Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
fenty.arm4.elf

Overview

General Information

Sample name:fenty.arm4.elf
Analysis ID:1587371
MD5:6e1047a7bd485a92ed0f2ec50cfd6725
SHA1:8309fa0b9efce6b63cdd62e94a89bf4585d69626
SHA256:1f9c9a1b487401f50194e8188fab9c7b2f88e5bf732c4f516b0419c6224a4ed0
Tags:elfuser-abuse_ch
Infos:

Detection

Mirai
Score:64
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Yara detected Mirai
Sample deletes itself
Sample is packed with UPX
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Sample contains only a LOAD segment without any section mappings
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:42.0.0 Malachite
Analysis ID:1587371
Start date and time:2025-01-10 09:27:09 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 38s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:fenty.arm4.elf
Detection:MAL
Classification:mal64.troj.evad.linELF@0/0@0/0
  • VT rate limit hit for: fenty.arm4.elf
Command:/tmp/fenty.arm4.elf
PID:6240
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
Hello, World!
Standard Error:
  • system is lnxubuntu20
  • sh (PID: 6248, Parent: 1477, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
  • gsd-housekeeping (PID: 6248, Parent: 1477, MD5: b55f3394a84976ddb92a2915e5d76914) Arguments: /usr/libexec/gsd-housekeeping
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
6240.1.00007f702c017000.00007f702c029000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
    6240.1.00007f702c017000.00007f702c029000.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
    • 0x1018c:$x2: /dev/misc/watchdog
    • 0x1017c:$x3: /dev/watchdog
    • 0x101c8:$x3: /dev/watchdog
    • 0x1033c:$s1: LCOGQGPTGP
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results
    Source: global trafficTCP traffic: 192.168.2.23:50710 -> 185.196.9.234:2969
    Source: /tmp/fenty.arm4.elf (PID: 6240)Socket: 0.0.0.0:54721Jump to behavior
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: unknownTCP traffic detected without corresponding DNS query: 185.196.9.234
    Source: fenty.arm4.elfString found in binary or memory: http://upx.sf.net
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

    System Summary

    barindex
    Source: 6240.1.00007f702c017000.00007f702c029000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
    Source: LOAD without section mappingsProgram segment: 0x8000
    Source: /tmp/fenty.arm4.elf (PID: 6246)SIGKILL sent: pid: 788, result: successfulJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6246)SIGKILL sent: pid: 884, result: successfulJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6246)SIGKILL sent: pid: 1664, result: successfulJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6246)SIGKILL sent: pid: 2096, result: successfulJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6246)SIGKILL sent: pid: 2102, result: successfulJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6246)SIGKILL sent: pid: 2223, result: successfulJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6246)SIGKILL sent: pid: 6248, result: successfulJump to behavior
    Source: 6240.1.00007f702c017000.00007f702c029000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
    Source: classification engineClassification label: mal64.troj.evad.linELF@0/0@0/0

    Data Obfuscation

    barindex
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
    Source: initial sampleString containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1582/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/3088/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/230/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/110/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/231/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/111/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/232/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1579/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/112/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/233/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1699/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/113/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/234/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1335/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1698/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/114/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/235/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1334/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1576/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/2302/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/115/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/236/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/116/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/237/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/117/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/118/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/910/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/119/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/912/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/10/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/2307/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/11/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/918/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/12/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/13/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/14/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/15/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/16/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/17/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/18/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/6246/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1594/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/120/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/121/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1349/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/122/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/243/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/123/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/2/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/124/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/3/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/4/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/125/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/126/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1344/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1465/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1586/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/127/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/6/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/248/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/128/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/249/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1463/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/800/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/9/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/801/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/20/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/21/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1900/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/22/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/23/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/24/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/25/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/26/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/27/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/28/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/29/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/491/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/250/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/130/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/251/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/252/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/132/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/253/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/254/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/255/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/4509/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/256/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1599/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/257/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1477/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/379/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/258/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1476/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/259/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1475/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/936/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/30/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/2208/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/35/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/6146/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1809/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/1494/cmdlineJump to behavior
    Source: /tmp/fenty.arm4.elf (PID: 6244)File opened: /proc/260/cmdlineJump to behavior

