8fb12a440cf2e8d811ec87872
        SHA256:061c6c1a2ff31f6d639592c9c881e9ce1a10926c1850e3bc1a82c5ae468ae931
        SHA512:62a4c302e774a1f045d70cb8ecf427d70ba76e655a568da2015f6c4e67ab0f566c9fb144fd7a28246a987a08962ddbda8f39ee682f6586ee4dcbe70ca8109ad7
        SSDEEP:192:AUcdBx/gWJSAZZlMB2vb2Xi24ex0PJfAXJO4X4Cjf+rgzb:tcPx/gWrRMBhXi24ex0lmJO4X4CzK6
        TLSH:4232300BAF60DD37DC5FDC7305EA8B1024CDE8676164271A3130EAAC7A1B9874AD3DA4
        File Content Preview:.ELF......................@.4....*......4. ...(........p......@...@...........................@...@...................... ... D.. D.....P...........Q.td..................................................D....<...'!......'.......................<...'!......

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:MIPS R3000
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:UNIX - System V
        ABI Version:0
        Entry Point Address:0x4002b0
        Flags:0x1007
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:4
        Section Header Offset:10916
        Section Header Size:40
        Number of Section Headers:19
        Header String Table Index:18
        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .reginfoMIPS_REGINFO0x4000b40xb40x180x180x2A004
        .initPROGBITS0x4000cc0xcc0x8c0x00x6AX004
        .textPROGBITS0x4001600x1600x1bc00x00x6AX0016
        .finiPROGBITS0x401d200x1d200x5c0x00x6AX004
        .rodataPROGBITS0x401d800x1d800x22c0x00x2A0016
        .eh_framePROGBITS0x4420000x20000x40x00x3WA004
        .ctorsPROGBITS0x4420040x20040x80x00x3WA004
        .dtorsPROGBITS0x44200c0x200c0x80x00x3WA004
        .jcrPROGBITS0x4420140x20140x40x00x3WA004
        .dataPROGBITS0x4420200x20200x700x00x3WA0016
        .gotPROGBITS0x4420900x20900x1400x40x10000003WAp0016
        .sdataPROGBITS0x4421d00x21d00x40x00x10000003WAp004
        .sbssNOBITS0x4421d40x21d40x80x00x10000003WAp004
        .bssNOBITS0x4421e00x21d40x700x00x3WA0016
        .commentPROGBITS0x00x21d40x20a0x00x0001
        .mdebug.abi32PROGBITS0x20a0x23de0x00x00x0001
        .pdrPROGBITS0x00x23e00x6400x00x0004
        .shstrtabSTRTAB0x00x2a200x840x00x0001
        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        <unknown>0xb40x4000b40x4000b40x180x180.98340x4R 0x4.reginfo
        LOAD0x00x4000000x4000000x1fac0x1fac4.89420x5R E0x10000.reginfo .init .text .fini .rodata
        LOAD0x20000x4420000x4420000x1d40x2503.00450x6RW 0x10000.eh_frame .ctors .dtors .jcr .data .got .sdata .sbss .bss
        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
        TimestampSource PortDest PortSource IPDest IP
        Jan 8, 2025 18:02:48.109560013 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.115320921 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.115411997 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.116590977 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.121346951 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734803915 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734827995 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734842062 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734855890 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734869003 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734880924 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734894991 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734908104 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734920025 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734937906 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.734942913 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.734942913 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.734942913 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.734983921 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.734983921 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.739882946 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.739923000 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.739939928 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.739953041 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.739974022 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.739974022 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.826381922 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.826397896 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.826410055 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.826423883 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.826436043 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.826450109 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.826459885 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.826482058 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.826482058 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.826482058 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.826503038 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.829428911 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829442024 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829454899 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829467058 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829468966 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.829468966 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.829479933 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829483986 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.829490900 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829505920 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829516888 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829535007 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829581022 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829593897 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829605103 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829615116 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829627991 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829639912 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829652071 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.829672098 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.830837011 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.831995964 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.875235081 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.916412115 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.916429043 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.916441917 