    Hooking and other Techniques for Hiding and Protection

    barindex
    Source: /tmp/fenty.arm4.elf (PID: 6240)File: /tmp/fenty.arm4.elfJump to behavior
    Source: fenty.arm4.elfSubmission file: segment LOAD with 7.7441 entropy (max. 8.0)
    Source: /tmp/fenty.arm4.elf (PID: 6240)Queries kernel information via 'uname': Jump to behavior
    Source: fenty.arm4.elf, 6240.1.000056369ba06000.000056369bb94000.rw-.sdmpBinary or memory string: 6V!/etc/qemu-binfmt/arm
    Source: fenty.arm4.elf, 6240.1.000056369ba06000.000056369bb94000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
    Source: fenty.arm4.elf, 6240.1.00007ffeb19d4000.00007ffeb19f5000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
    Source: fenty.arm4.elf, 6240.1.00007ffeb19d4000.00007ffeb19f5000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/fenty.arm4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/fenty.arm4.elf

    Stealing of Sensitive Information

    barindex
    Source: Yara matchFile source: 6240.1.00007f702c017000.00007f702c029000.r-x.sdmp, type: MEMORY

    Remote Access Functionality

    barindex
    Source: Yara matchFile source: 6240.1.00007f702c017000.00007f702c029000.r-x.sdmp, type: MEMORY
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception11
    Obfuscated Files or Information
    1
    OS Credential Dumping
    11
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
    File Deletion
    LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
    Non-Standard Port
    Exfiltration Over BluetoothNetwork Denial of Service
    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
    Application Layer Protocol
    Automated ExfiltrationData Encrypted for Impact
    No configs have been found
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Number of created Files
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1587371 Sample: fenty.arm4.elf Startdate: 10/01/2025 Architecture: LINUX Score: 64 19 185.196.9.234, 2969, 50710, 50712 SIMPLECARRIERCH Switzerland 2->19 21 109.202.202.202, 80 INIT7CH Switzerland 2->21 23 2 other IPs or domains 2->23 25 Malicious sample detected (through community Yara rule) 2->25 27 Yara detected Mirai 2->27 29 Sample is packed with UPX 2->29 8 fenty.arm4.elf 2->8         started        11 gnome-session-binary sh gsd-housekeeping 2->11         started        signatures3 process4 signatures5 31 Sample deletes itself 8->31 13 fenty.arm4.elf 8->13         started        process6 process7 15 fenty.arm4.elf 13->15         started        17 fenty.arm4.elf 13->17         started       
    SourceDetectionScannerLabelLink
    fenty.arm4.elf11%ReversingLabs
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    http://upx.sf.netfenty.arm4.elffalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      109.202.202.202
      unknownSwitzerland
      13030INIT7CHfalse
      185.196.9.234
      unknownSwitzerland
      42624SIMPLECARRIERCHfalse
      91.189.91.43
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      91.189.91.42
      unknownUnited Kingdom
      41231CANONICAL-ASGBfalse
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
      • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
      185.196.9.234fenty.arm7.elfGet hashmaliciousMiraiBrowse
        fenty.arm4.elfGet hashmaliciousMiraiBrowse
          fenty.arm7.elfGet hashmaliciousMiraiBrowse
            fenty.arm5.elfGet hashmaliciousMiraiBrowse
              fenty.arm5.elfGet hashmaliciousMiraiBrowse
                fenty.arm5.elfGet hashmaliciousMiraiBrowse
                  fenty.arm5.elfGet hashmaliciousMiraiBrowse
                    fenty.arm5.elfGet hashmaliciousMiraiBrowse
                      91.189.91.432.elfGet hashmaliciousUnknownBrowse
                        bin.sh.elfGet hashmaliciousUnknownBrowse
                          12.elfGet hashmaliciousUnknownBrowse
                            Aqua.ppc.elfGet hashmaliciousUnknownBrowse
                              2.elfGet hashmaliciousUnknownBrowse
                                ssa.elfGet hashmaliciousUnknownBrowse
                                  main_arm.elfGet hashmaliciousMiraiBrowse
                                    arm7.elfGet hashmaliciousMiraiBrowse
                                      12.elfGet hashmaliciousUnknownBrowse
                                        2.elfGet hashmaliciousUnknownBrowse
                                          91.189.91.422.elfGet hashmaliciousUnknownBrowse
                                            bin.sh.elfGet hashmaliciousUnknownBrowse
                                              12.elfGet hashmaliciousUnknownBrowse
                                                Aqua.ppc.elfGet hashmaliciousUnknownBrowse
                                                  2.elfGet hashmaliciousUnknownBrowse
                                                    ssa.elfGet hashmaliciousUnknownBrowse
                                                      main_arm.elfGet hashmaliciousMiraiBrowse
                                                        arm7.elfGet hashmaliciousMiraiBrowse
                                                          12.elfGet hashmaliciousUnknownBrowse
                                                            2.elfGet hashmaliciousUnknownBrowse
                                                              No context
                                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                              CANONICAL-ASGB2.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              bin.sh.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              12.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              Aqua.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              2.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              ssa.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              main_arm.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 91.189.91.42
                                                              main_sh4.elfGet hashmaliciousMiraiBrowse
                                                              • 185.125.190.26
                                                              12.elfGet hashmaliciousUnknownBrowse
                                                              • 91.189.91.42
                                                              SIMPLECARRIERCHfenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              fenty.arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              fenty.arm5.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.9.234
                                                              sparc.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.10.127
                                                              armv6l.elfGet hashmaliciousMiraiBrowse
                                                              • 185.196.10.127
                                                              INIT7CH2.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              bin.sh.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              12.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              Aqua.ppc.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              2.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              ssa.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              main_arm.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                              • 109.202.202.202
                                                              12.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              2.elfGet hashmaliciousUnknownBrowse
                                                              • 109.202.202.202
                                                              No context
                                                              No context
                                                              No created / dropped files found
                                                              File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, no section header
                                                              Entropy (8bit):7.740933611086042
                                                              TrID:
                                                              • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                              File name:fenty.arm4.elf
                                                              File size:33'668 bytes
                                                              MD5:6e1047a7bd485a92ed0f2ec50cfd6725
                                                              SHA1:8309fa0b9efce6b63cdd62e94a89bf4585d69626
                                                              SHA256:1f9c9a1b487401f50194e8188fab9c7b2f88e5bf732c4f516b0419c6224a4ed0
                                                              SHA512:d54669944f19d313985bc4cd77d2cd7f54eb0935d4eeb2b233b7e284ebf67fb4fa8694d67f35b933b340df16cdbed33f87291a3dea5e706943e87d59726b7aca
                                                              SSDEEP:768:l6CfcrIcAv7xFuX3KO6iuhrnCs1QR8hRnngJ9f3ykdd3R:l6ocjAzxFgv6iuheRqEf3ykT3R
                                                              TLSH:8CE2E19DF1B01A56C60A007290FDD9F7AE2F77EA1986A3AC2C50802BFD2D4C79767C44
                                                              File Content Preview:.ELF...a..........(.....P...4...........4. ...(..........................................8...8...8..................Q.td............................~..vGeg!X...................[.........ELF.ra....(........4.....[... ..............8..6.....<.l...h.....%...

                                                              ELF header

                                                              Class:ELF32
                                                              Data:2's complement, little endian
                                                              Version:1 (current)
                                                              Machine:ARM
                                                              Version Number:0x1
                                                              Type:EXEC (Executable file)
                                                              OS/ABI:ARM - ABI
                                                              ABI Version:0
                                                              Entry Point Address:0xf950
                                                              Flags:0x202
                                                              ELF Header Size:52
                                                              Program Header Offset:52
                                                              Program Header Size:32
                                                              Number of Program Headers:3
                                                              Section Header Offset:0
                                                              Section Header Size:40
                                                              Number of Section Headers:0
                                                              Header String Table Index:0
                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                              LOAD0x00x80000x80000x828b0x828b7.74410x5R E0x8000
                                                              LOAD0x38f40x238f40x238f40x00x00.00000x6RW 0x8000
                                                              GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
                                                              TimestampSource PortDest PortSource IPDest IP
                                                              Jan 10, 2025 09:27:57.231257915 CET507102969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.236219883 CET296950710185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:57.236279011 CET507102969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.266005993 CET507102969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.270890951 CET296950710185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:57.270956993 CET507102969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.275748968 CET296950710185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:57.683017969 CET43928443192.168.2.2391.189.91.42
                                                              Jan 10, 2025 09:27:57.912455082 CET296950710185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:57.912523031 CET507102969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.912694931 CET507102969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.914385080 CET507122969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.919248104 CET296950712185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:57.919326067 CET507122969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.923268080 CET507122969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.928054094 CET296950712185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:57.928117990 CET507122969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:57.932956934 CET296950712185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:58.581736088 CET296950712185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:58.581979036 CET507122969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:58.581979036 CET507122969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:58.583671093 CET507142969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:58.588486910 CET296950714185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:58.589304924 CET507142969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:58.592645884 CET507142969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:58.597418070 CET296950714185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:58.597618103 CET507142969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:58.602418900 CET296950714185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.270431995 CET296950714185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.270678997 CET507142969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.270678997 CET507142969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.272238970 CET507162969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.277090073 CET296950716185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.277158976 CET507162969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.278400898 CET507162969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.283200979 CET296950716185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.283318996 CET507162969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.288145065 CET296950716185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.942612886 CET296950716185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.942692041 CET507162969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.942753077 CET507162969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.943289042 CET507182969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.948132038 CET296950718185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.948220968 CET507182969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.949057102 CET507182969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.953870058 CET296950718185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:27:59.953922033 CET507182969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:27:59.958719015 CET296950718185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:00.612168074 CET296950718185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:00.612251997 CET507182969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:00.612375021 CET507182969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:00.613715887 CET507202969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:00.618594885 CET296950720185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:00.618886948 CET507202969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:00.623121977 CET507202969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:00.627968073 CET296950720185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:00.628041029 CET507202969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:00.632798910 CET296950720185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:01.274224043 CET296950720185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:01.274657965 CET507202969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:01.274657965 CET507202969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:01.275203943 CET507222969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:01.481755018 CET296950722185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:01.482034922 CET507222969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:01.560348988 CET507222969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:01.565207005 CET296950722185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:01.565268993 CET507222969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:01.570219040 CET296950722185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.141154051 CET296950722185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.141247988 CET507222969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.141304016 CET507222969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.141678095 CET507242969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.147682905 CET296950724185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.147763968 CET507242969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.148495913 CET507242969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.153290987 CET296950724185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.153354883 CET507242969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.158951044 CET296950724185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.822627068 CET296950724185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.822695017 CET507242969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.822777033 CET507242969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.823299885 CET507262969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.828161001 CET296950726185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.828233004 CET507262969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.829504967 CET507262969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.834323883 CET296950726185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:02.834376097 CET507262969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:02.839190960 CET296950726185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:03.058043003 CET42836443192.168.2.2391.189.91.43