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.916503906 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.916527033 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.916539907 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.916551113 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917002916 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917018890 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917177916 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917191029 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917203903 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917325974 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917339087 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.917351961 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.918267012 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.918286085 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.918298960 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.918312073 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.918323994 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.918438911 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.918811083 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.919270039 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.919281960 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.919294119 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.919307947 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.919326067 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.919337988 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.920157909 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.920171022 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.920181990 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.920193911 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.920306921 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.920320034 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.920752048 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.921089888 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.921103001 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.921120882 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.921232939 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.921247959 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.921261072 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.921896935 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.922082901 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.922094107 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.922103882 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.922115088 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.922126055 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.922651052 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.922979116 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.922991037 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.923002005 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:48.924566984 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:48.994158983 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:49.006681919 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006697893 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006716013 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006727934 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006737947 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006812096 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006824970 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006836891 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.006917953 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:49.006922007 CET8050808103.136.41.100192.168.2.13
        Jan 8, 2025 18:02:49.032464981 CET5080880192.168.2.13103.136.41.100
        Jan 8, 2025 18:02:49.037261963 CET8050808103.136.41.100192.168.2.13
        • 127.0.0.1
        Session IDSource IPSource PortDestination IPDestination Port
        0192.168.2.1350808103.136.41.10080
        TimestampBytes transferredDirectionData
        Jan 8, 2025 18:02:48.116590977 CET91OUTGET /2 HTTP/1.1
        Host: 127.0.0.1
        Connection: close
        User-Agent: wget (dlr)
        Jan 8, 2025 18:02:48.734803915 CET1236INHTTP/1.1 200 OK
        Accept-Ranges: bytes
        Content-Length: 104176
        Content-Type: application/octet-stream
        Last-Modified: Wed, 08 Jan 2025 16:59:29 GMT
        Date: Wed, 08 Jan 2025 17:02:48 GMT
        Connection: close
        Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 08 00 01 00 00 00 70 02 40 00 34 00 00 00 98 94 01 00 07 10 00 00 34 00 20 00 03 00 28 00 0f 00 0e 00 01 00 00 00 00 00 00 00 00 00 40 00 00 00 40 00 60 8a 01 00 60 8a 01 00 05 00 00 00 00 00 01 00 01 00 00 00 60 8a 01 00 60 8a 45 00 60 8a 45 00 c8 09 00 00 38 33 00 00 06 00 00 00 00 00 01 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 06 00 1c 3c 8c 0e 9c 27 21 e0 99 03 e0 ff bd 27 10 00 bc af 1c 00 bf af 18 00 bc af 01 00 11 04 00 00 00 00 06 00 1c 3c 68 0e 9c 27 21 e0 9f 03 1c 80 99 8f 00 00 00 00 dc 01 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 01 00 11 04 00 00 00 00 06 00 1c 3c 38 0e 9c 27 21 e0 9f 03 20 80 99 8f 00 00 00 00 90 71 39 27 09 f8 20 03 00 00 00 00 10 00 bc 8f 00 00 00 00 1c 00 bf 8f 00 00 00 00 08 00 e0 03 20 00 bd 27 06 00 1c 3c 00 0e 9c 27 21 e0 99 03 d8 ff bd 27 20 00 bf af 1c 00 b1 af 18 00 b0 af 10 00 bc af 18 80 91 8f 00 00 00 00 40 94 22 92 00 00 00 00 1d 00 [TRUNCATED]
        Data Ascii: ELFp@44 (@@````E`E83Qtd<'!'<h'!9' <8'! q9' '<'!' @"@Y B$ Y B$@$ `$$@" ('<D'!'h@h`$ D$t@| t$ ' '!<'!!'$$' <@'!'Y@! !( $_@&!( $ d@ &!( $0i@0&!( $@n@@&!( $Ps@P&!( $`x@`&!( [TRUNCATED]
        Jan 8, 2025 18:02:48.734827995 CET1236INData Raw: 00 06 24 70 00 02 8e 10 00 bc 8f 7d 00 40 14 00 00 00 00 04 84 99 8f 70 00 04 26 21 28 00 00 09 f8 20 03 10 00 06 24 80 00 02 8e 10 00 bc 8f 82 00 40 14 00 00 00 00 04 84 99 8f 80 00 04 26 21 28 00 00 09 f8 20 03 10 00 06 24 90 00 02 8e 10 00 bc
        Data Ascii: $p}@p&!( $@&!( $@&!($ ' $! !( $@ $&!( $ @$
        Jan 8, 2025 18:02:48.734842062 CET1203INData Raw: 00 40 10 00 00 00 00 20 00 02 8e 00 00 00 00 58 00 40 10 00 00 00 00 30 00 02 8e 00 00 00 00 56 00 40 10 00 00 00 00 40 00 02 8e 00 00 00 00 54 00 40 10 00 00 00 00 50 00 02 8e 00 00 00 00 52 00 40 10 00 00 00 00 60 00 02 8e 00 00 00 00 37 00 40
        Data Ascii: @ X@0V@@T@PR@`7@p4@$0@$,@$0,($ 8'( !@$b0`L !