                                                              Jan 10, 2025 09:28:03.519095898 CET296950726185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:03.519150019 CET507262969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:03.519236088 CET507262969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:03.520050049 CET507282969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:03.525047064 CET296950728185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:03.525208950 CET507282969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:03.525854111 CET507282969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:03.530720949 CET296950728185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:03.530765057 CET507282969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:03.535629034 CET296950728185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.180598021 CET296950728185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.180881977 CET507282969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.180882931 CET507282969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.181544065 CET507302969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.186355114 CET296950730185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.186440945 CET507302969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.187624931 CET507302969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.192470074 CET296950730185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.192526102 CET507302969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.197370052 CET296950730185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.593888998 CET4251680192.168.2.23109.202.202.202
                                                              Jan 10, 2025 09:28:04.854110956 CET296950730185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.854284048 CET507302969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.854363918 CET507302969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.854790926 CET507322969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.859602928 CET296950732185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.859661102 CET507322969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.860452890 CET507322969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.865211010 CET296950732185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:04.865257978 CET507322969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:04.870031118 CET296950732185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:05.520425081 CET296950732185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:05.520477057 CET507322969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:05.520545006 CET507322969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:05.521435022 CET507342969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:05.526283026 CET296950734185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:05.526340961 CET507342969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:05.528250933 CET507342969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:05.533085108 CET296950734185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:05.533126116 CET507342969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:05.537929058 CET296950734185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.202614069 CET296950734185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.202866077 CET507342969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.202866077 CET507342969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.204032898 CET507362969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.208822966 CET296950736185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.209039927 CET507362969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.210911036 CET507362969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.215686083 CET296950736185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.215785980 CET507362969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.220586061 CET296950736185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.899538040 CET296950736185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.899629116 CET507362969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.899734974 CET507362969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.900764942 CET507382969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.905581951 CET296950738185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.905646086 CET507382969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.906642914 CET507382969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.911448956 CET296950738185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:06.911845922 CET507382969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:06.916680098 CET296950738185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:07.564860106 CET296950738185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:07.565090895 CET507382969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:07.565285921 CET507382969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:07.565759897 CET507402969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:07.570575953 CET296950740185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:07.570689917 CET507402969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:07.571857929 CET507402969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:07.576637983 CET296950740185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:07.576703072 CET507402969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:07.581552029 CET296950740185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.257256985 CET296950740185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.257316113 CET507402969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.257436037 CET507402969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.260663033 CET507422969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.266773939 CET296950742185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.266840935 CET507422969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.273417950 CET507422969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.278192043 CET296950742185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.278247118 CET507422969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.283041954 CET296950742185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.932347059 CET296950742185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.932511091 CET507422969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.932511091 CET507422969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.933358908 CET507442969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.938186884 CET296950744185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.938252926 CET507442969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.940128088 CET507442969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.944907904 CET296950744185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:08.944967031 CET507442969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:08.949801922 CET296950744185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:09.597853899 CET296950744185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:09.597995043 CET507442969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:09.597995043 CET507442969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:09.598586082 CET507462969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:09.603431940 CET296950746185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:09.603492975 CET507462969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:09.606065035 CET507462969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:09.610862970 CET296950746185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:09.611037970 CET507462969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:09.615895033 CET296950746185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.266450882 CET296950746185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.266546965 CET507462969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.266603947 CET507462969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.267364979 CET507482969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.272167921 CET296950748185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.272252083 CET507482969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.273328066 CET507482969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.278163910 CET296950748185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.278218985 CET507482969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.282994032 CET296950748185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.934458971 CET296950748185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.934521914 CET507482969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.934606075 CET507482969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.935810089 CET507502969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.940589905 CET296950750185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.940648079 CET507502969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.943123102 CET507502969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.947897911 CET296950750185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:10.947949886 CET507502969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:10.952925920 CET296950750185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:11.621804953 CET296950750185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:11.621870041 CET507502969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:11.621988058 CET507502969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:11.623105049 CET507522969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:11.628201962 CET296950752185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:11.628277063 CET507522969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:11.631146908 CET507522969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:11.637376070 CET296950752185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:11.637432098 CET507522969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:11.642244101 CET296950752185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:12.308188915 CET296950752185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:12.308285952 CET507522969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:12.308464050 CET507522969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:12.349533081 CET507542969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:12.354449987 CET296950754185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:12.354732037 CET507542969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:12.429625988 CET507542969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:12.434468985 CET296950754185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:12.434575081 CET507542969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:12.442620039 CET296950754185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.017216921 CET296950754185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.017330885 CET507542969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.017411947 CET507542969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.018132925 CET507562969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.023067951 CET296950756185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.023341894 CET507562969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.024166107 CET507562969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.029017925 CET296950756185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.029073000 CET507562969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.033878088 CET296950756185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.701678038 CET296950756185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.701745987 CET507562969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.702014923 CET507562969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.702414989 CET507582969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.707282066 CET296950758185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.707365036 CET507582969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.708467007 CET507582969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.713267088 CET296950758185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:13.713323116 CET507582969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:13.718103886 CET296950758185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:14.387139082 CET296950758185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:14.387253046 CET507582969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:14.387331963 CET507582969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:14.387967110 CET507602969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:14.392905951 CET296950760185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:14.392980099 CET507602969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:14.394098043 CET507602969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:14.399450064 CET296950760185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:14.399518013 CET507602969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:14.404830933 CET296950760185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.062715054 CET296950760185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.062787056 CET507602969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.062880039 CET507602969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.063844919 CET507622969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.068661928 CET296950762185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.068730116 CET507622969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.070071936 CET507622969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.074853897 CET296950762185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.074906111 CET507622969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.079672098 CET296950762185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.736510038 CET296950762185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.736598015 CET507622969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.736689091 CET507622969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.737200975 CET507642969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.742023945 CET296950764185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.742100000 CET507642969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.742867947 CET507642969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.747628927 CET296950764185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:15.747693062 CET507642969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:15.752542973 CET296950764185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:16.425951958 CET296950764185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:16.426098108 CET507642969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:16.426198006 CET507642969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:16.426826000 CET507662969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:16.433139086 CET296950766185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:16.433357000 CET507662969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:16.434238911 CET507662969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:16.440587044 CET296950766185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:16.440959930 CET507662969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:16.447428942 CET296950766185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.105510950 CET296950766185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.105751038 CET507662969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.105792999 CET507662969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.106414080 CET507682969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.112875938 CET296950768185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.112946987 CET507682969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.113919020 CET507682969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.120354891 CET296950768185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.120421886 CET507682969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.128660917 CET296950768185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.648082972 CET43928443192.168.2.2391.189.91.42
                                                              Jan 10, 2025 09:28:17.797277927 CET296950768185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.797383070 CET507682969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.797480106 CET507682969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.798223019 CET507702969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.803102970 CET296950770185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.803179979 CET507702969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.804119110 CET507702969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.808952093 CET296950770185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:17.809004068 CET507702969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:17.813836098 CET296950770185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:18.492552042 CET296950770185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:18.492680073 CET507702969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:18.492860079 CET507702969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:18.493550062 CET507722969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:18.498358965 CET296950772185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:18.498502970 CET507722969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:18.499521017 CET507722969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:18.504317999 CET296950772185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:18.504565001 CET507722969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:18.509385109 CET296950772185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.177819967 CET296950772185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.177928925 CET507722969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.178092003 CET507722969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.178730965 CET507742969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.183536053 CET296950774185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.183727026 CET507742969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.184562922 CET507742969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.189436913 CET296950774185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.189508915 CET507742969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.194277048 CET296950774185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.871285915 CET296950774185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.871592999 CET507742969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.871623993 CET507742969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.872195005 