        Jan 8, 2025 18:02:48.734855890 CET1236INData Raw: d5 ff 00 12 fe ff a3 26 01 00 22 92 d2 ff 60 10 04 00 82 a2 02 00 30 92 fd ff b5 26 2a 10 b0 02 cd ff 40 14 03 00 32 26 f4 82 99 8f 00 00 00 00 38 00 b9 af e8 83 99 8f 08 00 82 26 21 88 80 02 21 f0 00 00 34 00 b9 af 0c 00 00 10 28 00 a2 af c1 ff
        Data Ascii: &"`0&*@2&8&!!4(b"p*@4& $"(! @8"&!(@!0 ('# !$r$$<'!'$
        Jan 8, 2025 18:02:48.734869003 CET1236INData Raw: 09 f8 20 03 01 00 04 24 10 00 bc 8f 00 00 05 92 8c 81 83 8f 3c 83 99 8f 21 88 40 00 00 00 44 8e 05 00 02 24 01 00 a5 24 00 00 23 ae 04 00 22 a2 09 f8 20 03 80 28 05 00 00 00 04 92 10 00 bc 8f 80 18 04 00 e8 83 99 8f 21 18 62 00 01 00 84 24 00 00
        Data Ascii: $<!@D$$#" (!b$qB$ $<!@D$$#" (!b$qB$ $\!@<D$$#"
        Jan 8, 2025 18:02:48.734880924 CET1236INData Raw: 00 00 70 8c 0f ff 03 24 00 00 02 8e 14 00 11 26 24 10 43 00 40 00 42 34 f0 ff 03 24 24 10 43 00 05 00 42 34 ff ff 03 24 00 00 02 ae 04 00 03 a6 00 40 02 24 40 00 03 24 02 00 02 a6 06 00 03 a6 42 01 a0 12 01 00 00 a2 06 00 02 24 09 00 02 a2 08 00
        Data Ascii: p$&$C@B4$$CB4$@$@$B$ @#C!FC"$$C%G$$C$%H$C$%I$C$%J$C$%K$C%L" 4
        Jan 8, 2025 18:02:48.734894991 CET1236INData Raw: 21 20 60 02 21 28 80 02 00 2c 06 24 2c 00 07 24 09 f8 20 03 10 00 80 a6 20 00 a3 8f 02 00 85 96 40 21 03 00 c0 18 03 00 23 20 83 00 14 01 a3 8f 18 00 bc 8f 21 20 83 00 10 00 82 a6 c4 00 b9 8f 02 00 85 a4 10 00 02 24 10 00 a4 af 9c 00 a4 8f 14 00
        Data Ascii: ! `!(,$,$ @!# ! $!(`@$ @$ d$*@ !@ B<4D# CB !d@!# #DdB$U0d
        Jan 8, 2025 18:02:48.734908104 CET388INData Raw: 25 b0 65 00 44 00 a4 af 48 00 a6 af 4c 00 a7 af 50 00 a8 af 54 00 a9 af 58 00 aa af 5c 00 ab af 21 80 00 00 80 00 04 24 21 c8 e0 02 09 f8 20 03 01 00 05 24 20 00 a5 8f 40 00 a4 8f 40 00 ac 8f 80 18 10 00 21 18 64 00 80 20 05 00 18 00 bc 8f 21 20
        Data Ascii: %eDHLPTX\!$! $ @@!d ! b$$$F@B4$CB4$@$(@!(# ! $<$D@$&"H$F$B4$CL
        Jan 8, 2025 18:02:48.734920025 CET1236INData Raw: 04 00 13 24 18 00 bc 8f 0e 00 23 a6 28 00 12 a2 29 00 13 a2 60 00 b9 8f 00 00 00 00 09 f8 20 03 00 00 00 00 0f 00 42 30 63 05 42 24 ff 00 43 30 00 1a 03 00 02 12 02 00 25 18 62 00 18 00 bc 8f 08 00 02 24 2a 00 03 a6 0a 00 03 24 2f 00 03 a2 2c 00
        Data Ascii: $#()` B0cB$C0%b$*$/,-.` $0$:9;84 P$*` @! ! ! ! ! @#C
        Jan 8, 2025 18:02:48.734937906 CET1236INData Raw: 21 98 40 00 18 00 bc 8f 21 90 40 00 a4 83 82 8f 80 84 99 8f 00 00 47 8c 21 28 00 02 21 20 20 02 09 f8 20 03 03 00 06 24 18 00 bc 8f 28 00 a2 af 44 84 99 8f 02 00 04 24 03 00 05 24 09 f8 20 03 06 00 06 24 ff ff 10 24 18 00 bc 8f 37 01 50 10 34 00
        Data Ascii: !@!@G!(! $(D$$ $$7P4$$4 !($ '%P38<B00, D0 ,0222F03j2K2\"*@3
        Jan 8, 2025 18:02:48.739882946 CET1236INData Raw: 18 00 bc 8f 21 c8 40 02 09 f8 20 03 02 00 02 a6 18 00 bc 8f 21 c8 40 02 09 f8 20 03 04 00 02 ae 18 00 bc 8f 08 00 02 ae 2c 00 a2 8f 00 00 00 00 af ff 40 10 21 20 20 02 21 c8 40 02 09 f8 20 03 00 00 00 00 18 00 bc 8f a8 ff 00 10 12 00 02 a6 64 81
        Data Ascii: !@ !@ ,@! !@ d4 |xtplhd`'<'!`'|x0! $! 0


        System Behavior

        Start time (UTC):17:02:46
        Start date (UTC):08/01/2025
        Path:/tmp/dlr.mpsl.elf
        Arguments:/tmp/dlr.mpsl.elf
        File size:5773336 bytes
        MD5 hash:0d6f61f82cf2f781c6eb0661071d42d9