CET507762969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.876995087 CET296950776185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.877053976 CET507762969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.877722025 CET507762969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.882507086 CET296950776185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:19.882581949 CET507762969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:19.887396097 CET296950776185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:20.538961887 CET296950776185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:20.539129972 CET507762969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:20.539222956 CET507762969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:20.539944887 CET507782969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:20.544749022 CET296950778185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:20.544806004 CET507782969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:20.546350002 CET507782969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:20.551140070 CET296950778185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:20.551208973 CET507782969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:20.556045055 CET296950778185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.219511032 CET296950778185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.219602108 CET507782969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.219805002 CET507782969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.220228910 CET507802969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.225058079 CET296950780185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.225120068 CET507802969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.225938082 CET507802969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.230705976 CET296950780185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.230777025 CET507802969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.235573053 CET296950780185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.888948917 CET296950780185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.889132977 CET507802969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.889132977 CET507802969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.889580965 CET507822969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.894366980 CET296950782185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.894443989 CET507822969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.895179033 CET507822969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.899935007 CET296950782185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:21.900019884 CET507822969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:21.904787064 CET296950782185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:22.581466913 CET296950782185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:22.581535101 CET507822969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:22.581640959 CET507822969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:22.582202911 CET507842969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:22.587032080 CET296950784185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:22.587095022 CET507842969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:22.587976933 CET507842969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:22.592767000 CET296950784185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:22.592819929 CET507842969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:22.597609997 CET296950784185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.247997046 CET296950784185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.248084068 CET507842969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.248116016 CET507842969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.248538017 CET507862969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.253310919 CET296950786185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.253370047 CET507862969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.253979921 CET507862969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.258744955 CET296950786185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.258800030 CET507862969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.263550997 CET296950786185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.919759035 CET296950786185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.919811964 CET507862969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.919853926 CET507862969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.920645952 CET507882969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.925975084 CET296950788185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.926059961 CET507882969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.927042961 CET507882969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.932317972 CET296950788185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:23.932435989 CET507882969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:23.937668085 CET296950788185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:24.590874910 CET296950788185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:24.590981007 CET507882969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:24.591047049 CET507882969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:24.591454029 CET507902969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:24.596281052 CET296950790185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:24.596402884 CET507902969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:24.597090006 CET507902969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:24.601881981 CET296950790185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:24.601969957 CET507902969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:24.606816053 CET296950790185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.267376900 CET296950790185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.267620087 CET507902969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.267787933 CET507902969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.268129110 CET507922969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.272922993 CET296950792185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.272979021 CET507922969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.273973942 CET507922969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.278757095 CET296950792185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.278827906 CET507922969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.283629894 CET296950792185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.946949959 CET296950792185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.947098017 CET507922969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.947212934 CET507922969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.948235035 CET507942969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.954910040 CET296950794185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.954993010 CET507942969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.956018925 CET507942969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.960885048 CET296950794185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:25.960939884 CET507942969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:25.967606068 CET296950794185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:26.626948118 CET296950794185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:26.627063036 CET507942969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:26.627136946 CET507942969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:26.627866983 CET507962969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:26.632767916 CET296950796185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:26.632848978 CET507962969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:26.634381056 CET507962969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:26.639223099 CET296950796185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:26.639290094 CET507962969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:26.644177914 CET296950796185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:29.934267998 CET42836443192.168.2.2391.189.91.43
                                                              Jan 10, 2025 09:28:34.029699087 CET4251680192.168.2.23109.202.202.202
                                                              Jan 10, 2025 09:28:36.641479015 CET507962969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:36.646358967 CET296950796185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:36.841003895 CET296950796185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:28:36.841052055 CET507962969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:28:58.602216959 CET43928443192.168.2.2391.189.91.42
                                                              Jan 10, 2025 09:29:36.882944107 CET507962969192.168.2.23185.196.9.234
                                                              Jan 10, 2025 09:29:36.887779951 CET296950796185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:29:37.082417011 CET296950796185.196.9.234192.168.2.23
                                                              Jan 10, 2025 09:29:37.082499981 CET507962969192.168.2.23185.196.9.234

                                                              System Behavior

                                                              Start time (UTC):08:27:56
                                                              Start date (UTC):10/01/2025
                                                              Path:/tmp/fenty.arm4.elf
                                                              Arguments:/tmp/fenty.arm4.elf
                                                              File size:4956856 bytes
                                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                              Start time (UTC):08:27:56
                                                              Start date (UTC):10/01/2025
                                                              Path:/tmp/fenty.arm4.elf
                                                              Arguments:-
                                                              File size:4956856 bytes
                                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                              Start time (UTC):08:27:56
                                                              Start date (UTC):10/01/2025
                                                              Path:/tmp/fenty.arm4.elf
                                                              Arguments:-
                                                              File size:4956856 bytes
                                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                              Start time (UTC):08:27:56
                                                              Start date (UTC):10/01/2025
                                                              Path:/tmp/fenty.arm4.elf
                                                              Arguments:-
                                                              File size:4956856 bytes
                                                              MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

                                                              Start time (UTC):08:27:56
                                                              Start date (UTC):10/01/2025
                                                              Path:/usr/libexec/gnome-session-binary
                                                              Arguments:-
                                                              File size:334664 bytes
                                                              MD5 hash:d9b90be4f7db60cb3c2d3da6a1d31bfb

                                                              Start time (UTC):08:27:56
                                                              Start date (UTC):10/01/2025
                                                              Path:/bin/sh
                                                              Arguments:/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-housekeeping
                                                              File size:129816 bytes
                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                              Start time (UTC):08:27:56
                                                              Start date (UTC):10/01/2025
                                                              Path:/usr/libexec/gsd-housekeeping
                                                              Arguments:/usr/libexec/gsd-housekeeping
                                                              File size:51840 bytes
                                                              MD5 hash:b55f3394a84976ddb92a2915e5d76914